CLIENT와 SERVER는 분리 된 것으로 가정
1. controller에서 /login 엔드 포인트로 로그인 진행
2. user id/password 검사 후 tokenService에서
accessToken(시간 30분)은 response body로 return
refreshToken(시간 7일)은 DB에 저장하고 http only cookie 로 클라이언트에게 return
--- 로그인 성공 후 api 요청 ---
3. client에서 accessToken과 함께 api 요청함
4. OncePerRequestFilter를 상속 받은 JwtRequestFilter에서 accessToken 검증 후
Authentication을 상속받은 UsernamePasswordToken으로 인증객체 Authentication을 생성하여
Sec,urityContextHolder.getContext().setAuthentication(authentication)으로 인증 객체 저장
5. accessToken이 만료 됏거나 좀 삐꾸다? AuthenticationEntry에서 HttpStatus.UNAUTHORIZED 401 반환
7. client에서 HttpStatus.UNAUTHORIZED 401 확인
8. /reissue 엔드 포인트로 refreshtoken 재발행 요청
9. tokenservice에서 refreshtoken 검증 진행
10. tokenservice에서 기존 refrehtoken 삭제 ( 혹시 모를 탈취 위험 )
11. tokenservice에서 최신 user 정보 조회
12. user 정보로
accessToken(30분) 생성 response body로 반환
refreshToken(7일) 생성 및 DB 저장, http only cookie로 클라이언트에게 return
댓글 0