Security

    [Spring] Spring Security + OAuth2.0 + JWT Token์„ ํ™œ์šฉํ•œ ์†Œ์…œ๋กœ๊ทธ์ธ ์ด์ •๋ฆฌ - (1) ๋ฐฐ๊ฒฝ ์ง€์‹ ์ดํ•ดํ•˜๊ธฐ, ์ „์ฒด ๊ทธ๋ฆผ ์‚ดํŽด๋ณด๊ธฐ

    [Spring] Spring Security + OAuth2.0 + JWT Token์„ ํ™œ์šฉํ•œ ์†Œ์…œ๋กœ๊ทธ์ธ ์ด์ •๋ฆฌ - (1) ๋ฐฐ๊ฒฝ ์ง€์‹ ์ดํ•ดํ•˜๊ธฐ, ์ „์ฒด ๊ทธ๋ฆผ ์‚ดํŽด๋ณด๊ธฐ

    ๐Ÿ™‹๐Ÿป ์„œ๋ก  NEO ํ† ์ด ํ”„๋กœ์ ํŠธ๋ฅผ ์ง„ํ–‰ํ•˜๋ฉด์„œ ์†Œ์…œ ๋กœ๊ทธ์ธ ๊ธฐ๋Šฅ์„ ๊ตฌํ˜„ํ•˜๊ฒŒ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ธํ„ฐ๋„ท ์ƒ์˜ ๋งŽ์€ ๊ธ€์„ ์ฝ๊ณ , ๋„์›€์„ ๋งŽ์ด ๋ฐ›์•˜์œผ๋‚˜ ์ •๋ณด๊ฐ€ ํ•œ๋ฐ ๋ชจ์—ฌ์žˆ์ง€ ์•Š๊ณ  ๋ณธ์ธ์ด ๊ฐœ์ธ์ ์œผ๋กœ ์ดํ•ด๊ฐ€ ๋˜์ง€ ์•Š๋Š” ๋ถ€๋ถ„์ด ๋งŽ์•„ ๋‚˜์ค‘์— ๋‹ค์‹œ ๊ตฌํ˜„ํ•  ๊ฒฝ์šฐ๋ฅผ ๋Œ€๋น„ํ•ด ๊ธ€๋กœ ์ž‘์„ฑํ•˜๊ธฐ๋กœ ๋งˆ์Œ์„ ๋จน์—ˆ์Šต๋‹ˆ๋‹ค. ๋ถ€์กฑํ•œ ๋‚ด์šฉ์ด ์žˆ์„ ์ˆ˜ ์žˆ์ง€๋งŒ ๋” ์ข‹์€ ๋‚ด์šฉ์ด ์žˆ๋‹ค๋ฉด ๋Œ“๊ธ€๋กœ ๋‹ฌ์•„์ฃผ์‹œ๋ฉด ๊ฐ์‚ฌํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. ์ข‹์€ ํ”ผ๋“œ๋ฐฑ์€ ์–ธ์ œ๋‚˜ ํ™˜์˜์ด๋ฉฐ, ์ œ ๊ธ€์ด ์†Œ์…œ๋กœ๊ทธ์ธ์„ ๊ตฌํ˜„ํ•˜๋ ค๋Š” ๋ˆ„๊ตฐ๊ฐ€์—๊ฒŒ ์ข‹์€ ๋„์›€์ด ๋˜์—ˆ์œผ๋ฉด ํ•ฉ๋‹ˆ๋‹ค. ๊ธ€์˜ ์ง„ํ–‰์€ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ˆœ์„œ๋กœ ์ด์–ด์งˆ ์˜ˆ์ •์ž…๋‹ˆ๋‹ค. 1. ๋ฐฐ๊ฒฝ์ง€์‹ ์ดํ•ดํ•˜๊ธฐ, ์ „์ฒด ๊ทธ๋ฆผ ์‚ดํŽด๋ณด๊ธฐ (OAuth2, JWT Token, ํ”„๋กœ์ ํŠธ ์ „์ฒด ๋„์‹ํ™”) 2. Naver, Kakao, Google์— ํ”„๋กœ์ ํŠธ๋ฅผ OAuth2 Client๋กœ..