From 2b16d1a3e18a04e5198bd9454fc76377d7025a11 Mon Sep 17 00:00:00 2001 From: "sungjin.choi" Date: Fri, 15 May 2026 10:36:20 +0900 Subject: [PATCH] nitial commit --- .gitattributes | 3 + .gitignore | 45 ++++ HELP.md | 34 +++ build.gradle | 53 ++++ gradlew | 248 ++++++++++++++++++ gradlew.bat | 93 +++++++ settings.gradle | 1 + .../SpecialsourceHomepageApplication.java | 13 + .../specialsource/config/DataInitializer.java | 32 +++ .../specialsource/config/JasyptConfig.java | 33 +++ .../specialsource/config/SecurityConfig.java | 31 +++ .../controller/AuthController.java | 26 ++ .../specialsource/dto/LoginRequest.java | 10 + .../company/specialsource/entity/User.java | 25 ++ .../repository/UserRepository.java | 10 + .../specialsource/service/UserService.java | 28 ++ src/main/resources/application.yaml | 18 ++ .../resources/setJasyptEncryptorPassword.ps1 | 2 + 18 files changed, 705 insertions(+) create mode 100644 .gitattributes create mode 100644 .gitignore create mode 100644 HELP.md create mode 100644 build.gradle create mode 100644 gradlew create mode 100644 gradlew.bat create mode 100644 settings.gradle create mode 100644 src/main/java/company/specialsource/SpecialsourceHomepageApplication.java create mode 100644 src/main/java/company/specialsource/config/DataInitializer.java create mode 100644 src/main/java/company/specialsource/config/JasyptConfig.java create mode 100644 src/main/java/company/specialsource/config/SecurityConfig.java create mode 100644 src/main/java/company/specialsource/controller/AuthController.java create mode 100644 src/main/java/company/specialsource/dto/LoginRequest.java create mode 100644 src/main/java/company/specialsource/entity/User.java create mode 100644 src/main/java/company/specialsource/repository/UserRepository.java create mode 100644 src/main/java/company/specialsource/service/UserService.java create mode 100644 src/main/resources/application.yaml create mode 100644 src/main/resources/setJasyptEncryptorPassword.ps1 diff --git a/.gitattributes b/.gitattributes new file mode 100644 index 0000000..8af972c --- /dev/null +++ b/.gitattributes @@ -0,0 +1,3 @@ +/gradlew text eol=lf +*.bat text eol=crlf +*.jar binary diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..01af45f --- /dev/null +++ b/.gitignore @@ -0,0 +1,45 @@ +HELP.md +.gradle +build/ +!gradle/wrapper/gradle-wrapper.jar +!**/src/main/**/build/ +!**/src/test/**/build/ + +### STS ### +.apt_generated +.classpath +.factorypath +.project +.settings +.springBeans +.sts4-cache +bin/ +!**/src/main/**/bin/ +!**/src/test/**/bin/ + +### IntelliJ IDEA ### +.idea +*.iws +*.iml +*.ipr +out/ +gen/ +!**/src/main/**/out/ +!**/src/test/**/out/ + +### NetBeans ### +/nbproject/private/ +/nbbuild/ +/dist/ +/nbdist/ +/.nb-gradle/ + +### VS Code ### +.vscode/ + +### 기타 운영체제 파일 ### +.DS_Store +Thumbs.db + +### 로그 파일 ### +*.log \ No newline at end of file diff --git a/HELP.md b/HELP.md new file mode 100644 index 0000000..07ac586 --- /dev/null +++ b/HELP.md @@ -0,0 +1,34 @@ +# Getting Started + +### Reference Documentation + +For further reference, please consider the following sections: + +* [Official Gradle documentation](https://docs.gradle.org) +* [Spring Boot Gradle Plugin Reference Guide](https://docs.spring.io/spring-boot/4.0.6/gradle-plugin) +* [Create an OCI image](https://docs.spring.io/spring-boot/4.0.6/gradle-plugin/packaging-oci-image.html) +* [Spring Data JPA](https://docs.spring.io/spring-boot/4.0.6/reference/data/sql.html#data.sql.jpa-and-spring-data) +* [Spring Boot DevTools](https://docs.spring.io/spring-boot/4.0.6/reference/using/devtools.html) +* [Spring Security](https://docs.spring.io/spring-boot/4.0.6/reference/web/spring-security.html) +* [Thymeleaf](https://docs.spring.io/spring-boot/4.0.6/reference/web/servlet.html#web.servlet.spring-mvc.template-engines) +* [Spring Web](https://docs.spring.io/spring-boot/4.0.6/reference/web/servlet.html) + +### Guides + +The following guides illustrate how to use some features concretely: + +* [Accessing Data with JPA](https://spring.io/guides/gs/accessing-data-jpa/) +* [Securing a Web Application](https://spring.io/guides/gs/securing-web/) +* [Spring Boot and OAuth2](https://spring.io/guides/tutorials/spring-boot-oauth2/) +* [Authenticating a User with LDAP](https://spring.io/guides/gs/authenticating-ldap/) +* [Handling Form Submission](https://spring.io/guides/gs/handling-form-submission/) +* [Building a RESTful Web Service](https://spring.io/guides/gs/rest-service/) +* [Serving Web Content with Spring MVC](https://spring.io/guides/gs/serving-web-content/) +* [Building REST services with Spring](https://spring.io/guides/tutorials/rest/) + +### Additional Links + +These additional references should also help you: + +* [Gradle Build Scans – insights for your project's build](https://scans.gradle.com#gradle) + diff --git a/build.gradle b/build.gradle new file mode 100644 index 0000000..fee9ba6 --- /dev/null +++ b/build.gradle @@ -0,0 +1,53 @@ +plugins { + id 'java' + id 'org.springframework.boot' version '3.3.0' // 또는 3.2.5 + id 'io.spring.dependency-management' version '1.1.5' // 최신 버전으로 업데이트 +} + +group = 'company.specialsource' +version = '0.0.1-SNAPSHOT' +description = 'specialsource-homepage-backend' + +java { + toolchain { + languageVersion = JavaLanguageVersion.of(21) // Temurin 21 사용 설정 + } +} + +repositories { + mavenCentral() +} + +dependencies { + // 1. 핵심 웹 및 API (Vue.js와 통신을 위해 필요) + implementation 'org.springframework.boot:spring-boot-starter-web' // webmvc 대신 표준 starter-web 사용 권장 + + // 2. 보안 및 인증 (Spring Security) + implementation 'org.springframework.boot:spring-boot-starter-security' + + // 3. 데이터베이스 (JPA + PostgreSQL) + implementation 'org.springframework.boot:spring-boot-starter-data-jpa' + runtimeOnly 'org.postgresql:postgresql' // PostgreSQL 드라이버 추가 (필수!) + + // 4. 화면 엔진 (Thymeleaf - 프런트를 Vue로 하더라도 초기 설정/오류 페이지용으로 유지 권장) + implementation 'org.springframework.boot:spring-boot-starter-thymeleaf' + implementation 'org.thymeleaf.extras:thymeleaf-extras-springsecurity6' + + // 5. 개발 편의성 도구 + compileOnly 'org.projectlombok:lombok' + annotationProcessor 'org.projectlombok:lombok' + developmentOnly 'org.springframework.boot:spring-boot-devtools' + + // 6. 테스트 도구 (필요 없는 -test 접미사 정리) + testImplementation 'org.springframework.boot:spring-boot-starter-test' + testImplementation 'org.springframework.security:spring-security-test' + testRuntimeOnly 'org.junit.platform:junit-platform-launcher' + + // Jasypt Spring Boot Starter + implementation 'com.github.ulisesbocchio:jasypt-spring-boot-starter:3.0.5' + +} + +tasks.named('test') { + useJUnitPlatform() +} \ No newline at end of file diff --git a/gradlew b/gradlew new file mode 100644 index 0000000..739907d --- /dev/null +++ b/gradlew @@ -0,0 +1,248 @@ +#!/bin/sh + +# +# Copyright © 2015 the original authors. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# https://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +# SPDX-License-Identifier: Apache-2.0 +# + +############################################################################## +# +# Gradle start up script for POSIX generated by Gradle. +# +# Important for running: +# +# (1) You need a POSIX-compliant shell to run this script. If your /bin/sh is +# noncompliant, but you have some other compliant shell such as ksh or +# bash, then to run this script, type that shell name before the whole +# command line, like: +# +# ksh Gradle +# +# Busybox and similar reduced shells will NOT work, because this script +# requires all of these POSIX shell features: +# * functions; +# * expansions «$var», «${var}», «${var:-default}», «${var+SET}», +# «${var#prefix}», «${var%suffix}», and «$( cmd )»; +# * compound commands having a testable exit status, especially «case»; +# * various built-in commands including «command», «set», and «ulimit». +# +# Important for patching: +# +# (2) This script targets any POSIX shell, so it avoids extensions provided +# by Bash, Ksh, etc; in particular arrays are avoided. +# +# The "traditional" practice of packing multiple parameters into a +# space-separated string is a well documented source of bugs and security +# problems, so this is (mostly) avoided, by progressively accumulating +# options in "$@", and eventually passing that to Java. +# +# Where the inherited environment variables (DEFAULT_JVM_OPTS, JAVA_OPTS, +# and GRADLE_OPTS) rely on word-splitting, this is performed explicitly; +# see the in-line comments for details. +# +# There are tweaks for specific operating systems such as AIX, CygWin, +# Darwin, MinGW, and NonStop. +# +# (3) This script is generated from the Groovy template +# https://github.com/gradle/gradle/blob/2d6327017519d23b96af35865dc997fcb544fb40/platforms/jvm/plugins-application/src/main/resources/org/gradle/api/internal/plugins/unixStartScript.txt +# within the Gradle project. +# +# You can find Gradle at https://github.com/gradle/gradle/. +# +############################################################################## + +# Attempt to set APP_HOME + +# Resolve links: $0 may be a link +app_path=$0 + +# Need this for daisy-chained symlinks. +while + APP_HOME=${app_path%"${app_path##*/}"} # leaves a trailing /; empty if no leading path + [ -h "$app_path" ] +do + ls=$( ls -ld "$app_path" ) + link=${ls#*' -> '} + case $link in #( + /*) app_path=$link ;; #( + *) app_path=$APP_HOME$link ;; + esac +done + +# This is normally unused +# shellcheck disable=SC2034 +APP_BASE_NAME=${0##*/} +# Discard cd standard output in case $CDPATH is set (https://github.com/gradle/gradle/issues/25036) +APP_HOME=$( cd -P "${APP_HOME:-./}" > /dev/null && printf '%s\n' "$PWD" ) || exit + +# Use the maximum available, or set MAX_FD != -1 to use that value. +MAX_FD=maximum + +warn () { + echo "$*" +} >&2 + +die () { + echo + echo "$*" + echo + exit 1 +} >&2 + +# OS specific support (must be 'true' or 'false'). +cygwin=false +msys=false +darwin=false +nonstop=false +case "$( uname )" in #( + CYGWIN* ) cygwin=true ;; #( + Darwin* ) darwin=true ;; #( + MSYS* | MINGW* ) msys=true ;; #( + NONSTOP* ) nonstop=true ;; +esac + + + +# Determine the Java command to use to start the JVM. +if [ -n "$JAVA_HOME" ] ; then + if [ -x "$JAVA_HOME/jre/sh/java" ] ; then + # IBM's JDK on AIX uses strange locations for the executables + JAVACMD=$JAVA_HOME/jre/sh/java + else + JAVACMD=$JAVA_HOME/bin/java + fi + if [ ! -x "$JAVACMD" ] ; then + die "ERROR: JAVA_HOME is set to an invalid directory: $JAVA_HOME + +Please set the JAVA_HOME variable in your environment to match the +location of your Java installation." + fi +else + JAVACMD=java + if ! command -v java >/dev/null 2>&1 + then + die "ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. + +Please set the JAVA_HOME variable in your environment to match the +location of your Java installation." + fi +fi + +# Increase the maximum file descriptors if we can. +if ! "$cygwin" && ! "$darwin" && ! "$nonstop" ; then + case $MAX_FD in #( + max*) + # In POSIX sh, ulimit -H is undefined. That's why the result is checked to see if it worked. + # shellcheck disable=SC2039,SC3045 + MAX_FD=$( ulimit -H -n ) || + warn "Could not query maximum file descriptor limit" + esac + case $MAX_FD in #( + '' | soft) :;; #( + *) + # In POSIX sh, ulimit -n is undefined. That's why the result is checked to see if it worked. + # shellcheck disable=SC2039,SC3045 + ulimit -n "$MAX_FD" || + warn "Could not set maximum file descriptor limit to $MAX_FD" + esac +fi + +# Collect all arguments for the java command, stacking in reverse order: +# * args from the command line +# * the main class name +# * -classpath +# * -D...appname settings +# * --module-path (only if needed) +# * DEFAULT_JVM_OPTS, JAVA_OPTS, and GRADLE_OPTS environment variables. + +# For Cygwin or MSYS, switch paths to Windows format before running java +if "$cygwin" || "$msys" ; then + APP_HOME=$( cygpath --path --mixed "$APP_HOME" ) + + JAVACMD=$( cygpath --unix "$JAVACMD" ) + + # Now convert the arguments - kludge to limit ourselves to /bin/sh + for arg do + if + case $arg in #( + -*) false ;; # don't mess with options #( + /?*) t=${arg#/} t=/${t%%/*} # looks like a POSIX filepath + [ -e "$t" ] ;; #( + *) false ;; + esac + then + arg=$( cygpath --path --ignore --mixed "$arg" ) + fi + # Roll the args list around exactly as many times as the number of + # args, so each arg winds up back in the position where it started, but + # possibly modified. + # + # NB: a `for` loop captures its iteration list before it begins, so + # changing the positional parameters here affects neither the number of + # iterations, nor the values presented in `arg`. + shift # remove old arg + set -- "$@" "$arg" # push replacement arg + done +fi + + +# Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script. +DEFAULT_JVM_OPTS='"-Xmx64m" "-Xms64m"' + +# Collect all arguments for the java command: +# * DEFAULT_JVM_OPTS, JAVA_OPTS, and optsEnvironmentVar are not allowed to contain shell fragments, +# and any embedded shellness will be escaped. +# * For example: A user cannot expect ${Hostname} to be expanded, as it is an environment variable and will be +# treated as '${Hostname}' itself on the command line. + +set -- \ + "-Dorg.gradle.appname=$APP_BASE_NAME" \ + -jar "$APP_HOME/gradle/wrapper/gradle-wrapper.jar" \ + "$@" + +# Stop when "xargs" is not available. +if ! command -v xargs >/dev/null 2>&1 +then + die "xargs is not available" +fi + +# Use "xargs" to parse quoted args. +# +# With -n1 it outputs one arg per line, with the quotes and backslashes removed. +# +# In Bash we could simply go: +# +# readarray ARGS < <( xargs -n1 <<<"$var" ) && +# set -- "${ARGS[@]}" "$@" +# +# but POSIX shell has neither arrays nor command substitution, so instead we +# post-process each arg (as a line of input to sed) to backslash-escape any +# character that might be a shell metacharacter, then use eval to reverse +# that process (while maintaining the separation between arguments), and wrap +# the whole thing up as a single "set" statement. +# +# This will of course break if any of these variables contains a newline or +# an unmatched quote. +# + +eval "set -- $( + printf '%s\n' "$DEFAULT_JVM_OPTS $JAVA_OPTS $GRADLE_OPTS" | + xargs -n1 | + sed ' s~[^-[:alnum:]+,./:=@_]~\\&~g; ' | + tr '\n' ' ' + )" '"$@"' + +exec "$JAVACMD" "$@" diff --git a/gradlew.bat b/gradlew.bat new file mode 100644 index 0000000..c4bdd3a --- /dev/null +++ b/gradlew.bat @@ -0,0 +1,93 @@ +@rem +@rem Copyright 2015 the original author or authors. +@rem +@rem Licensed under the Apache License, Version 2.0 (the "License"); +@rem you may not use this file except in compliance with the License. +@rem You may obtain a copy of the License at +@rem +@rem https://www.apache.org/licenses/LICENSE-2.0 +@rem +@rem Unless required by applicable law or agreed to in writing, software +@rem distributed under the License is distributed on an "AS IS" BASIS, +@rem WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +@rem See the License for the specific language governing permissions and +@rem limitations under the License. +@rem +@rem SPDX-License-Identifier: Apache-2.0 +@rem + +@if "%DEBUG%"=="" @echo off +@rem ########################################################################## +@rem +@rem Gradle startup script for Windows +@rem +@rem ########################################################################## + +@rem Set local scope for the variables with windows NT shell +if "%OS%"=="Windows_NT" setlocal + +set DIRNAME=%~dp0 +if "%DIRNAME%"=="" set DIRNAME=. +@rem This is normally unused +set APP_BASE_NAME=%~n0 +set APP_HOME=%DIRNAME% + +@rem Resolve any "." and ".." in APP_HOME to make it shorter. +for %%i in ("%APP_HOME%") do set APP_HOME=%%~fi + +@rem Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script. +set DEFAULT_JVM_OPTS="-Xmx64m" "-Xms64m" + +@rem Find java.exe +if defined JAVA_HOME goto findJavaFromJavaHome + +set JAVA_EXE=java.exe +%JAVA_EXE% -version >NUL 2>&1 +if %ERRORLEVEL% equ 0 goto execute + +echo. 1>&2 +echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH. 1>&2 +echo. 1>&2 +echo Please set the JAVA_HOME variable in your environment to match the 1>&2 +echo location of your Java installation. 1>&2 + +goto fail + +:findJavaFromJavaHome +set JAVA_HOME=%JAVA_HOME:"=% +set JAVA_EXE=%JAVA_HOME%/bin/java.exe + +if exist "%JAVA_EXE%" goto execute + +echo. 1>&2 +echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME% 1>&2 +echo. 1>&2 +echo Please set the JAVA_HOME variable in your environment to match the 1>&2 +echo location of your Java installation. 1>&2 + +goto fail + +:execute +@rem Setup the command line + + + +@rem Execute Gradle +"%JAVA_EXE%" %DEFAULT_JVM_OPTS% %JAVA_OPTS% %GRADLE_OPTS% "-Dorg.gradle.appname=%APP_BASE_NAME%" -jar "%APP_HOME%\gradle\wrapper\gradle-wrapper.jar" %* + +:end +@rem End local scope for the variables with windows NT shell +if %ERRORLEVEL% equ 0 goto mainEnd + +:fail +rem Set variable GRADLE_EXIT_CONSOLE if you need the _script_ return code instead of +rem the _cmd.exe /c_ return code! +set EXIT_CODE=%ERRORLEVEL% +if %EXIT_CODE% equ 0 set EXIT_CODE=1 +if not ""=="%GRADLE_EXIT_CONSOLE%" exit %EXIT_CODE% +exit /b %EXIT_CODE% + +:mainEnd +if "%OS%"=="Windows_NT" endlocal + +:omega diff --git a/settings.gradle b/settings.gradle new file mode 100644 index 0000000..94b0e93 --- /dev/null +++ b/settings.gradle @@ -0,0 +1 @@ +rootProject.name = 'specialsource-homepage-backend' diff --git a/src/main/java/company/specialsource/SpecialsourceHomepageApplication.java b/src/main/java/company/specialsource/SpecialsourceHomepageApplication.java new file mode 100644 index 0000000..a633f36 --- /dev/null +++ b/src/main/java/company/specialsource/SpecialsourceHomepageApplication.java @@ -0,0 +1,13 @@ +package company.specialsource; + +import org.springframework.boot.SpringApplication; +import org.springframework.boot.autoconfigure.SpringBootApplication; + +@SpringBootApplication +public class SpecialsourceHomepageApplication { + + public static void main(String[] args) { + SpringApplication.run(SpecialsourceHomepageApplication.class, args); + } + +} diff --git a/src/main/java/company/specialsource/config/DataInitializer.java b/src/main/java/company/specialsource/config/DataInitializer.java new file mode 100644 index 0000000..f8361a4 --- /dev/null +++ b/src/main/java/company/specialsource/config/DataInitializer.java @@ -0,0 +1,32 @@ +package company.specialsource.config; + +import company.specialsource.entity.User; +import company.specialsource.repository.UserRepository; +import lombok.RequiredArgsConstructor; +import lombok.extern.slf4j.Slf4j; // 로그를 위해 추가 +import org.springframework.boot.CommandLineRunner; +import org.springframework.security.crypto.password.PasswordEncoder; +import org.springframework.stereotype.Component; + +@Component +@RequiredArgsConstructor +@Slf4j // 로그 라이브러리 +public class DataInitializer implements CommandLineRunner { + + private final UserRepository userRepository; + private final PasswordEncoder passwordEncoder; + + @Override + public void run(String... args) { + if (userRepository.findByUsername("admin").isEmpty()) { + userRepository.save(User.builder() + .username("admin") + .password(passwordEncoder.encode("1234")) + .role("ROLE_USER") + .build()); + log.info("초기 관리자 계정(admin)이 생성되었습니다."); + } else { + log.info("이미 관리자 계정이 존재합니다."); + } + } +} \ No newline at end of file diff --git a/src/main/java/company/specialsource/config/JasyptConfig.java b/src/main/java/company/specialsource/config/JasyptConfig.java new file mode 100644 index 0000000..5551c76 --- /dev/null +++ b/src/main/java/company/specialsource/config/JasyptConfig.java @@ -0,0 +1,33 @@ +package company.specialsource.config; + +import com.ulisesbocchio.jasyptspringboot.annotation.EnableEncryptableProperties; +import org.jasypt.encryption.StringEncryptor; +import org.jasypt.encryption.pbe.PooledPBEStringEncryptor; +import org.jasypt.encryption.pbe.config.SimpleStringPBEConfig; +import org.springframework.beans.factory.annotation.Value; +import org.springframework.context.annotation.Bean; +import org.springframework.context.annotation.Configuration; + +@Configuration +@EnableEncryptableProperties +public class JasyptConfig { + + @Value("${jasypt.encryptor.password}") + private String password; + + @Bean("jasyptStringEncryptor") + public StringEncryptor stringEncryptor() { + PooledPBEStringEncryptor encryptor = new PooledPBEStringEncryptor(); + SimpleStringPBEConfig config = new SimpleStringPBEConfig(); + config.setPassword(password); // 암호화 키 (절대 외부에 유출 금지!) + config.setAlgorithm("PBEWithMD5AndDES"); + config.setKeyObtentionIterations("1000"); + config.setPoolSize("1"); + config.setProviderName("SunJCE"); + config.setSaltGeneratorClassName("org.jasypt.salt.RandomSaltGenerator"); + config.setIvGeneratorClassName("org.jasypt.iv.NoIvGenerator"); + config.setStringOutputType("base64"); + encryptor.setConfig(config); + return encryptor; + } +} \ No newline at end of file diff --git a/src/main/java/company/specialsource/config/SecurityConfig.java b/src/main/java/company/specialsource/config/SecurityConfig.java new file mode 100644 index 0000000..f07efe9 --- /dev/null +++ b/src/main/java/company/specialsource/config/SecurityConfig.java @@ -0,0 +1,31 @@ +package company.specialsource.config; + +import org.springframework.context.annotation.Bean; +import org.springframework.context.annotation.Configuration; +import org.springframework.security.config.annotation.web.builders.HttpSecurity; +import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity; +import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder; +import org.springframework.security.crypto.password.PasswordEncoder; +import org.springframework.security.web.SecurityFilterChain; + +@Configuration +@EnableWebSecurity +public class SecurityConfig { + + @Bean + public SecurityFilterChain filterChain(HttpSecurity http) throws Exception { + http + .csrf(csrf -> csrf.disable()) // REST API 통신을 위해 CSRF 비활성화 + .authorizeHttpRequests(auth -> auth + .requestMatchers("/api/login").permitAll() // 로그인 API는 누구나 접근 가능 + .anyRequest().authenticated() + ); + return http.build(); + } + + + @Bean + public PasswordEncoder passwordEncoder() { + return new BCryptPasswordEncoder(); // BCrypt 암호화 알고리즘 사용 + } +} \ No newline at end of file diff --git a/src/main/java/company/specialsource/controller/AuthController.java b/src/main/java/company/specialsource/controller/AuthController.java new file mode 100644 index 0000000..0eef7d3 --- /dev/null +++ b/src/main/java/company/specialsource/controller/AuthController.java @@ -0,0 +1,26 @@ +package company.specialsource.controller; + +import company.specialsource.dto.LoginRequest; +import company.specialsource.service.UserService; +import lombok.RequiredArgsConstructor; +import org.springframework.http.ResponseEntity; +import org.springframework.web.bind.annotation.*; + +@RestController +@RequestMapping("/api") +@RequiredArgsConstructor +public class AuthController { + + private final UserService userService; + + @PostMapping("/login") + public ResponseEntity login(@RequestBody LoginRequest loginRequest) { + boolean isSuccess = userService.login(loginRequest.getUsername(), loginRequest.getPassword()); + + if (isSuccess) { + return ResponseEntity.ok("로그인 성공!"); + } else { + return ResponseEntity.status(401).body("아이디 또는 비밀번호가 틀렸습니다."); + } + } +} \ No newline at end of file diff --git a/src/main/java/company/specialsource/dto/LoginRequest.java b/src/main/java/company/specialsource/dto/LoginRequest.java new file mode 100644 index 0000000..8a44b88 --- /dev/null +++ b/src/main/java/company/specialsource/dto/LoginRequest.java @@ -0,0 +1,10 @@ +package company.specialsource.dto; + +import lombok.Getter; +import lombok.Setter; + +@Getter @Setter +public class LoginRequest { + private String username; + private String password; +} \ No newline at end of file diff --git a/src/main/java/company/specialsource/entity/User.java b/src/main/java/company/specialsource/entity/User.java new file mode 100644 index 0000000..4fd32c1 --- /dev/null +++ b/src/main/java/company/specialsource/entity/User.java @@ -0,0 +1,25 @@ +package company.specialsource.entity; + +import jakarta.persistence.*; +import lombok.*; + +@Entity +@Table(name = "users") // PostgreSQL에서 'user'는 예약어이므로 'users' 테이블 명칭 권장 +@Getter +@NoArgsConstructor(access = AccessLevel.PROTECTED) +@AllArgsConstructor +@Builder +public class User { + + @Id + @GeneratedValue(strategy = GenerationType.IDENTITY) + private Long id; + + @Column(unique = true, nullable = false) + private String username; + + @Column(nullable = false) + private String password; + + private String role; // 예: ROLE_USER, ROLE_ADMIN +} \ No newline at end of file diff --git a/src/main/java/company/specialsource/repository/UserRepository.java b/src/main/java/company/specialsource/repository/UserRepository.java new file mode 100644 index 0000000..d17256a --- /dev/null +++ b/src/main/java/company/specialsource/repository/UserRepository.java @@ -0,0 +1,10 @@ +package company.specialsource.repository; + +import company.specialsource.entity.User; +import org.springframework.data.jpa.repository.JpaRepository; +import java.util.Optional; + +public interface UserRepository extends JpaRepository { + // 사용자 아이디로 정보를 찾아오는 메서드 + Optional findByUsername(String username); +} \ No newline at end of file diff --git a/src/main/java/company/specialsource/service/UserService.java b/src/main/java/company/specialsource/service/UserService.java new file mode 100644 index 0000000..0e3ecbb --- /dev/null +++ b/src/main/java/company/specialsource/service/UserService.java @@ -0,0 +1,28 @@ +package company.specialsource.service; + +import company.specialsource.entity.User; +import company.specialsource.repository.UserRepository; +import lombok.RequiredArgsConstructor; +import org.springframework.security.crypto.password.PasswordEncoder; +import org.springframework.stereotype.Service; + +import java.util.Optional; + +@Service +@RequiredArgsConstructor +public class UserService { + + private final UserRepository userRepository; + private final PasswordEncoder passwordEncoder; + + public boolean login(String username, String password) { + Optional userOptional = userRepository.findByUsername(username); + + if (userOptional.isPresent()) { + User user = userOptional.get(); + // DB의 암호화된 비번과 입력받은 평문 비번 비교 + return passwordEncoder.matches(password, user.getPassword()); + } + return false; + } +} \ No newline at end of file diff --git a/src/main/resources/application.yaml b/src/main/resources/application.yaml new file mode 100644 index 0000000..45ec844 --- /dev/null +++ b/src/main/resources/application.yaml @@ -0,0 +1,18 @@ +spring: + datasource: + url: jdbc:postgresql://192.168.0.215:5435/mydb + username: headporter + password: ENC(Gg03NzjjcVOrFSXoBrPEusNgDNbYOPO4) + driver-class-name: org.postgresql.Driver + + jpa: + hibernate: + ddl-auto: update # 테이블 자동 생성 + show-sql: true # SQL 로그 출력 + properties: + hibernate: + format_sql: true + +jasypt: + encryptor: + password: 81sungjin1015 \ No newline at end of file diff --git a/src/main/resources/setJasyptEncryptorPassword.ps1 b/src/main/resources/setJasyptEncryptorPassword.ps1 new file mode 100644 index 0000000..6f4bb84 --- /dev/null +++ b/src/main/resources/setJasyptEncryptorPassword.ps1 @@ -0,0 +1,2 @@ +$env:JASYPT_ENCRYPTOR_PASSWORD="81sungjin1015" +./gradlew bootRun