Task 5 Report: 토큰 인증 인터셉터 + 매핑 + 시큐리티 예외#
Files Changed#
Created#
src/main/java/itn/com/cmm/interceptor/DashboardApiAuthInterceptor.java
Modified#
src/main/webapp/WEB-INF/config/egovframework/springmvc/egov-interceptor-servlet.xmlsrc/main/resources/egovframework/spring/com/context-security.xml
XML Snippets Added#
egov-interceptor-servlet.xml — inside <interceptors>, first position#
<!-- 대시보드 요약 API 토큰 인증 -->
<interceptor>
<mapping path="/api/dashboard/**"/>
<beans:bean class="itn.com.cmm.interceptor.DashboardApiAuthInterceptor"/>
</interceptor>
Style mirrors existing interceptors: <interceptor>/<mapping> are in the default mvc namespace; the bean uses the beans: prefix as <beans:bean>, matching InterceptorHandler and IPIgnoreInterceptorHandler.
context-security.xml — after existing security="none" entries (line 16)#
<security:http pattern="/api/dashboard/**" security="none"/>
Placed immediately after the \A/WEB-INF/jsp/.*\Z regex entry, before <egov-security:config>.
@Value / globalSettings Pattern Verification#
Reference file: src/main/java/itn/let/mjo/api/sms/web/ApiSmsTestMsgController.java line 32:
@Value("#{globalSettings['Globals.api.ip']}")
private String API_IP;
The new interceptor uses:
@Value("#{globalSettings['Globals.dashboard.api.token']}")
private String apiToken;
Identical SpEL pattern #{globalSettings['<key>']}. The globalSettings bean is defined in context-properties.xml and is available in the dispatcher servlet context (interceptors are registered there and Spring injects @Value into interceptor beans declared via <beans:bean> in the servlet context). Pattern confirmed to match the reference.
XML Well-Formedness Confirmation#
egov-interceptor-servlet.xml#
- Root element:
<beans:beans>(line 2) — closed at line 40</beans:beans>. Balanced. <interceptors>(line 10) — closed at line 38</interceptors>. Balanced.- New
<interceptor>block (lines 11-15):<mapping/>self-closing,<beans:bean/>self-closing,</interceptor>closes. Balanced. - Namespaces:
mvcdefault,beans:prefix. New snippet uses correct prefixes.
context-security.xml#
- Root element:
<beans>(line 2) — closed at line 95 (original line 95)</beans>. Balanced. - New entry is a self-closing
<security:http ... />element using the already-declaredsecurity:namespace. Well-formed.
Commit Short Hash#
(See below — recorded after commit)
Concerns / Notes#
@Value injection into interceptor: Spring injects
@Valueinto interceptor beans only when the bean is instantiated by the application context (i.e., declared as<beans:bean>in the servlet XML). This pattern is consistent with how the project already declares interceptor beans inegov-interceptor-servlet.xml.IPIgnoreInterceptorHandler also matches
/api/dashboard/**: The/**mapping interceptor still runs on this path. That interceptor only logs specific URI patterns (errorLogInsert,*Ajax.do, etc.) and will not block the API flow.mvn/curl verification deferred: Plan Steps 4-6 (mvn clean package, mvn tomcat7:run, curl 401/200 checks) could NOT be run in this environment — mvn and curl are not available. Verification was performed statically: file content read-back, XML tag balance check, @Value pattern cross-reference. Runtime verification must be performed by the developer in IntelliJ (Run → Deploy, then manual curl or browser test).
Token value:
globals_local.properties/globals_dev.properties/globals_prod.propertiesall containGlobals.dashboard.api.token=CHANGE_ME_TOKEN. Replace with a real secret before deploying to production.