Skip to content

[Feat/#86] KConnect OAuth 클라이언트 구현 - #91

Open
tnals0924 wants to merge 1 commit into
feat/#84-member-oauth-profilefrom
feat/#86-kconnect-client
Open

tnals0924 wants to merge 1 commit into
feat/#84-member-oauth-profilefrom
feat/#86-kconnect-client

Conversation

@tnals0924

@tnals0924 tnals0924 commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

#️⃣연관된 이슈

🎯 해결하려는 문제가 무엇인가요?

OAuthClient의 KConnect(국민대 학생용 OAuth) 구현체를 추가합니다.

❓ 왜 해결해야 하나요?

국민대 학생 로그인 수단이 KConnect입니다. 또 KConnect 측에서 API 명세를 공개하지 말아 달라고 요청해서, 주소·경로·응답 필드를 코드에 두지 않아야 합니다(이 저장소는 public).

⭐ 어떻게 해결했나요?

  • 흐름: 토큰 교환(authorization code + PKCE code verifier + client secret, form) → 사용자 정보 조회(Bearer) → 응답 JSON에서 설정된 필드 이름으로 값 추출
  • 명세는 전부 환경 변수(oauth.kconnect.*): 코드에는 범용 "code 교환 + JSON 매핑"만 남았습니다. .env.example에는 자리표시자만 있고 실제 값은 팀 내부 문서에 있습니다.
  • 타임아웃: 연결 3초, 응답 5초 (KConnectClientConfig의 RestClient 빈)
  • 에러 매핑
    • invalid_grant(code 만료·재사용·verifier 불일치) → 401 INVALID_AUTHORIZATION_CODE
    • invalid_client 등 그 밖의 4xx → IllegalStateException → 500 + error 로그(서버 설정 오류라 알아야 함)
    • 5xx·연결 실패·타임아웃 → 502 OAUTH_PROVIDER_UNAVAILABLE
  • 토큰 교환은 재시도하지 않습니다(code는 1회용).
  • code·verifier·access token·client secret은 로그와 예외 메시지에 남기지 않습니다.
  • 필수 설정이 비어 있으면 기동은 되고 warn 로그에 빠진 키 이름만 남깁니다. 이 상태에서 로그인하면 500입니다.

🧩 이 PR의 한계 & 트레이드오프

  • 응답 필드 이름이 문자열 설정이라 오타를 컴파일러가 잡지 못합니다. 누락만 검사합니다.
  • provider access token은 저장하지 않습니다. KConnect API를 다시 불러야 하는 기능이 생기면 그때 검토합니다.
  • 실제 KConnect와의 end-to-end는 dev 배포 후 확인이 필요합니다. 로컬에서는 목 서버로 매핑·에러 매핑을 확인했습니다.

⛓️ 기존 기능에 미치는 영향

  • infrastructure:client가 core:domain:auth에 의존합니다.
  • 새 환경 변수 KCONNECT_*를 Coolify dev/prod에 등록해야 합니다(.env.example 참고). 등록하지 않아도 기동은 됩니다.

🔀 Edge Case & 실패 시나리오

  • 사용자 정보 응답에 고유 ID가 없거나 응답이 비어 있으면 500
  • 방금 받은 토큰으로 사용자 정보 조회가 4xx면 scope·경로 설정 문제로 보고 500

📋 검토한 대안과 선택 이유

  • KConnect 연동만 별도 private 레포로 분리: 배포 이미지가 public이라 디컴파일하면 보이고, 포트 배포·CI 토큰·권한 없는 팀원 빌드 문제로 복잡도가 커서 설정 주입 방식을 택했습니다.
  • 응답을 record로 역직렬화: 필드 이름이 코드에 남아 제외했습니다.

💬 리뷰 포인트

  • 에러 매핑과 설정 누락 처리 방식
  • 명세(주소·경로·필드 이름)가 코드·주석·설정 기본값에 남지 않았는지

@tnals0924 tnals0924 self-assigned this Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

🗂️ Base branches to auto review (1)
  • main

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: billilge/stream-server/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 87e11972-ff94-4bf6-8c80-8691c68aedc7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant