WEBBOOK CHAPTER

Spring Security 6, 인증에서 운영까지: 5장. Authentication이 만들어지는 경로를 이해한다

5장. Authentication이 만들어지는 경로를 이해한다

인증 구조의 핵심은 SecurityContextHolder, SecurityContext, Authentication, AuthenticationManager, ProviderManager, AuthenticationProvider다. 공식 인증 구조Authentication이 인증 전 자격 증명의 입력이면서 인증 뒤 현재 사용자를 나타낸다고 설명한다.

Spring Security 인증 구성 요소의 흐름
Spring Security 인증 구성 요소의 흐름

principal은 사용자 식별, credentials는 보통 비밀번호 같은 비밀, authorities는 역할과 scope 같은 고수준 권한이다. 성공 뒤 credentials를 지우는 기본 동작을 우회하지 않는다. 캐시된 UserDetails의 비밀번호가 같이 지워져 재인증이 실패한다면 캐시 모델을 복사하거나 경계를 다시 설계한다.


Authentication authentication = SecurityContextHolder.getContext().getAuthentication();
String subject = authentication.getName();
Collection<? extends GrantedAuthority> authorities = authentication.getAuthorities();

업무 코드는 가능하면 정적 holder를 직접 읽기보다 controller의 @AuthenticationPrincipal, service method의 Authentication 또는 도메인용 Actor로 변환해 받는다. 그러면 테스트에 전역 상태가 덜 새고 비동기 경계가 드러난다. thread pool에 context를 무작정 전달하면 다른 작업에 신원이 누출될 수 있다.