Skip to content

Commit 1ef3bc9

Browse files
authored
Merge pull request #347 from MT-TEAM-Org/epic/inquirymail
Epic/inquirymail
2 parents 49fc0f9 + f4bc5b3 commit 1ef3bc9

2 files changed

Lines changed: 23 additions & 8 deletions

File tree

‎src/main/java/org/myteam/server/global/security/filter/JwtAuthenticationFilter.java‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -176,14 +176,14 @@ protected void unsuccessfulAuthentication(HttpServletRequest request, HttpServle
176176
if (redisService.isAdminLoginAllowed("LOGIN_ADMIN", username)) {
177177
int count = redisService.getRequestCount("LOGIN_ADMIN", username);
178178
sendErrorResponse(response, HttpStatus.UNAUTHORIZED,
179-
"아이디 또는 비밀번호를 확인해주세요(%s/10)".formatted(String.valueOf(10 - count)));
179+
"아이디 또는 비밀번호를 확인해주세요. (%s/10)".formatted(String.valueOf(count)));
180180
return;
181181
}
182182
int count = redisService.getRequestCount("LOGIN_ADMIN", username);
183183
if (count >= 10) {
184184
eventPublisher.publishEvent(new AdminBanEvent(username, ClientUtils.getRemoteIP(request)));
185185
}
186-
sendErrorResponse(response, HttpStatus.UNAUTHORIZED, "해당 아이디 로그인 시도가 10번 불일치하여" +
186+
sendErrorResponse(response, HttpStatus.UNAUTHORIZED, "해당 아이디 로그인 시도가 10번 불일치하여\n" +
187187
"계정이 잠금되었습니다.");
188188
return;
189189
}

‎src/main/java/org/myteam/server/global/util/redis/service/RedisService.java‎

Lines changed: 21 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@
1616
public class RedisService { // TODO: RedisReportService 로 변경.
1717

1818
private final RedisTemplate<String, String> redisTemplate;
19-
19+
private static final String ADMIN_ALARM_KEY="ADMIN_ALARM";
2020
private static final int ADMIN_LOGIN_MAX_REQUESTS=10;
2121
private static final int MAX_REQUESTS = 3; // 제한 횟수 (기본값: 5분 동안 3회)
2222
private static final long EXPIRED_TIME = 5L; // 만료 시간 (5분)
@@ -63,8 +63,8 @@ public boolean isAdminLoginAllowed(String category,String identifier){
6363
String redisKey = getRateLimitKey(category, identifier);
6464
String requestCountStr = redisTemplate.opsForValue().get(redisKey);
6565
int requestCount = requestCountStr == null ? 0 : Integer.parseInt(requestCountStr);
66-
67-
if (requestCount >= ADMIN_LOGIN_MAX_REQUESTS) {
66+
requestCount+=1;
67+
if (0>=(ADMIN_LOGIN_MAX_REQUESTS-requestCount)) {
6868
log.warn("🚫 [RateLimit] 관리자 요청 차단 - Key: {}, 요청 횟수: {}", redisKey, requestCount);
6969
return false;
7070
}
@@ -75,7 +75,6 @@ public boolean isAdminLoginAllowed(String category,String identifier){
7575
return true;
7676

7777
}
78-
7978
public boolean AdminReadCheck(String category, String adminIdentifier, StaticDataType staticDataType, Long contentId){
8079

8180
String redisKey=getRateLimitKey(category,adminIdentifier+staticDataType.name()+String.valueOf(contentId));
@@ -96,8 +95,24 @@ public void adminReadCheckUpdate(String category, String adminIdentifier, Static
9695
redisTemplate.expire(redisKey, Duration.ofMinutes(ADMIN_ALARM_READ_EXPIRE_TIME));
9796
}
9897
}
99-
100-
98+
/*public boolean AdminReadCheck(String adminIdentifier, StaticDataType staticDataType, Long contentId){
99+
String redisKey=ADMIN_ALARM_KEY+adminIdentifier+staticDataType.name()+String.valueOf(contentId);
100+
String requestCountStr=redisTemplate.opsForValue().get(redisKey);
101+
int requestCount = requestCountStr == null ? 0 : Integer.parseInt(requestCountStr);
102+
if(requestCount==0){
103+
return false;
104+
}
105+
return true;
106+
}
107+
public void adminReadCheckUpdate(String adminIdentifier, StaticDataType staticDataType, Long contentId){
108+
String redisKey=ADMIN_ALARM_KEY+adminIdentifier+staticDataType.name()+String.valueOf(contentId);
109+
String requestCountStr=redisTemplate.opsForValue().get(redisKey);
110+
int requestCount = requestCountStr == null ? 0 : Integer.parseInt(requestCountStr);
111+
if(requestCount==0) {
112+
redisTemplate.opsForValue().increment(redisKey);
113+
redisTemplate.expire(redisKey, Duration.ofDays(30L));
114+
}
115+
}*/
101116
/**
102117
* 요청 제한을 적용할 Redis Key 생성
103118
*

0 commit comments

Comments
 (0)