Hamutaro - Hamtaro 4

Backend/Spring

[Spring] Bearer ํ† ํฐ ์ธ์ฆ ๊ตฌ์กฐ ์ดํ•ดํ•˜๊ธฐ

carsumin 2026. 2. 11. 15:19
Bearer
  • HTTP ์ธ์ฆ ๋ฐฉ์‹ ์ค‘ ํ•˜๋‚˜

HTTP ์š”์ฒญ ํ—ค๋”

Authorization: Bearer {accessToken}
  • Authorization : ์ธ์ฆ ์ •๋ณด๋ฅผ ๋‹ด๋Š” ํ—ค๋”
  • Bearer : ์ธ์ฆ ๋ฐฉ์‹ (Type)
  • {accessToken} : ์‹ค์ œ ์ธ์ฆ ํ† ํฐ

 

์™œ Bearer ๋ผ๊ณ  ๋ถ€๋ฅด๋Š”๊ฐ€
  • Bearer์€ ์ง์—ญํ•˜๋ฉด '์†Œ์ง€์ž' ๋ผ๋Š” ๋œป
  • ์ด ํ† ํฐ์„ ์†Œ์ง€ํ•˜๊ณ  ์žˆ๋Š” ์‚ฌ๋žŒ์€ ์ธ์ฆ๋œ ์‚ฌ์šฉ์ž๋กœ ๊ฐ„์ฃผ
  • ์„œ๋ฒ„๋Š” ํ† ํฐ์„ ๋ˆ„๊ฐ€ ๋“ค๊ณ  ์™”๋Š”์ง€ ํ™•์ธํ•˜์ง€ ์•Š์Œ
    • ํ† ํฐ ์„œ๋ช…์ด ์œ ํšจํ•œ์ง€
    • ํ† ํฐ์ด ๋งŒ๋ฃŒ๋˜์ง€ ์•Š์•˜๋Š”์ง€
    • ํ•„์š”ํ•œ ํด๋ ˆ์ž„์ด ํฌํ•จ๋˜์–ด ์žˆ๋Š”์ง€

 

Bearer ์ธ์ฆ ๋ฐฉ์‹ ํŠน์ง•
  • Stateless
    • ์„œ๋ฒ„๋Š” ์„ธ์…˜์„ ์ €์žฅํ•˜์ง€ ์•Š์Œ
    • ํ† ํฐ ์ž์ฒด์— ์‚ฌ์šฉ์ž ์ •๋ณด๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์Œ
  • ๋‹จ์ˆœ ๊ตฌ์กฐ
    • ์„œ๋ฒ„๋Š” ๋งค ์š”์ฒญ๋งˆ๋‹ค ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํ๋ฆ„์œผ๋กœ ๋™์ž‘
      • Authorization ํ—ค๋” ์ถ”์ถœ
      • Bearer ์ œ๊ฑฐ
      • ํ† ํฐ ๊ฒ€์ฆ
      • SecurityContext ์„ค์ •
  • ํ† ํฐ ์†Œ์ง€ ๊ธฐ๋ฐ˜ ์ธ์ฆ
    • Bearer ๋ฐฉ์‹์€ ํ† ํฐ์ด ์œ ํšจํ•œ์ง€๋งŒ ํŒ๋‹จ
    • ํ† ํฐ ํƒˆ์ทจ์— ์ทจ์•ฝํ•  ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์— HTTPS ์‚ฌ์šฉ์ด ํ•„์ˆ˜