Hamutaro - Hamtaro 4

JWT 1

[Spring] JWT (JSON Web Token)

JWT ๋ž€?JSON Web Token, JSON ๊ฐ์ฒด๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ์ „์†กํ•˜๊ธฐ ์œ„ํ•œ ํ† ํฐ ๊ธฐ๋ฐ˜ ์ธ์ฆ ๋ฐฉ์‹์ž๊ธฐ ํฌํ•จ (Self-contained) : ํ† ํฐ์•ˆ์— ์œ ์ € ์ •๋ณด๋‚˜ ๊ถŒํ•œ ๊ฐ™์€ ํ•„์š”ํ•œ ์ •๋ณด๋ฅผ ์ง์ ‘ ๋‹ด๊ณ  ์žˆ์–ด์„œ ๋ณ„๋„์˜ ์„ธ์…˜ ์ €์žฅ์†Œ๊ฐ€ ํ•„์š”์—†์Œ์„œ๋ช… (Signature) : ํ† ํฐ์€ ์„œ๋ช…๋˜์–ด ์žˆ์–ด์„œ ๋‚ด์šฉ์ด ์œ„์กฐ๋˜์ง€ ์•Š์•˜๋Š”์ง€ ๊ฒ€์ฆ์ด ๊ฐ€๋Šฅํ•จStateless : ์„œ๋ฒ„๋Š” ํด๋ผ์ด์–ธํŠธ์˜ ์ƒํƒœ๋ฅผ ์œ ์ง€ํ•  ํ•„์š”์—†์ด ํ† ํฐ๋งŒ ํ™•์ธํ•˜๋ฉด ๋จ JWT ๊ตฌ์กฐHeader : ํ† ํฐ์˜ ํƒ€์ž…๊ณผ ํ•ด์‹ฑ ์•Œ๊ณ ๋ฆฌ์ฆ˜ (ex : HS256)Payload : ์œ ์ € ์ •๋ณด ๋ฐ ํด๋ ˆ์ž„(claims)์ด ํฌํ•จ๋˜๋Š” ๋ฐ์ดํ„ฐ (ex : sub, name, exp ๋“ฑ)Signature : ํ—ค๋”์™€ ํŽ˜์ด๋กœ๋“œ๋ฅผ ๋น„๋ฐ€ํ‚ค๋กœ ํ•ด์‹ฑํ•œ ์„œ๋ช… JWT util class ์˜ˆ์ œimport io.j..

Backend/Spring 2025.02.18