diff --git a/src/main/java/me/thinkcat/opic/practice/config/security/JwtTokenProvider.java b/src/main/java/me/thinkcat/opic/practice/config/security/JwtTokenProvider.java index 2e0f007..7fe7d89 100644 --- a/src/main/java/me/thinkcat/opic/practice/config/security/JwtTokenProvider.java +++ b/src/main/java/me/thinkcat/opic/practice/config/security/JwtTokenProvider.java @@ -10,6 +10,7 @@ import javax.crypto.SecretKey; import java.nio.charset.StandardCharsets; import java.util.Date; +import java.util.UUID; @Component public class JwtTokenProvider { @@ -51,6 +52,7 @@ private String buildToken(String username, Long userId, UserRole role, long vali Date validity = new Date(now.getTime() + validityInMilliseconds); JwtBuilder builder = Jwts.builder() + .id(UUID.randomUUID().toString()) .subject(username) .claim("userId", userId) .issuedAt(now) diff --git a/src/main/java/me/thinkcat/opic/practice/repository/RefreshTokenRepository.java b/src/main/java/me/thinkcat/opic/practice/repository/RefreshTokenRepository.java index 0b6a16a..1c784e4 100644 --- a/src/main/java/me/thinkcat/opic/practice/repository/RefreshTokenRepository.java +++ b/src/main/java/me/thinkcat/opic/practice/repository/RefreshTokenRepository.java @@ -2,8 +2,12 @@ import me.thinkcat.opic.practice.entity.RefreshToken; import org.springframework.data.jpa.repository.JpaRepository; +import org.springframework.data.jpa.repository.Modifying; +import org.springframework.data.jpa.repository.Query; +import org.springframework.data.repository.query.Param; import org.springframework.stereotype.Repository; +import java.time.LocalDateTime; import java.util.Optional; @Repository @@ -14,4 +18,8 @@ public interface RefreshTokenRepository extends JpaRepository tokens = new HashSet<>(); + for (int i = 0; i < 100; i++) { + tokens.add(jwtTokenProvider.generateRefreshToken("user", 1L)); + } + + assertThat(tokens).hasSize(100); + } +} diff --git a/src/test/java/me/thinkcat/opic/practice/service/UserServiceTest.java b/src/test/java/me/thinkcat/opic/practice/service/UserServiceTest.java index b0733ea..f1a3259 100644 --- a/src/test/java/me/thinkcat/opic/practice/service/UserServiceTest.java +++ b/src/test/java/me/thinkcat/opic/practice/service/UserServiceTest.java @@ -1,8 +1,11 @@ package me.thinkcat.opic.practice.service; import me.thinkcat.opic.practice.config.security.JwtTokenProvider; +import me.thinkcat.opic.practice.dto.request.LoginRequest; import me.thinkcat.opic.practice.dto.request.UserRegisterRequest; +import me.thinkcat.opic.practice.dto.response.TokenResponse; import me.thinkcat.opic.practice.dto.response.UserResponse; +import me.thinkcat.opic.practice.entity.RefreshToken; import me.thinkcat.opic.practice.entity.User; import me.thinkcat.opic.practice.exception.ValidationException; import me.thinkcat.opic.practice.repository.UserRepository; @@ -17,6 +20,7 @@ import org.springframework.security.crypto.password.PasswordEncoder; import java.time.LocalDateTime; +import java.util.Optional; import static org.assertj.core.api.Assertions.assertThat; import static org.assertj.core.api.Assertions.assertThatThrownBy; @@ -62,6 +66,25 @@ class UserServiceTest { assertThat(response.getUsername()).isEqualTo("user"); } + @Test + void 동일_사용자_연속_두번_로그인시_서로다른_refreshToken_반환() { + User user = User.builder().id(1L).username("user").build(); + RefreshToken firstToken = RefreshToken.builder().token("refresh-token-aaa").build(); + RefreshToken secondToken = RefreshToken.builder().token("refresh-token-bbb").build(); + + given(userRepository.findByUsername("user")).willReturn(Optional.of(user)); + given(jwtTokenProvider.generateAccessToken(any(), any(), any())).willReturn("access-token"); + given(jwtTokenProvider.getAccessTokenValidityInSeconds()).willReturn(3600L); + given(refreshTokenService.createRefreshToken(user)) + .willReturn(firstToken) + .willReturn(secondToken); + + TokenResponse response1 = userService.login(new LoginRequest("user", "Password1@")); + TokenResponse response2 = userService.login(new LoginRequest("user", "Password1@")); + + assertThat(response1.getRefreshToken()).isNotEqualTo(response2.getRefreshToken()); + } + @ParameterizedTest @ValueSource(strings = { "notanemail",