fix: 코드 리뷰 기반 전체 개선 — 보안, 품질, UX
All checks were successful
Client CI/CD / deploy (push) Successful in 30s

- refreshToken 중복 로직 일원화 (동시 호출 방지 포함)
- 파일 업로드 401 시 토큰 갱신 후 재시도 추가
- XHR JSON.parse 에러 보호
- index.html lang="ko", title "One of the plans" 변경
- Vite 기본 에셋(vite.svg, react.svg) 및 빈 App.css 제거
- 공지 CRUD API 레이어 분리 (AnnouncementAdmin → announcements.js)
- load 함수 useCallback 적용 및 useEffect 의존성 정상화
- 로딩/빈 목록 상태 표시 추가 (AnnouncementBoard, UserAdmin)
- 누락 CSS 정의 추가 (announcement-error, announcement-empty)
- 로그인/회원가입 빈 필드 클라이언트 검증 추가
- 공지 등록 시 빈 제목/내용 에러 피드백 추가

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-03-12 14:37:05 +09:00
parent c2e3be491d
commit 97453b1d81
17 changed files with 162 additions and 77 deletions

View File

@@ -1,10 +1,9 @@
<!doctype html>
<html lang="en">
<html lang="ko">
<head>
<meta charset="UTF-8" />
<link rel="icon" type="image/svg+xml" href="/vite.svg" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<title>a301_client</title>
<title>One of the plans</title>
</head>
<body>
<div id="root"></div>

View File

@@ -1 +0,0 @@
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" class="iconify iconify--logos" width="31.88" height="32" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 257"><defs><linearGradient id="IconifyId1813088fe1fbc01fb466" x1="-.828%" x2="57.636%" y1="7.652%" y2="78.411%"><stop offset="0%" stop-color="#41D1FF"></stop><stop offset="100%" stop-color="#BD34FE"></stop></linearGradient><linearGradient id="IconifyId1813088fe1fbc01fb467" x1="43.376%" x2="50.316%" y1="2.242%" y2="89.03%"><stop offset="0%" stop-color="#FFEA83"></stop><stop offset="8.333%" stop-color="#FFDD35"></stop><stop offset="100%" stop-color="#FFA800"></stop></linearGradient></defs><path fill="url(#IconifyId1813088fe1fbc01fb466)" d="M255.153 37.938L134.897 252.976c-2.483 4.44-8.862 4.466-11.382.048L.875 37.958c-2.746-4.814 1.371-10.646 6.827-9.67l120.385 21.517a6.537 6.537 0 0 0 2.322-.004l117.867-21.483c5.438-.991 9.574 4.796 6.877 9.62Z"></path><path fill="url(#IconifyId1813088fe1fbc01fb467)" d="M185.432.063L96.44 17.501a3.268 3.268 0 0 0-2.634 3.014l-5.474 92.456a3.268 3.268 0 0 0 3.997 3.378l24.777-5.718c2.318-.535 4.413 1.507 3.936 3.838l-7.361 36.047c-.495 2.426 1.782 4.5 4.151 3.78l15.304-4.649c2.372-.72 4.652 1.36 4.15 3.788l-11.698 56.621c-.732 3.542 3.979 5.473 5.943 2.437l1.313-2.028l72.516-144.72c1.215-2.423-.88-5.186-3.54-4.672l-25.505 4.922c-2.396.462-4.435-1.77-3.759-4.114l16.646-57.705c.677-2.35-1.37-4.583-3.769-4.113Z"></path></svg>

Before

Width:  |  Height:  |  Size: 1.5 KiB

View File

@@ -1 +0,0 @@
/* Global app styles - kept minimal, page-level styles in pages/ */

View File

@@ -3,3 +3,21 @@ import { apiFetch } from './client';
export async function getAnnouncements() {
return apiFetch('/api/announcements');
}
export async function createAnnouncement(title, content) {
return apiFetch('/api/announcements', {
method: 'POST',
body: JSON.stringify({ title, content }),
});
}
export async function updateAnnouncement(id, title, content) {
return apiFetch(`/api/announcements/${id}`, {
method: 'PUT',
body: JSON.stringify({ title, content }),
});
}
export async function deleteAnnouncement(id) {
return apiFetch(`/api/announcements/${id}`, { method: 'DELETE' });
}

View File

@@ -29,25 +29,6 @@ export async function ssafyCallback(code) {
});
}
// 토큰을 리프레시하고 새 access token을 반환
export async function refreshToken() {
const rt = localStorage.getItem('refreshToken');
if (!rt) throw new Error('no_refresh_token');
const res = await fetch(
(import.meta.env.VITE_API_BASE_URL || '') + '/api/auth/refresh',
{
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ refreshToken: rt }),
}
);
if (!res.ok) throw new Error('refresh_failed');
const data = await res.json();
localStorage.setItem('token', data.token);
localStorage.setItem('refreshToken', data.refreshToken);
return data.token;
}
// 토큰을 리프레시하고 새 access token을 반환 (동시 호출 방지 포함)
export { tryRefresh as refreshToken } from './client';

View File

@@ -3,7 +3,7 @@ const BASE = import.meta.env.VITE_API_BASE_URL || '';
// 동시 401 발생 시 refresh를 한 번만 실행하기 위한 Promise 공유
let refreshingPromise = null;
async function tryRefresh() {
export async function tryRefresh() {
if (refreshingPromise) return refreshingPromise;
refreshingPromise = (async () => {
@@ -40,7 +40,7 @@ async function parseError(res) {
try {
const body = await res.json();
if (body.error) message = body.error;
} catch {}
} catch { /* 응답 바디 파싱 실패 시 statusText 사용 */ }
const err = new Error(message);
err.status = res.status;
return err;

View File

@@ -1 +0,0 @@
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" class="iconify iconify--logos" width="35.93" height="32" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 228"><path fill="#00D8FF" d="M210.483 73.824a171.49 171.49 0 0 0-8.24-2.597c.465-1.9.893-3.777 1.273-5.621c6.238-30.281 2.16-54.676-11.769-62.708c-13.355-7.7-35.196.329-57.254 19.526a171.23 171.23 0 0 0-6.375 5.848a155.866 155.866 0 0 0-4.241-3.917C100.759 3.829 77.587-4.822 63.673 3.233C50.33 10.957 46.379 33.89 51.995 62.588a170.974 170.974 0 0 0 1.892 8.48c-3.28.932-6.445 1.924-9.474 2.98C17.309 83.498 0 98.307 0 113.668c0 15.865 18.582 31.778 46.812 41.427a145.52 145.52 0 0 0 6.921 2.165a167.467 167.467 0 0 0-2.01 9.138c-5.354 28.2-1.173 50.591 12.134 58.266c13.744 7.926 36.812-.22 59.273-19.855a145.567 145.567 0 0 0 5.342-4.923a168.064 168.064 0 0 0 6.92 6.314c21.758 18.722 43.246 26.282 56.54 18.586c13.731-7.949 18.194-32.003 12.4-61.268a145.016 145.016 0 0 0-1.535-6.842c1.62-.48 3.21-.974 4.76-1.488c29.348-9.723 48.443-25.443 48.443-41.52c0-15.417-17.868-30.326-45.517-39.844Zm-6.365 70.984c-1.4.463-2.836.91-4.3 1.345c-3.24-10.257-7.612-21.163-12.963-32.432c5.106-11 9.31-21.767 12.459-31.957c2.619.758 5.16 1.557 7.61 2.4c23.69 8.156 38.14 20.213 38.14 29.504c0 9.896-15.606 22.743-40.946 31.14Zm-10.514 20.834c2.562 12.94 2.927 24.64 1.23 33.787c-1.524 8.219-4.59 13.698-8.382 15.893c-8.067 4.67-25.32-1.4-43.927-17.412a156.726 156.726 0 0 1-6.437-5.87c7.214-7.889 14.423-17.06 21.459-27.246c12.376-1.098 24.068-2.894 34.671-5.345a134.17 134.17 0 0 1 1.386 6.193ZM87.276 214.515c-7.882 2.783-14.16 2.863-17.955.675c-8.075-4.657-11.432-22.636-6.853-46.752a156.923 156.923 0 0 1 1.869-8.499c10.486 2.32 22.093 3.988 34.498 4.994c7.084 9.967 14.501 19.128 21.976 27.15a134.668 134.668 0 0 1-4.877 4.492c-9.933 8.682-19.886 14.842-28.658 17.94ZM50.35 144.747c-12.483-4.267-22.792-9.812-29.858-15.863c-6.35-5.437-9.555-10.836-9.555-15.216c0-9.322 13.897-21.212 37.076-29.293c2.813-.98 5.757-1.905 8.812-2.773c3.204 10.42 7.406 21.315 12.477 32.332c-5.137 11.18-9.399 22.249-12.634 32.792a134.718 134.718 0 0 1-6.318-1.979Zm12.378-84.26c-4.811-24.587-1.616-43.134 6.425-47.789c8.564-4.958 27.502 2.111 47.463 19.835a144.318 144.318 0 0 1 3.841 3.545c-7.438 7.987-14.787 17.08-21.808 26.988c-12.04 1.116-23.565 2.908-34.161 5.309a160.342 160.342 0 0 1-1.76-7.887Zm110.427 27.268a347.8 347.8 0 0 0-7.785-12.803c8.168 1.033 15.994 2.404 23.343 4.08c-2.206 7.072-4.956 14.465-8.193 22.045a381.151 381.151 0 0 0-7.365-13.322Zm-45.032-43.861c5.044 5.465 10.096 11.566 15.065 18.186a322.04 322.04 0 0 0-30.257-.006c4.974-6.559 10.069-12.652 15.192-18.18ZM82.802 87.83a323.167 323.167 0 0 0-7.227 13.238c-3.184-7.553-5.909-14.98-8.134-22.152c7.304-1.634 15.093-2.97 23.209-3.984a321.524 321.524 0 0 0-7.848 12.897Zm8.081 65.352c-8.385-.936-16.291-2.203-23.593-3.793c2.26-7.3 5.045-14.885 8.298-22.6a321.187 321.187 0 0 0 7.257 13.246c2.594 4.48 5.28 8.868 8.038 13.147Zm37.542 31.03c-5.184-5.592-10.354-11.779-15.403-18.433c4.902.192 9.899.29 14.978.29c5.218 0 10.376-.117 15.453-.343c-4.985 6.774-10.018 12.97-15.028 18.486Zm52.198-57.817c3.422 7.8 6.306 15.345 8.596 22.52c-7.422 1.694-15.436 3.058-23.88 4.071a382.417 382.417 0 0 0 7.859-13.026a347.403 347.403 0 0 0 7.425-13.565Zm-16.898 8.101a358.557 358.557 0 0 1-12.281 19.815a329.4 329.4 0 0 1-23.444.823c-7.967 0-15.716-.248-23.178-.732a310.202 310.202 0 0 1-12.513-19.846h.001a307.41 307.41 0 0 1-10.923-20.627a310.278 310.278 0 0 1 10.89-20.637l-.001.001a307.318 307.318 0 0 1 12.413-19.761c7.613-.576 15.42-.876 23.31-.876H128c7.926 0 15.743.303 23.354.883a329.357 329.357 0 0 1 12.335 19.695a358.489 358.489 0 0 1 11.036 20.54a329.472 329.472 0 0 1-11 20.722Zm22.56-122.124c8.572 4.944 11.906 24.881 6.52 51.026c-.344 1.668-.73 3.367-1.15 5.09c-10.622-2.452-22.155-4.275-34.23-5.408c-7.034-10.017-14.323-19.124-21.64-27.008a160.789 160.789 0 0 1 5.888-5.4c18.9-16.447 36.564-22.941 44.612-18.3ZM128 90.808c12.625 0 22.86 10.235 22.86 22.86s-10.235 22.86-22.86 22.86s-22.86-10.235-22.86-22.86s10.235-22.86 22.86-22.86Z"></path></svg>

Before

Width:  |  Height:  |  Size: 4.0 KiB

View File

@@ -59,3 +59,15 @@
color: rgba(255, 255, 255, 0.6);
line-height: 1.6;
}
.announcement-error {
font-size: 0.9rem;
color: #e57373;
padding: 12px 8px;
}
.announcement-empty {
font-size: 0.9rem;
color: rgba(255, 255, 255, 0.35);
padding: 12px 8px;
}

View File

@@ -5,18 +5,24 @@ import './AnnouncementBoard.css';
export default function AnnouncementBoard() {
const [list, setList] = useState([]);
const [expanded, setExpanded] = useState(null);
const [loading, setLoading] = useState(true);
const [error, setError] = useState(false);
useEffect(() => {
getAnnouncements()
.then(setList)
.catch(() => setError(true));
.catch(() => setError(true))
.finally(() => setLoading(false));
}, []);
return (
<section className="announcement-board">
<h2 className="announcement-heading">공지사항</h2>
{loading && <p className="announcement-empty">불러오는 ...</p>}
{error && <p className="announcement-error">공지사항을 불러오지 못했습니다.</p>}
{!loading && !error && list.length === 0 && (
<p className="announcement-empty">등록된 공지사항이 없습니다.</p>
)}
<ul className="announcement-list">
{list.map((item) => (
<li key={item.id} className="announcement-item">

View File

@@ -1,4 +1,4 @@
import { useState, useEffect, useCallback } from 'react';
import { useState, useEffect } from 'react';
import { useNavigate } from 'react-router-dom';
import { useAuth } from '../context/useAuth';
import { getDownloadInfo } from '../api/download';
@@ -14,15 +14,19 @@ export default function DownloadSection() {
const { user } = useAuth();
const navigate = useNavigate();
const loadInfo = useCallback(() => {
const loadInfo = () => {
setReady(false);
setLoadError(false);
getDownloadInfo()
.then((data) => { setInfo(data); setReady(true); })
.catch(() => { setLoadError(true); setReady(true); });
}, []);
};
useEffect(() => { loadInfo(); }, [loadInfo]);
useEffect(() => {
getDownloadInfo()
.then((data) => { setInfo(data); setReady(true); })
.catch(() => { setLoadError(true); setReady(true); });
}, []);
const handlePlay = async () => {
if (!user) {
@@ -76,7 +80,7 @@ export default function DownloadSection() {
<button onClick={handlePlay} className="btn-play" disabled={launching}>
{launching ? '준비 중...' : '게임 시작'}
</button>
{info?.launcherUrl && (
{info.launcherUrl && (
<button onClick={handleDownloadLauncher} className="btn-launcher-download">
런처 다운로드
</button>

View File

@@ -282,6 +282,13 @@
}
/* Role badge */
.admin-list-empty {
font-size: 0.9rem;
color: rgba(255, 255, 255, 0.35);
padding: 12px 16px;
margin: 0;
}
.admin-role-badge {
font-size: 0.7rem;
padding: 2px 8px;

View File

@@ -1,6 +1,5 @@
import { useState, useEffect } from 'react';
import { getAnnouncements } from '../../api/announcements';
import { apiFetch } from '../../api/client';
import { useState, useEffect, useCallback } from 'react';
import { getAnnouncements, createAnnouncement, updateAnnouncement, deleteAnnouncement } from '../../api/announcements';
import './AdminCommon.css';
export default function AnnouncementAdmin() {
@@ -10,25 +9,24 @@ export default function AnnouncementAdmin() {
const [loading, setLoading] = useState(false);
const [error, setError] = useState('');
const load = () => getAnnouncements().then(setList).catch(() => {});
useEffect(() => { load(); }, []);
const load = useCallback(() => {
getAnnouncements().then(setList).catch(() => {});
}, []);
useEffect(() => { load(); }, [load]);
const handleSubmit = async (e) => {
e.preventDefault();
if (!form.title || !form.content) return;
if (!form.title || !form.content) {
setError('제목과 내용을 모두 입력해주세요.');
return;
}
setLoading(true);
setError('');
try {
if (editingId) {
await apiFetch(`/api/announcements/${editingId}`, {
method: 'PUT',
body: JSON.stringify(form),
});
await updateAnnouncement(editingId, form.title, form.content);
} else {
await apiFetch('/api/announcements', {
method: 'POST',
body: JSON.stringify(form),
});
await createAnnouncement(form.title, form.content);
}
setForm({ title: '', content: '' });
setEditingId(null);
@@ -49,7 +47,7 @@ export default function AnnouncementAdmin() {
const handleDelete = async (id) => {
if (!confirm('삭제하시겠습니까?')) return;
try {
await apiFetch(`/api/announcements/${id}`, { method: 'DELETE' });
await deleteAnnouncement(id);
load();
} catch (err) {
setError(err.message || '삭제에 실패했습니다.');

View File

@@ -1,9 +1,28 @@
import { useState, useEffect } from 'react';
import { getDownloadInfo } from '../../api/download';
import { tryRefresh } from '../../api/client';
import './AdminCommon.css';
const BASE = import.meta.env.VITE_API_BASE_URL || '';
function sendXhr(url, token, file, { onProgress, onDone, onError }) {
const xhr = new XMLHttpRequest();
xhr.upload.onprogress = (event) => {
if (event.lengthComputable) {
onProgress(Math.round((event.loaded / event.total) * 100));
}
};
xhr.onload = () => onDone(xhr);
xhr.onerror = () => onError();
xhr.open('POST', url);
xhr.setRequestHeader('Authorization', `Bearer ${token}`);
xhr.setRequestHeader('Content-Type', 'application/octet-stream');
xhr.send(file);
}
function UploadForm({ title, hint, accept, endpoint, onSuccess }) {
const [file, setFile] = useState(null);
const [uploading, setUploading] = useState(false);
@@ -21,43 +40,71 @@ function UploadForm({ title, hint, accept, endpoint, onSuccess }) {
if (!file) return;
const token = localStorage.getItem('token');
const xhr = new XMLHttpRequest();
const url = `${BASE}${endpoint}?filename=${encodeURIComponent(file.name)}`;
xhr.upload.onprogress = (event) => {
if (event.lengthComputable) {
setProgress(Math.round((event.loaded / event.total) * 100));
}
};
setUploading(true);
setError('');
xhr.onload = () => {
setUploading(false);
const handleDone = (xhr) => {
// 401 시 토큰 갱신 후 재시도
if (xhr.status === 401) {
window.dispatchEvent(new Event('auth:unauthorized'));
tryRefresh()
.then((newToken) => {
sendXhr(url, newToken, file, {
onProgress: (p) => setProgress(p),
onDone: (retryXhr) => {
setUploading(false);
if (retryXhr.status === 401) {
window.dispatchEvent(new Event('auth:unauthorized'));
return;
}
parseXhrResponse(retryXhr);
},
onError: handleError,
});
})
.catch(() => {
setUploading(false);
window.dispatchEvent(new Event('auth:unauthorized'));
});
return;
}
if (xhr.status >= 200 && xhr.status < 300) {
onSuccess(JSON.parse(xhr.responseText));
setFile(null);
setProgress(0);
} else {
const res = JSON.parse(xhr.responseText || '{}');
setError(res.error || '업로드에 실패했습니다.');
setUploading(false);
parseXhrResponse(xhr);
};
const parseXhrResponse = (xhr) => {
try {
const body = JSON.parse(xhr.responseText || '{}');
if (xhr.status >= 200 && xhr.status < 300) {
onSuccess(body);
setFile(null);
setProgress(0);
} else {
setError(body.error || '업로드에 실패했습니다.');
setProgress(0);
}
} catch {
if (xhr.status >= 200 && xhr.status < 300) {
setError('응답을 처리할 수 없습니다.');
} else {
setError('업로드에 실패했습니다.');
}
setProgress(0);
}
};
xhr.onerror = () => {
const handleError = () => {
setUploading(false);
setError('네트워크 오류가 발생했습니다.');
setProgress(0);
};
xhr.open('POST', `${BASE}${endpoint}?filename=${encodeURIComponent(file.name)}`);
xhr.setRequestHeader('Authorization', `Bearer ${token}`);
xhr.setRequestHeader('Content-Type', 'application/octet-stream');
setUploading(true);
setError('');
xhr.send(file);
sendXhr(url, token, file, {
onProgress: (p) => setProgress(p),
onDone: handleDone,
onError: handleError,
});
};
return (

View File

@@ -1,15 +1,21 @@
import { useState, useEffect } from 'react';
import { useState, useEffect, useCallback } from 'react';
import { getUsers, updateUserRole, deleteUser } from '../../api/users';
import { useAuth } from '../../context/useAuth';
import './AdminCommon.css';
export default function UserAdmin() {
const [users, setUsers] = useState([]);
const [loading, setLoading] = useState(true);
const [error, setError] = useState('');
const { user: me } = useAuth();
const load = () => getUsers().then(setUsers).catch(() => {});
useEffect(() => { load(); }, []);
const load = useCallback(() => {
getUsers()
.then(setUsers)
.catch(() => {})
.finally(() => setLoading(false));
}, []);
useEffect(() => { load(); }, [load]);
const handleRoleToggle = async (u) => {
const newRole = u.role === 'admin' ? 'user' : 'admin';
@@ -38,6 +44,8 @@ export default function UserAdmin() {
<div className="admin-section">
<h2 className="admin-section-title">유저 관리</h2>
{error && <p className="admin-error">{error}</p>}
{loading && <p className="admin-list-empty">불러오는 ...</p>}
{!loading && users.length === 0 && <p className="admin-list-empty">등록된 유저가 없습니다.</p>}
<ul className="admin-list">
{users.map((u) => (
<li key={u.id} className="admin-list-item">

View File

@@ -41,7 +41,7 @@ export function AuthProvider({ children }) {
const logout = useCallback(async () => {
try {
await apiLogout();
} catch {}
} catch { /* 서버 실패해도 로컬 세션은 정리 */ }
clearSession();
}, [clearSession]);

View File

@@ -17,6 +17,10 @@ export default function LoginPage() {
const handleSubmit = async (e) => {
e.preventDefault();
setError('');
if (!username.trim() || !password) {
setError('아이디와 비밀번호를 입력해주세요.');
return;
}
setLoading(true);
try {
await login(username, password);

View File

@@ -31,6 +31,10 @@ export default function RegisterPage() {
e.preventDefault();
setError('');
if (!username.trim()) {
setError('아이디를 입력해주세요.');
return;
}
if (password !== confirm) {
setError('비밀번호가 일치하지 않습니다.');
return;