Skip to content

Commit

Permalink
Update about oauth
Browse files Browse the repository at this point in the history
  • Loading branch information
mongzza committed Dec 4, 2020
1 parent 652f0e4 commit 53bec7e
Show file tree
Hide file tree
Showing 2 changed files with 45 additions and 1 deletion.
3 changes: 2 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -201,7 +201,8 @@
* ํŒจ์Šค์›Œ๋“œ ์•”ํ˜ธํ™” ๋ฐฉ๋ฒ•
* SQL Injection ๊ณต๊ฒฉ
* CSRF ๊ณต๊ฒฉ
* XSS ๊ณต๊ฒฉ
* XSS ๊ณต๊ฒฉ
* OAuth

## 11. ETC
:arrow_forward: [๋‹ต๋ณ€ ๋‚ด์šฉ](/contents/etc.md)
Expand Down
43 changes: 43 additions & 0 deletions contents/security.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@
- [SQL Injection ๊ณต๊ฒฉ](#sql-injection-๊ณต๊ฒฉ)
- [CSRF ๊ณต๊ฒฉ](#csrf-๊ณต๊ฒฉ)
- [XSS ๊ณต๊ฒฉ](#xss-๊ณต๊ฒฉ)
- [OAuth](#oauth)

---

Expand Down Expand Up @@ -124,6 +125,48 @@
> :arrow_double_up:[Top](#9-security) :leftwards_arrow_with_hook:[Back](https://github.com/WeareSoft/tech-interview#9-security) :information_source:[Home](https://github.com/WeareSoft/tech-interview#tech-interview)
> - []()
### OAuth
#### OAuth ๊ฐœ๋…
- ์‚ฌ์šฉ์ž๊ฐ€ ์–ด๋–ค ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์ด์šฉํ•  ๋•Œ, ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•˜์ง€ ์•Š๊ณ  OAuth๋ฅผ ์ œ๊ณตํ•˜๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๊ณ„์ • ์ •๋ณด๋ฅผ ๊ณต์œ ํ•˜์—ฌ ์ ‘๊ทผ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•  ์ˆ˜ ์žˆ๋Š” ์ˆ˜๋‹จ
- OAuth๊ฐ€ ์‚ฌ์šฉ๋˜๊ธฐ ์ „์—๋Š” ๋ณด์•ˆ์ด ์ทจ์•ฝํ•œ ๊ตฌ์กฐ
- ๊ฐ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด๋‚˜ ์›น ์‚ฌ์ดํŠธ๋งˆ๋‹ค ๊ฐœ๋ณ„์ ์ธ ์ธ์ฆ ๋ฐฉ์‹์œผ๋กœ ์•„์ด๋””์™€ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋กœ๊ทธ์ธ
- OAuth๋Š” ์ œ๊ฐ๊ฐ์ธ ์ธ์ฆ๋ฐฉ์‹์„ ํ‘œ์ค€ํ™”ํ•œ ๊ฒƒ
- ์ธ์ฆ์„ ๊ณต์œ ํ•˜๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜๋ผ๋ฆฌ๋Š” ๋ณ„๋„ ์ธ์ฆ๊ณผ์ • ๋ถˆํ•„์š”
- '์ธ์ฆ(Authentication)' ํ”„๋กœํ† ์ฝœ์ด ์•„๋‹Œ **'์ธ๊ฐ€(Authorization)' ํ”„๋กœํ† ์ฝœ**
- ์ธ์ฆ : ์ ‘๊ทผ ๊ฐ€๋Šฅํ•จ์„ ํ™•์ธํ•˜๋Š” ๊ณผ์ •
- ์ธ๊ฐ€ : ํ—ˆ๊ฐ€, ์ ‘๊ทผ ๊ถŒํ•œ์„ ๊ด€๋ฆฌ
- ์‚ฌ์šฉ์ž์˜ ํ™•์ธ(์ธ์ฆ) ๊ณผ์ •์„ ํ†ตํ•ด ๊ถŒํ•œ์„ ๋ถ€์—ฌ(์ธ๊ฐ€)

#### OAuth ๊ด€๋ จ ์šฉ์–ด
- ์‚ฌ์šฉ์ž
- '์„œ๋น„์Šค ์ œ๊ณต์ž'์™€ '์†Œ๋น„์ž'๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ณ„์ •์„ ๊ฐ€์ง€๊ณ ์žˆ๋Š” ๊ฐœ์ธ
- ์„œ๋น„์Šค ์ œ๊ณต์ž
- OAuth๋ฅผ ํ†ตํ•œ ์ ‘๊ทผ์„ ์ง€์›ํ•˜๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜(Open API ์ œ๊ณต ์„œ๋น„์Šค)
- ๋Œ€ํ‘œ์ ์œผ๋กœ ๊ตฌ๊ธ€, ๋„ค์ด๋ฒ„, ์นด์นด์˜ค, ํŽ˜์ด์Šค๋ถ ๋“ฑ
- ์†Œ๋น„์ž
- Open API๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ฐœ๋ฐœ๋œ OAuth๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ '์„œ๋น„์Šค ์ œ๊ณต์ž'์—๊ฒŒ ์ ‘๊ทผํ•˜๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜
- ์†Œ๋น„์ž ๋น„๋ฐ€๋ฒˆํ˜ธ
- '์„œ๋น„์Šค ์ œ๊ณต์ž'์—์„œ ์†Œ๋น„์ž๊ฐ€ ์ž์‹ ์ž„์„ ์ธ์ฆํ•˜๋Š” ํ‚ค
- ์š”์ฒญ ํ† ํฐ
- '์†Œ๋น„์ž'๊ฐ€ '์‚ฌ์šฉ์ž'์˜ ์ ‘๊ทผ ๊ถŒํ•œ์„ ์ธ์ฆ๋ฐ›๊ธฐ ์œ„ํ•ด ํ•„์š”ํ•œ ์ •๋ณด
- ์ดํ›„ '์ ‘๊ทผ ํ† ํฐ'์œผ๋กœ ๋ณ€๊ฒฝ
- ์ ‘๊ทผ ํ† ํฐ
- ์ธ์ฆ ํ›„์— '์‚ฌ์šฉ์ž'๊ฐ€ '์„œ๋น„์Šค ์ œ๊ณต์ž'๊ฐ€ ์•„๋‹Œ '์†Œ๋น„์ž'๋ฅผ ํ†ตํ•ด ๋ณดํ˜ธ๋œ ์ž์›์— ์ ‘๊ทผํ•˜๊ธฐ ์œ„ํ•œ ํ‚ค๋ฅผ ํฌํ•จํ•œ ๊ฐ’

#### ๊ณผ์ •
- '์†Œ๋น„์ž'์™€ '์„œ๋น„์Šค ์ œ๊ณต์ž' ๊ฐ„์— OAuth ๊ณผ์ • ์ง„ํ–‰
1. ์†Œ๋น„์ž๊ฐ€ ์„œ๋น„์Šค ์ œ๊ณต์ž์—๊ฒŒ '์š”์ฒญ ํ† ํฐ'์„ ์š”์ฒญ
2. ์„œ๋น„์Šค ์ œ๊ณต์ž๊ฐ€ ์†Œ๋น„์ž์—๊ฒŒ '์š”์ฒญ ํ† ํฐ' ๋ฐœ๊ธ‰
3. ์†Œ๋น„์ž๊ฐ€ ์‚ฌ์šฉ์ž๋ฅผ ์„œ๋น„์Šค ์ œ๊ณต์ž์—๊ฒŒ ์ด๋™์‹œํ‚ค๊ณ , ์ด ๊ณผ์ •์—์„œ ์‚ฌ์šฉ์ž ์ธ์ฆ ์ˆ˜ํ–‰(์ธ์ฆ, Authentication)
4. ์‚ฌ์šฉ์ž ์ธ์ฆ ํ›„, ์„œ๋น„์Šค ์ œ๊ณต์ž๊ฐ€ ์‚ฌ์šฉ์ž๋ฅผ ์†Œ๋น„์ž๋กœ ์ด๋™
5. ์†Œ๋น„์ž๊ฐ€ '์ ‘๊ทผ ํ† ํฐ' ์š”์ฒญ
6. ์„œ๋น„์Šค ์ œ๊ณต์ž๊ฐ€ '์ ‘๊ทผ ํ† ํฐ' ๋ฐœ๊ธ‰(๊ถŒํ•œ ๋ถ€์—ฌ, Authorization)
7. ์†Œ๋น„์ž๋Š” '์ ‘๊ทผ ํ† ํฐ'์„ ์‚ฌ์šฉํ•˜์—ฌ ์‚ฌ์šฉ์ž ์ •๋ณด์— ์ ‘๊ทผ ๊ฐ€๋Šฅ

> :arrow_double_up:[Top](#9-security) :leftwards_arrow_with_hook:[Back](https://github.com/WeareSoft/tech-interview#9-security) :information_source:[Home](https://github.com/WeareSoft/tech-interview#tech-interview)
> - [OAuth](https://ko.wikipedia.org/wiki/OAuth)

---

## Reference
Expand Down

0 comments on commit 53bec7e

Please sign in to comment.