The originating repository's SVGs were drawn by hand and every one of them
put a title, a subtitle and an explanation band inside the canvas. This
repository forbids both, so they could not be carried over — the whole set
was rebuilt through the skill's pipeline instead.
Each diagram went through prepare, references, prompt, a VizSpec 1.1 citing
document line ranges, lint, and render. All 28 pass lint and produce the
same eight formats the existing keycloak project has. Sentences moved out of
the canvas into <desc> and the paragraph beside each figure; the drawings
carry names only.
Two lint rules did real work rather than formatting work:
edge-through-node caught arrows crossing an unrelated
node and implying an adjacency that
does not exist — four diagrams had to
be restructured, not just relaid out
evidence-outside-prepared-context caught a diagram citing another
section; its anchor moved from B-0 to
B-1 so all three sections it draws on
are inside the prepared context
lab-topology also had to change profile: its context offers a different
candidate set, and query-fanout with shard roles is what the section
actually shows — one entry point spreading to two Keycloak nodes.
The document now carries all 28 inline, one per claim that needed one, and
the section recording what was still missing is updated: the diagram gap is
closed, Studio records remain.
verify-pipeline.py passes. audit-records.py reports no issues.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
150 lines
4.3 KiB
JSON
150 lines
4.3 KiB
JSON
{
|
|
"version": "1.1",
|
|
"id": "b2-primary-key-overwrite",
|
|
"title": "덮어쓰기를 만드는 기본키",
|
|
"question": "같은 사용자의 두 브라우저가 서로의 토큰을 지우는 이유는 무엇인가",
|
|
"type": "architecture",
|
|
"direction": "TB",
|
|
"audience": [
|
|
"BFF 의 토큰 저장을 설계하는 백엔드 엔지니어"
|
|
],
|
|
"summary": "저장소를 바꿔도 풀리지 않는다. 기본키에 세션 id 가 없어 같은 사용자의 두 세션이 같은 행을 쓴다.",
|
|
"alt": "두 브라우저 세션이 서로 다른 세션 행을 갖지만 토큰 테이블에서는 같은 행을 가리키는 구성.",
|
|
"long_description": "토큰을 PostgreSQL 로 옮겨 다중 인스턴스 문제는 풀렸다. 그러나 기본키가 client_registration_id 와 principal_name 의 조합이고 세션 id 가 들어 있지 않다. 같은 사용자의 두 세션이 같은 행을 쓰므로 나중 로그인이 앞의 토큰을 덮어쓴다. 그리고 로그아웃하면 Redis 세션은 0 키로 정리되지만 PostgreSQL 에는 평문 refresh token 이 한 행 그대로 남는다.",
|
|
"source_context": {
|
|
"document": "docs/keycloak-session-store/final/document.md",
|
|
"document_sha256": "1d44cba1905544d92f1d26ae36a8deb64a3db3914d6b488fd30d6ae7f8cfbabe",
|
|
"anchor": {
|
|
"kind": "heading",
|
|
"value": "B-2 · 저장소를 나눠 풀자 다른 두 문제가 남았다",
|
|
"line": 365
|
|
}
|
|
},
|
|
"composition": {
|
|
"profile": "component-flow",
|
|
"diagram_only": true,
|
|
"reference_ids": [
|
|
"payment-event-flow"
|
|
],
|
|
"rationale": "두 세션이 하나의 행으로 합쳐지는 자리가 지배적 질문이다. 조회 키의 충돌이므로 component-flow 를 골랐다."
|
|
},
|
|
"groups": [],
|
|
"nodes": [
|
|
{
|
|
"id": "s1",
|
|
"label": "브라우저 A 세션",
|
|
"kind": "component",
|
|
"role": "source",
|
|
"emphasis": "primary",
|
|
"description": "세션 id 가 다르다.",
|
|
"details": [],
|
|
"evidence": [
|
|
{
|
|
"start_line": 360,
|
|
"end_line": 366
|
|
}
|
|
],
|
|
"assumption": false
|
|
},
|
|
{
|
|
"id": "s2",
|
|
"label": "브라우저 B 세션",
|
|
"kind": "component",
|
|
"role": "source",
|
|
"emphasis": "primary",
|
|
"description": "세션 id 가 다르다.",
|
|
"details": [],
|
|
"evidence": [
|
|
{
|
|
"start_line": 360,
|
|
"end_line": 366
|
|
}
|
|
],
|
|
"assumption": false
|
|
},
|
|
{
|
|
"id": "token-row",
|
|
"label": "토큰 행",
|
|
"kind": "datastore",
|
|
"role": "target",
|
|
"emphasis": "warning",
|
|
"description": "기본키에 세션 id 가 없어 둘이 같은 행을 쓴다.",
|
|
"details": [
|
|
"PRIMARY KEY (client_registration_id, principal_name)"
|
|
],
|
|
"evidence": [
|
|
{
|
|
"start_line": 370,
|
|
"end_line": 377
|
|
}
|
|
],
|
|
"assumption": false
|
|
},
|
|
{
|
|
"id": "leftover",
|
|
"label": "로그아웃 후 남는 것",
|
|
"kind": "datastore",
|
|
"role": "target",
|
|
"emphasis": "warning",
|
|
"description": "Redis 세션은 0 키인데 여기는 1 행이 남는다.",
|
|
"details": [
|
|
"평문 refresh token"
|
|
],
|
|
"evidence": [
|
|
{
|
|
"start_line": 378,
|
|
"end_line": 384
|
|
}
|
|
],
|
|
"assumption": false
|
|
}
|
|
],
|
|
"edges": [
|
|
{
|
|
"id": "s1-t",
|
|
"from": "s1",
|
|
"to": "token-row",
|
|
"label": "principal 이름으로 쓴다",
|
|
"kind": "write",
|
|
"evidence": [
|
|
{
|
|
"start_line": 370,
|
|
"end_line": 377
|
|
}
|
|
],
|
|
"assumption": false
|
|
},
|
|
{
|
|
"id": "s2-t",
|
|
"from": "s2",
|
|
"to": "token-row",
|
|
"label": "같은 키로 덮어쓴다",
|
|
"kind": "write",
|
|
"evidence": [
|
|
{
|
|
"start_line": 370,
|
|
"end_line": 377
|
|
}
|
|
],
|
|
"assumption": false
|
|
},
|
|
{
|
|
"id": "t-l",
|
|
"from": "token-row",
|
|
"to": "leftover",
|
|
"label": "로그아웃이 정리하지 않는다",
|
|
"kind": "blocked",
|
|
"evidence": [
|
|
{
|
|
"start_line": 378,
|
|
"end_line": 384
|
|
}
|
|
],
|
|
"assumption": false
|
|
}
|
|
],
|
|
"legend": [],
|
|
"metadata": {
|
|
"rationale": "저장소가 아니라 스키마가 원인이라는 것을 키로 보이게 그렸다."
|
|
}
|
|
} |