85 lines
6.9 KiB
XML
85 lines
6.9 KiB
XML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<svg xmlns="http://www.w3.org/2000/svg" width="999" height="319" viewBox="0 0 999 319" role="img" aria-labelledby="diagram-title diagram-description">
|
|
<title id="diagram-title">헤더 도착과 인가 우회는 다르다</title>
|
|
<desc id="diagram-description">위조 헤더는 app1.hyeonworks.com/api 의 permitAll echo 앱까지 그대로 도착했다. 같은 헤더로 JWT 를 요구하는 /api/me 와 /api/protected 를 호출하면 401이었다. 따라서 헤더 도착과 인가 우회는 다른 사건이다. proxy_set_header 로 먼저 지우는 것은 문서에 적힌 처방이지만 이 실험대에서는 적용하지 않아 미검증이다.</desc>
|
|
<metadata>{"techviz":{"spec_version":"1.1","id":"b4-header-trust-boundary","profile":"component-flow"},"source_context":{"document":"docs/keycloak-session-store/final/document.md","document_sha256":"28aef96a2bbb94fbb10ade26a71238fee62a5a4d9fa6e7749ae98cfd0a65e560","anchor":{"kind":"heading","value":"B-4 · Edge 인가의 범위 (Q4)","line":821}},"evidence_policy":"Each factual element cites source lines or is marked assumption.","diagram_only":true}</metadata>
|
|
<defs>
|
|
<marker id="arrow" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse">
|
|
<path d="M 0 0 L 10 5 L 0 10 z" />
|
|
</marker>
|
|
<style>
|
|
:root { color-scheme: light; }
|
|
text { font-family: Inter, Pretendard, ui-sans-serif, system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", sans-serif; fill: #111827; }
|
|
.canvas { fill: #ffffff; }
|
|
.group-box { fill: #ffffff; stroke: #9ca3af; stroke-width: 1.4; stroke-dasharray: 7 5; }
|
|
.group-label-bg { fill: #ffffff; }
|
|
.group-label { font-size: 13px; font-weight: 650; fill: #374151; }
|
|
.edge { fill: none; stroke: #374151; stroke-width: 1.8; stroke-linejoin: round; stroke-linecap: round; marker-end: url(#arrow); }
|
|
.edge.style-dashed, .edge.semantic-dashed, .edge.assumption { stroke-dasharray: 7 5; }
|
|
.edge.style-dotted { stroke-dasharray: 2 5; }
|
|
.edge.emphasis-primary { stroke: #2563eb; stroke-width: 2.2; }
|
|
.edge.emphasis-muted { stroke: #9ca3af; }
|
|
.edge.emphasis-warning, .edge.kind-failure, .edge.kind-error { stroke: #dc2626; stroke-width: 2.2; }
|
|
.edge-label-bg { fill: #ffffff; }
|
|
.edge-label { font-size: 12px; font-weight: 560; text-anchor: middle; }
|
|
.node-shape { fill: #ffffff; stroke: #4b5563; stroke-width: 1.7; }
|
|
.node-shape.emphasis-primary { stroke: #2563eb; stroke-width: 2.2; }
|
|
.node-shape.emphasis-muted { stroke: #9ca3af; fill: #f9fafb; }
|
|
.node-shape.emphasis-warning { stroke: #d97706; stroke-width: 2; fill: #fffdf5; }
|
|
.node-shape.kind-database, .node-shape.kind-datastore, .node-shape.kind-storage { fill: #f8fafc; }
|
|
.node-shape.kind-queue, .node-shape.kind-event, .node-shape.kind-topic { fill: #fafafa; }
|
|
.node-shape.assumption { stroke-dasharray: 4 4; }
|
|
.storage-bottom, .controller-divider { fill: none; stroke: #4b5563; stroke-width: 1.4; }
|
|
.controller-led { fill: #4b5563; }
|
|
.actor-symbol { fill: none; stroke: #4b5563; stroke-width: 1.8; stroke-linecap: round; }
|
|
.actor-symbol.emphasis-primary { stroke: #2563eb; stroke-width: 2.2; }
|
|
.node-label { font-size: 14px; font-weight: 650; text-anchor: middle; }
|
|
.node-role { font-size: 10px; letter-spacing: 0.04em; text-anchor: middle; fill: #6b7280; }
|
|
.node-detail-divider { stroke: #d1d5db; stroke-width: 1; }
|
|
.node-detail { font-size: 11px; fill: #374151; }
|
|
.assumption-badge { font-size: 9px; font-weight: 700; fill: #92400e; }
|
|
.failure-mark { stroke: #dc2626; stroke-width: 4; stroke-linecap: round; }
|
|
.lifeline { stroke: #9ca3af; stroke-width: 1.2; stroke-dasharray: 5 5; }
|
|
.timeline-axis { stroke: #374151; stroke-width: 1.8; marker-end: url(#arrow); }
|
|
.timeline-stem { stroke: #6b7280; stroke-width: 1.3; }
|
|
.timeline-marker { fill: #ffffff; stroke: #374151; stroke-width: 1.7; }
|
|
.timeline-marker.primary { fill: #2563eb; stroke: #2563eb; }
|
|
.timeline-marker.warning { fill: #dc2626; stroke: #dc2626; }
|
|
.timeline-label { font-size: 13px; font-weight: 650; text-anchor: middle; }
|
|
.timeline-detail { font-size: 11px; fill: #4b5563; text-anchor: middle; }
|
|
</style>
|
|
</defs>
|
|
<rect class="canvas" width="999" height="319" />
|
|
<polyline class="edge kind-request style-solid emphasis-normal" points="240.0,167.0 320.0,167.0 320.0,167.0 400.0,167.0" data-evidence="823-830" />
|
|
<rect class="edge-label-bg" x="294.2" y="125.0" width="51.5" height="22" rx="3" />
|
|
<text class="edge-label" x="320.0" y="140.0">위조 헤더</text>
|
|
<polyline class="edge kind-request style-solid emphasis-normal" points="550.0,158.0 647.5,158.0 647.5,95.5 745.0,95.5" data-evidence="825-840" />
|
|
<rect class="edge-label-bg" x="642.4" y="112.8" width="58.2" height="22" rx="3" />
|
|
<text class="edge-label" x="671.5" y="127.8">그대로 전달</text>
|
|
<polyline class="edge kind-request style-solid emphasis-normal" points="550.0,176.0 630.0,176.0 630.0,238.5 710.0,238.5" data-evidence="832-840" />
|
|
<rect class="edge-label-bg" x="628.2" y="193.2" width="51.5" height="22" rx="3" />
|
|
<text class="edge-label" x="654.0" y="208.2">같은 헤더</text>
|
|
<g id="node-attacker">
|
|
<g class="actor-symbol emphasis-warning" data-evidence="823-830"><circle cx="155.0" cy="145.0" r="11.0" /><line x1="155.0" y1="161.0" x2="155.0" y2="180.0" /><line x1="137.0" y1="171.0" x2="173.0" y2="171.0" /><line x1="155.0" y1="180.0" x2="140.0" y2="197.0" /><line x1="155.0" y1="180.0" x2="170.0" y2="197.0" /></g>
|
|
<text class="node-label" x="155.0" y="202.0">외부 위조 헤더</text>
|
|
</g>
|
|
<g id="node-nginx">
|
|
<polygon class="node-shape kind-gateway emphasis-warning role-control" data-evidence="829-830" points="475.0,131.5 550.0,167.0 475.0,202.5 400.0,167.0" />
|
|
<text class="node-label" x="475.0" y="158.5">nginx</text>
|
|
<line class="node-detail-divider" x1="414.0" y1="179.5" x2="536.0" y2="179.5" />
|
|
<text class="node-detail" x="416.0" y="196.5">동명 헤더 미삭제</text>
|
|
</g>
|
|
<g id="node-echo">
|
|
<rect class="node-shape kind-service emphasis-normal role-target" data-evidence="825-840" x="745.0" y="60.0" width="174.0" height="71.0" rx="7" />
|
|
<text class="node-label" x="832.0" y="87.0">permitAll echo</text>
|
|
<line class="node-detail-divider" x1="759.0" y1="108.0" x2="905.0" y2="108.0" />
|
|
<text class="node-detail" x="761.0" y="125.0">/api/echo · HTTP 200</text>
|
|
</g>
|
|
<g id="node-protected">
|
|
<rect class="node-shape kind-service emphasis-primary role-target" data-evidence="832-840" x="710.0" y="203.0" width="244.0" height="71.0" rx="7" />
|
|
<text class="node-label" x="832.0" y="230.0">JWT 보호 경로</text>
|
|
<line class="node-detail-divider" x1="724.0" y1="251.0" x2="940.0" y2="251.0" />
|
|
<text class="node-detail" x="726.0" y="268.0">/api/me · /api/protected · 401</text>
|
|
</g>
|
|
</svg>
|