feat(ap1): add vanilla SPA PKCE login

This commit is contained in:
donghyeon-ka
2026-07-25 14:09:03 +09:00
parent e2fba41f56
commit c1fae6137c
15 changed files with 951 additions and 13 deletions
+14
View File
@@ -96,3 +96,17 @@ Keycloak을 잠시 중지하고 export한 뒤 자동으로 다시 올립니다.
runtime export에는 실제 client secret과 credential hash가 포함될 수 있어
gitignored `build/keycloak-export/`에 권한 `0600`으로만 저장됩니다.
## AP1: SPA Direct + Resource Server
`develop-keycloak-pattern1`은 vanilla JavaScript SPA가 `spa-public` client로
Authorization Code + PKCE S256 로그인을 수행하는 패턴입니다. access/refresh
token은 명시적인 in-memory store에만 보관되므로 새로고침하면 사라집니다.
```bash
./scripts/verify-pattern1.sh
```
브라우저에서 `http://localhost:8088`을 열어 로그인한 뒤 보호 API를 호출할 수
있습니다. SPA는 `http://localhost:8081/api/me`를 직접 호출하며 Spring
Resource Server가 Bearer JWT를 검증합니다.