★★ 챗봇 웹훅의 user.properties.appUserId 는 카카오 로그인의 회원번호와 **같은 값**이다
(카카오 공식 문서, 봇에 앱키가 물려 있을 때). 그래서 카카오로 로그인만 해 두면 채널에
말을 거는 순간 누구인지 알 수 있고, 6자리 코드 절차가 필요 없어진다.
- external/kakao_identity: 액세스 토큰을 카카오에 되물어 확인한다. ★ 응답의 app_id 를
우리 앱과 대조하는 것이 구글의 aud 검사에 해당한다 — 이게 없으면 남의 앱 토큰으로
우리 계정이 된다. 이름·이메일은 동의 항목이라 못 받아도 로그인은 되게 했다
- auth_service.kakao_login: google_login 과 같은 세 갈래. 이메일이 겹쳐도 자동으로
잇지 않는다(DECISIONS 1 — 계정 선점)
- kakao_link_service.link_by_app_user_id: 자동 매칭. ★ 이미 다른 사장님에게 묶인
카톡은 빼앗지 않는다 — 조용히 빼앗으면 앞사람이 남의 가게를 보게 된다
- ★ 코드 경로는 그대로 둔다: id/pw·구글 가입자에겐 appUserId 가 없고, 봇에 앱키가
안 물린 환경에서는 값 자체가 안 온다
★ 함께 고친 것 — services/agent/tools.py 가 사라진 site_payload._DEFAULT_THEME 를
보고 있었다(c690862 템플릿 정의 통합에서 이름이 없어졌는데 이 한 줄만 남았다).
**대화의 섹션 기능이 통째로 죽어 있었고** 웹훅이 AttributeError 를 삼켜 "지금은
처리할 수 없어요" 로만 보였다 — common/template_catalog.industry_of 로 바꿨다.
test_kakao_link·test_kakao_webhook·test_agent_runtime·test_auth 194 passed
(신규 4: 자동 매칭·미가입자·빼앗지 않음·재진입). 남은 1건은 컨테이너에 실제
GOOGLE_CLIENT_ID 가 있어 나는 기존 실패다.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
69 lines
1.7 KiB
Python
69 lines
1.7 KiB
Python
from typing import Optional
|
|
|
|
from common.enums import AuthProvider, UserRole
|
|
from common.models.gmodel import Res_WebPacketProtocol, WebPacketProtocol
|
|
|
|
|
|
# 라우터 폴더마다 protocol.py 를 두고 Req_/Res_ 를 정의한다 (protocol 규약).
|
|
class AuthProtocol(WebPacketProtocol):
|
|
pass
|
|
|
|
|
|
class Req_Login(AuthProtocol):
|
|
id: str = ""
|
|
password: str = ""
|
|
|
|
|
|
class Req_Signup(AuthProtocol):
|
|
"""id/pw 가입."""
|
|
|
|
id: str = ""
|
|
password: str = ""
|
|
name: Optional[str] = None
|
|
email: str = ""
|
|
|
|
|
|
class Req_GoogleLogin(AuthProtocol):
|
|
"""구글 로그인."""
|
|
|
|
credential: str = ""
|
|
|
|
|
|
class Req_KakaoLogin(AuthProtocol):
|
|
"""카카오 로그인.
|
|
|
|
★ 구글은 ID 토큰(credential)을 우리가 직접 검증하지만, 카카오는 **액세스 토큰**을
|
|
카카오에 되물어 확인한다 — 그래서 필드 이름이 다르다."""
|
|
|
|
access_token: str = ""
|
|
|
|
|
|
class Res_Login(Res_WebPacketProtocol):
|
|
access_token: str = ""
|
|
refresh_token: str = ""
|
|
token_type: str = "bearer"
|
|
|
|
|
|
class Req_UpdateMe(AuthProtocol):
|
|
# 본인 정보 수정.
|
|
name: Optional[str] = None
|
|
email: Optional[str] = None
|
|
contact_number: Optional[str] = None
|
|
password: Optional[str] = None # 비밀번호 변경(옵션).
|
|
|
|
|
|
class Res_RefreshToken(Res_WebPacketProtocol):
|
|
access_token: str = ""
|
|
token_type: str = "bearer"
|
|
|
|
|
|
class Res_Me(Res_WebPacketProtocol):
|
|
user_id: str = ""
|
|
id: str = ""
|
|
name: Optional[str] = None
|
|
email: Optional[str] = None
|
|
contact_number: Optional[str] = None
|
|
role: UserRole = UserRole.USER
|
|
# 이 계정이 무엇으로 로그인하는가.
|
|
provider: AuthProvider = AuthProvider.LOCAL
|