Skip to content

chore: 릴리즈 — 계정 아이디 대문자 허용 - #527

Merged
chanwoo7 merged 4 commits into
mainfrom
develop
Oct 8, 2026
Merged

chanwoo7 merged 4 commits into
mainfrom
develop

Conversation

@chanwoo7

@chanwoo7 chanwoo7 commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

관리자 페이지에서 관리자·판매자 계정을 만들 때 아이디에 영문 대문자를 허용하는 변경과 릴리즈 리뷰 수정을 운영에 반영합니다.

  • feat: 계정 아이디에 영문 대문자 허용 #526 계정 아이디(username)에 영문 대문자 허용
    • 규칙: 4~80자, 영문 대소문자·숫자·.·_·-
    • 입력한 대소문자 그대로 저장·표시, 로그인은 대소문자 무관
    • 대소문자만 다른 아이디는 USERNAME_TAKEN(컬럼 정렬 utf8mb4_unicode_ci)
    • SDL은 설명만 변경(타입 변경 없음)
  • fix: 시드 username 검증을 생성 정책과 맞춤 #528 시드 username 검증을 생성 정책과 맞춤(이 릴리즈의 Codex 리뷰 반영)
    • 시드 검증이 정책 사본 대신 USERNAME_PATTERN·길이 상수를 직접 사용

운영 반영 사항입니다.

  • 마이그레이션 없음, 시크릿 변경 없음.
  • 관리자 FE의 생성 폼 검증 완화는 이 릴리즈 배포 뒤 FE 릴리즈로 이어서 반영합니다.

관리자 페이지의 관리자·판매자 계정 생성에서 username 규칙에 영문 대문자를 더함.

- USERNAME_PATTERN: [a-z0-9._-] → [A-Za-z0-9._-]
- 입력한 대소문자 그대로 저장·표시, 로그인은 대소문자 무관
- 대소문자만 다른 username은 USERNAME_TAKEN — account_credential.username 정렬이 utf8mb4_unicode_ci라 사전 조회·unique 인덱스 모두 같은 값으로 봄. 마이그레이션 없음
- SDL 설명 2곳(AdminCreateAdminInput·AdminCreateSellerInput) 갱신

테스트
- input spec 2개: 대문자 거절 케이스 → 허용 케이스
- 관리자·판매자 생성: 대소문자만 다른 username 충돌 2건, 대문자 그대로 저장 1건
- AccountCredentialRepository.findCredentialByUsername: 대소문자 무관 조회 3건
feat: 계정 아이디에 영문 대문자 허용
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T01:38:52.728800Z 8e20ef8 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 32 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: CaQuick/caquick-be/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: a48a2682-30f2-40d2-adcc-71f2ea95661d
📥 Commits

Reviewing files that changed from the base of the PR and between 0e36600 and 8e20ef8.

📒 Files selected for processing (2)
  • prisma/seed/credential-policy.ts
  • src/test/seed-credential-policy.spec.ts

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: CaQuick/caquick-be/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 53176a7c-fbc1-4f13-9b0c-695d6b66fbbd
📥 Commits

Reviewing files that changed from the base of the PR and between b59a242 and 0e36600.

📒 Files selected for processing (8)
  • src/features/auth/auth-admin-account.graphql
  • src/features/auth/constants/auth-admin.constants.ts
  • src/features/auth/dto/inputs/admin-create-admin.input.spec.ts
  • src/features/auth/repositories/account-credential.repository.spec.ts
  • src/features/auth/services/auth-admin-account.service.spec.ts
  • src/features/store/dto/inputs/admin-create-seller.input.spec.ts
  • src/features/store/services/store-admin-seller.service.spec.ts
  • src/features/store/store-admin-seller.graphql

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

관리자와 판매자 username에서 영문 대문자를 허용하도록 정규식과 입력 설명을 변경했습니다. 대소문자만 다른 username의 조회 및 중복 처리 사례를 검증하는 테스트를 추가했습니다.

Changes

관리자 username 대소문자 처리

Layer / File(s) Summary
대문자 허용 규칙과 입력 검증
src/features/auth/constants/auth-admin.constants.ts, src/features/auth/auth-admin-account.graphql, src/features/store/store-admin-seller.graphql, src/features/auth/dto/inputs/admin-create-admin.input.spec.ts, src/features/store/dto/inputs/admin-create-seller.input.spec.ts
USERNAME_PATTERN이 영문 대소문자를 허용하도록 변경됐습니다. GraphQL 설명과 입력 검증 테스트도 대문자 username을 허용하도록 갱신됐습니다.
대소문자 비구분 조회와 중복 검증
src/features/auth/repositories/account-credential.repository.spec.ts, src/features/auth/services/auth-admin-account.service.spec.ts, src/features/store/services/store-admin-seller.service.spec.ts
자격증명 조회 시 대소문자 변형 입력을 확인하는 테스트를 추가했습니다. 관리자 및 판매자 생성 테스트는 대소문자만 다른 username이 USERNAME_TAKEN 오류를 반환하는지 확인합니다.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to 0e366

대문자 username을 허용해도 대소문자만 다른 계정은 중복으로 처리되고 대소문자 비구분 로그인이 유지됩니다. 확인된 병합 차단 위험은 없습니다.

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 6…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed 제목은 관리자·판매자 계정 username에 영문 대문자를 허용하는 주요 변경을 간결하게 설명합니다.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

🧹 knip — dead-code 리포트

Unused exported types (1)
전체 리포트
Unused exported types (1)
RateLimitPolicy  type  src/global/rate-limit/index.ts:4:8

청소 후보(오탐 가능) · 기준 docs/guide/architecture-conventions.md

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

🩺 NestJS Doctor — 90/100 (Excellent)

진단 484건 (error 12).

Category error warning info
architecture 1 1 44
correctness 0 266 0
performance 0 36 28
schema 0 0 76
security 11 21 0
architecture / security 상위 항목
  • error architecture/architecture/no-manual-instantiation: Manual instantiation of 'OutboxRepository' detected. Use dependency injection instead.
  • info architecture/architecture/no-barrel-export-internals: Barrel file re-exports internal type 'IAuditLogRepository'.
  • warning security/security/no-exposed-env-vars: Direct 'process.env.NODE_ENV' access in 'AuthController'. Use ConfigService instead.
  • warning security/security/require-guards-on-endpoints: Endpoint 'start' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'callback' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'refresh' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'logout' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'sellerLogin' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'sellerRefresh' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'sellerLogout' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'devIssueToken' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'adminLogin' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'adminRefresh' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'adminLogout' has no @UseGuards() at class or method level.
  • warning security/security/require-guards-on-endpoints: Endpoint 'getJwks' has no @UseGuards() at class or method level.

오탐 포함 가능 · 기준 docs/guide/architecture-conventions.md

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0e366005b8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

/** 정책: 소문자·숫자·`.`·`_`·`-`만. 대소문자 혼용 username 충돌을 원천 차단한다. */
export const USERNAME_PATTERN = /^[a-z0-9._-]+$/;
/** 정책: 영문 대소문자·숫자·`.`·`_`·`-`만. 대소문자만 다른 username은 컬럼 정렬(ci)이 같은 값으로 봐 중복으로 막는다. */
export const USERNAME_PATTERN = /^[A-Za-z0-9._-]+$/;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Synchronize the seed username validator

When ADMIN_SEED_USERNAME contains a newly valid mixed-case value such as Ops.Admin, seedAdmins still passes it to prisma/seed/credential-policy.ts, whose lowercase-only regex throws before the account is inserted. This leaves the documented optional admin-seeding path unable to use the username policy introduced here; update that validator and its error message, preferably by reusing the shared policy.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

반영: 시드 username 검증이 생성 정책(USERNAME_PATTERN·길이 상수)을 직접 쓰도록 바꿈 — fix/release-review-seed-username → develop PR로 반영 후 이 릴리즈에 포함.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Coverage report

St.❔
Category Percentage Covered / Total
🟢 Statements 98% 10692/10910
🟢 Branches 92.92% 4070/4380
🟢 Functions 97.53% 2133/2187
🟢 Lines 98.57% 9728/9869

Test suite run success

4262 tests passing in 384 suites.

Report generated by 🧪jest coverage report action from 8e20ef8

@codecov

codecov Bot commented Oct 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

릴리즈 #527 Codex 리뷰 반영. #526에서 생성 정책에 대문자를 허용했는데 prisma/seed/credential-policy.ts는 소문자 전용 정규식을 따로 들고 있어 ADMIN_SEED_USERNAME=Ops.Admin 같은 값이 시드에서 거절됨.

- 시드 검증이 USERNAME_PATTERN·MIN/MAX_USERNAME_LENGTH를 직접 쓰도록 변경(정책 사본 제거)
- 위반 메시지: 소문자 → 영문 대소문자, 값은 계속 싣지 않음

테스트
- src/test/seed-credential-policy.spec.ts: username 10건을 시드 검증과 AdminCreateAdminInput이 같은 판정을 내리는지 표로 확인, 메시지에 값 미포함·password 위반 메시지 각 1건
- 반증: 수정 전 시드 정책으로 되돌리면 대문자 케이스 2건 실패
fix: 시드 username 검증을 생성 정책과 맞춤
@chanwoo7

chanwoo7 commented Oct 8, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@chanwoo7
chanwoo7 merged commit b3fe44f into main Oct 8, 2026
27 checks passed
@chanwoo7
chanwoo7 deleted the develop branch October 8, 2026 01:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant