설명
Spring Security에서 csrf().disable(), frameOptions().disable(), anyRequest().permitAll() 같은 설정은 해당 보안 필터 체인의 보호 기능이나 접근 제한을 해제합니다. 위험은 브라우저가 자동으로 보내는 인증 정보의 사용 여부, 다른 프레임 제한, 체인이 적용되는 요청 범위에 따라 달라집니다.
잠재적 영향
- 쿠키 등 자동 전송되는 인증 정보를 사용하는 경우, CSRF 보호가 꺼지면 외부 사이트가 상태 변경 요청을 유발할 수 있습니다.
frameOptions비활성화로 클릭재킹 방어가 약화될 수 있습니다.- 해당 필터 체인의
anyRequest().permitAll()은 적용 대상 요청에 인증을 요구하지 않으므로 보호할 기능도 공개될 수 있습니다.
해결 방법
- 브라우저 인증 방식을 확인하고 CSRF 보호를 유지하세요. 보호가 필요하지 않은 경로만 명시적으로 제외하세요. 한 체인의
csrf().disable()은 그 체인 전체에 적용됩니다. frameOptions().disable()대신sameOrigin또는 CSP의frame-ancestors를 사용합니다.anyRequest().permitAll()대신 허용 대상만 명시적으로 열고 나머지는 인증을 요구합니다.
예시
Spring Security 6.x 방식의 설정 발췌입니다. 구성 클래스 등록과 인증 방식은 별도로 준비하고, 사용 중인 버전에 맞는 DSL을 사용하세요.
변경 전
java
import org.springframework.context.annotation.Bean;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;
public class UnsafeCsrfConfig {
@Bean
SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
http.csrf().disable();
return http.build();
}
}
변경 후
java
import org.springframework.context.annotation.Bean;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;
public class SafeSecurityConfig {
@Bean
SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
http
.authorizeHttpRequests(auth -> auth
.requestMatchers("/health").permitAll()
.anyRequest().authenticated()
);
return http.build();
}
}
설명:
- 변경 전: 이 필터 체인에서 CSRF 보호를 비활성화합니다.
- 변경 후: 기본 CSRF 보호를 유지하고
/health만 인증 없이 허용하며 나머지 요청에는 인증을 요구합니다. 역할·객체별 인가 조건은 별도로 구성하세요.
다른 보호 설정 점검
프레임 제한과 전체 요청 허용 설정도 실제 의도에 맞는지 확인하세요. Java와 Kotlin DSL 모두 필요한 보호를 유지하고, 의도한 공개 경로만 허용해야 합니다.