Skip to content

[Fix/#56] 스캐너·봇으로 인한 401 로그 노이즈 정리 - #57

Merged
tnals0924 merged 2 commits into
mainfrom
fix/#56-suppress-scanner-log-noise
Sep 22, 2026
Merged

tnals0924 merged 2 commits into
mainfrom
fix/#56-suppress-scanner-log-noise

Conversation

@tnals0924

Copy link
Copy Markdown
Member

#️⃣연관된 이슈

🎯 해결하려는 문제가 무엇인가요?

인터넷에 노출된 서버에 봇·스캐너가 GET /, /robots.txt, /favicon.ico 등을 상시 요청한다. 이 요청들은 인증 토큰이 없어 전부 401로 차단되지만, 요청 1건당 GlobalExceptionHandler의 WARN 1줄 + AccessLogFilter의 INFO 1줄이 쌓여 로그 노이즈가 심하다.

❓ 왜 해결해야 하나요?

실제 위협은 없는데(이미 401로 차단) WARN 레벨 로그가 대량으로 남아 정작 봐야 할 경고가 묻힌다. 인터넷 노출 서버에서 인증 실패는 상시 발생하는 정상 트래픽에 가깝다.

⭐ 어떻게 해결했나요?

  • GlobalExceptionHandler.handleBusiness: status가 401(ErrorStatus.UNAUTHORIZED)이면 WARN → DEBUG. 403 등 나머지 도메인 예외는 WARN 유지.
  • LoggingExclusions: /, /robots.txt, /favicon.ico를 노이즈 경로로 추가해 액세스 로그·MDC 대상에서 제외(헬스체크와 동일한 취급).

prod 로그 레벨이 kr.ac.kookmin: INFO라 401 DEBUG는 출력되지 않고, dev는 DEBUG라 로컬 디버깅 시에는 그대로 보인다.

🧩 이 PR의 한계 & 트레이드오프

  • 401을 전부 DEBUG로 낮췄으므로, 정상 유저가 만료 토큰으로 401을 받는 경우도 prod에서 WARN으로 남지 않는다(응답은 정상적으로 401 반환).
  • 노이즈 경로는 명시적 리스트 방식이라 /.env, /wp-login.php 같은 리스트 밖 스캐너 경로는 여전히 401 + 액세스 로그 1줄이 남는다. 필요 시 NOISE_PATHS에 추가한다.

⛓️ 기존 기능에 미치는 영향

  • 로깅 동작만 변경. 응답 상태코드·바디는 그대로다.
  • LoggingExclusions는 MdcFilter·AccessLogFilter가 공유하므로 추가된 경로는 MDC도 붙지 않는다.

🔀 Edge Case & 실패 시나리오

  • 만료/무효 토큰으로 인한 401: 응답은 동일, prod 로그에는 미출력(dev에선 DEBUG로 확인 가능).
  • 리스트 외 스캐너 경로: 401 응답 + 액세스 로그 INFO 1줄 유지.

📋 검토한 대안과 선택 이유

  • /favicon.ico 등을 permitAll로 푸는 방안: 서빙할 정적 리소스가 없어 통과 후 404 또는 catch-all 예외 핸들러를 타 500 + ERROR 스택트레이스로 악화될 수 있어 배제.
  • 액세스 로그에서 401 전부 제외(status 기반): 정상 유저의 401까지 무조건 사라져, 경로 기반 명시 제외를 선택.

💬 리뷰 포인트

  • [c] 401 → DEBUG 하향 범위가 적절한지(403 등은 WARN 유지)
  • [a] NOISE_PATHS 초기 경로 구성이 적절한지

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: billilge/stream-server/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 455583c3-f928-4d70-bc76-d27829745a6d

📥 Commits

Reviewing files that changed from the base of the PR and between 958756b and 624d6fc.

📒 Files selected for processing (2)
  • api/common-api/src/main/java/kr/ac/kookmin/stream/api/common/GlobalExceptionHandler.java
  • gateway/logging/src/main/java/kr/ac/kookmin/stream/logging/LoggingExclusions.java

Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

UNAUTHORIZED 예외의 로그 수준을 DEBUG로 변경했다. /actuator/health 하위 경로와 지정된 노이즈 경로를 로깅 제외 대상으로 추가했다. 응답 처리 방식은 유지된다.

Changes

로그 노이즈 필터링

Layer / File(s) Summary
로그 기록 조건 조정
api/common-api/.../GlobalExceptionHandler.java, gateway/logging/.../LoggingExclusions.java
UNAUTHORIZED 비즈니스 예외는 DEBUG로 기록한다. 그 외 비즈니스 예외는 WARN을 유지한다. 헬스체크 및 /, /robots.txt, /favicon.ico 경로를 제외한다.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 624d6

인증 실패와 지정된 노이즈 경로의 로그만 줄이고 응답 동작은 유지하므로, 현재 병합을 막을 위험은 없습니다.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed 제목은 401 로그 노이즈 감소와 스캐너·봇 요청 처리를 명확히 요약하며 실제 변경 범위와 일치합니다.
Description check ✅ Passed 문제, 필요성, 구현 방식, 한계, 영향 범위, 예외 시나리오, 대안, 리뷰 포인트를 모두 설명합니다. 템플릿의 필수 정보가 충분히 포함되어 있습니다.
Linked Issues check ✅ Passed [#56] GlobalExceptionHandler.handleBusiness는 ErrorStatus.UNAUTHORIZED일 때만 DEBUG를 사용하고, 그 외 BusinessException은 기존처럼 WARN으로 기록합니다. 응답 상태와 바디 생성 코드는 유지됩니다. LoggingExclusions는 /, `/robots.tx…
Out of Scope Changes check ✅ Passed 변경은 GlobalExceptionHandler의 401 로그 레벨 분기와 로깅 제외 경로 확장에 한정됩니다. 두 변경 모두 직접 연결된 이슈 [#56]의 요구사항과 연결됩니다. 다른 도메인 예외의 처리나 응답 형식 변경은 확인되지 않습니다.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@tnals0924
tnals0924 merged commit 7c9871f into main Sep 22, 2026
2 checks passed
@tnals0924
tnals0924 deleted the fix/#56-suppress-scanner-log-noise branch September 22, 2026 09:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

스캐너·봇으로 인한 401 로그 노이즈 정리

2 participants