Skip to content

[FIX] 온보딩 미완료 사용자의 홈(main 라우트) 접근 제한#273

Merged
jjangminii merged 1 commit into
developfrom
fix/web/272-restrict-home-access-without-onboarding
Jul 17, 2026
Merged

[FIX] 온보딩 미완료 사용자의 홈(main 라우트) 접근 제한#273
jjangminii merged 1 commit into
developfrom
fix/web/272-restrict-home-access-without-onboarding

Conversation

@kimminna

Copy link
Copy Markdown
Member

ISSUE 🔗

close #272



What is this PR? 🔍

온보딩을 완료하지 않은 사용자가 /home을 포함한 (main) 라우트에 접근할 수 있던 버그를 수정했습니다.

배경

  • 기존 구조: (main) 레이아웃은 AuthGuardProvider로만 보호되어 있었고, AuthGuardProvideraccessToken 존재 여부만 검사했습니다. 온보딩 완료 여부(onboardingCompleted)를 검사하는 가드는 OnboardingCompletedGuardProvider 하나뿐이었는데, 이는 /onboarding 페이지에서 이미 온보딩을 완료한 사용자를 /home으로 내보내는 반대 방향 가드였습니다.
  • 발생 문제: 로그인은 했지만 온보딩을 완료하지 않은 사용자가 /home(main) 라우트로 직접 접근하면, 온보딩을 건너뛴 채 홈 화면에 그대로 진입할 수 있었습니다.
  • 해결 방향: onboardingCompletedfalse인 사용자를 /onboarding으로 리다이렉트하는 반대 방향 가드를 새로 만들고, (main) 레이아웃에 적용했습니다.

온보딩 접근 가드

  • 변경 요약: OnboardingRequiredGuardProvider를 신설하고 (main)/layout.tsx에서 AuthGuardProvider 하위에 적용했습니다.
  • 이유: 인증 여부(accessToken)와 온보딩 완료 여부(onboardingCompleted)는 서로 다른 조건이라 하나의 가드가 두 책임을 모두 지지 않도록 분리했습니다. AuthGuardProvider/onboarding 페이지에서도 그대로 재사용되고 있어, 만약 AuthGuardProvider 자체에 온보딩 완료 검사를 추가하면 온보딩 미완료 사용자가 온보딩 페이지 자체에 진입하지 못하는 리다이렉트 루프가 생기기 때문에 별도 컴포넌트로 분리했습니다.
  • 구현 방식: 기존 OnboardingCompletedGuardProvider와 동일한 패턴으로, useAuthStore에서 onboardingCompleted, isInitialized를 구독해 isInitialized && !onboardingCompleted일 때 router.replace(ROUTES.ONBOARDING)을 호출합니다. isInitialized가 끝나기 전이나 온보딩이 미완료 상태면 children을 렌더링하지 않고 null을 반환해 리다이렉트 전 깜빡임을 막습니다.
  • 경계 · 제약: /onboarding 페이지 자체는 이번 가드의 적용 대상이 아닙니다 (AuthGuardProvider만 적용되어 있고, OnboardingRequiredGuardProvider(main) 레이아웃에만 적용됩니다).



To Reviewers

AuthGuardProvider/onboarding 페이지와 (main) 레이아웃 양쪽에서 공유되고 있어, AuthGuardProvider 자체를 수정하는 대신 온보딩 완료 검사를 별도 OnboardingRequiredGuardProvider로 분리해 (main) 레이아웃에만 적용했습니다. 이 분리가 적절한지 확인 부탁드립니다.

Screenshot 📷

Test Checklist ✔

  • pnpm check-types 통과
  • pnpm lint 통과
  • pnpm build 통과
  • 브라우저에서 온보딩 미완료 계정으로 /home 직접 접근 시 /onboarding 리다이렉트 확인 — 미실행: 로컬 인증 계정 없어 재현 불가

- 온보딩 미완료 사용자를 /onboarding으로 리다이렉트하는 OnboardingRequiredGuardProvider를 추가했습니다
- (main) 레이아웃에 해당 가드를 적용해 /home 등 메인 라우트 접근을 막았습니다
@vercel

vercel Bot commented Jul 17, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
timo Ready Ready Preview, Comment Jul 17, 2026 8:28am

Request Review

@github-actions github-actions Bot added the ⏰ Timo-web Timo 웹 서비스 label Jul 17, 2026
@coderabbitai

coderabbitai Bot commented Jul 17, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@kimminna, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 33 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 52f5f4bf-832e-41e7-9746-180a353bf4ca

📥 Commits

Reviewing files that changed from the base of the PR and between fd06b80 and bb1246d.

📒 Files selected for processing (2)
  • apps/timo-web/app/[locale]/(main)/layout.tsx
  • apps/timo-web/providers/auth/OnboardingRequiredGuardProvider.tsx
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/web/272-restrict-home-access-without-onboarding

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added 🐛 Bug 기능이 정상적으로 작동하지 않는 문제 수정 ♦️ 민아 민아상 labels Jul 17, 2026
@github-actions

Copy link
Copy Markdown

Timo Performance Report

Bundle Size — timo-web
라우트 크기 First Load JS
/[locale]/home 214.30 kB 🔴 420.19 kB
/[locale]/today 198.46 kB 🔴 404.35 kB
/[locale]/focus 162.13 kB 🔴 368.03 kB
/[locale]/settings 168.97 kB 🔴 374.86 kB
/[locale]/statistics 155.88 kB 🔴 361.77 kB
/[locale]/[...rest] 0 B 🟡 205.89 kB
/[locale]/login 213.91 kB 🔴 419.80 kB
/[locale]/oauth/calendar/callback 120.93 kB 🟡 326.82 kB
/[locale]/oauth/callback 120.60 kB 🟡 326.49 kB
/[locale]/onboarding 234.66 kB 🔴 440.56 kB
/[locale] 119.91 kB 🟡 325.80 kB
/[locale]/policy 126.04 kB 🟡 331.93 kB
/robots.txt/route 0 B 🟡 205.89 kB
/sitemap.xml/route 0 B 🟡 205.89 kB

공유 번들: 205.89 kB
🟢 < 200kB  |  🟡 < 350kB  |  🔴 ≥ 350kB (First Load JS · gzip)

Lighthouse — timo-web
URL Perf A11y LCP CLS TBT
/en/home 🔴 59 🟢 95 🔴 15.8s 🟢 0.000 🟡 592ms
/en/today 🔴 61 🟢 95 🔴 15.6s 🟢 0.000 🟡 545ms
/en/focus 🔴 60 🟢 95 🔴 15.2s 🟢 0.000 🟡 545ms
/en/statistics 🔴 56 🟢 95 🔴 15.0s 🟢 0.000 🔴 749ms

Perf ≥ 70 / A11y ≥ 85 목표
LCP 🟢 < 2.5s 🟡 < 4s 🔴 ≥ 4s  |  CLS 🟢 < 0.1 🟡 < 0.25 🔴 ≥ 0.25  |  TBT 🟢 < 200ms 🟡 < 600ms 🔴 ≥ 600ms

Image Optimization — timo-web
파일 크기 포맷 상태
favicon.png 27.84 kB PNG ⚠️ 🟢
images/google-calendar.png 36.20 kB PNG ⚠️ 🟢
images/google-logo.png 26.79 kB PNG ⚠️ 🟢
og.png 437.44 kB PNG ⚠️ 🟡

총 4개 · 528.28 kB  |  🟢 < 200KB  |  🟡 < 500KB  |  🔴 ≥ 500KB
⚠️ 4개 파일 WebP/AVIF 변환 권장

측정 커밋: 449d878

@jjangminii jjangminii left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

체크아웃해서 확인했습니다~

@jjangminii
jjangminii merged commit 0eb2cc6 into develop Jul 17, 2026
13 checks passed
@kimminna
kimminna deleted the fix/web/272-restrict-home-access-without-onboarding branch July 17, 2026 08:53
@jjangminii jjangminii mentioned this pull request Jul 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

⏰ Timo-web Timo 웹 서비스 ♦️ 민아 민아상 🐛 Bug 기능이 정상적으로 작동하지 않는 문제 수정

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FIX] 온보딩 미완료 사용자의 홈(main 라우트) 접근 제한

2 participants