Jenkins & GitHub Webhook : 403 No valid crumb was included in the request - boostcamp-2020/IssueTracker-14 GitHub Wiki

๋ฌธ์ œ์ 

Jenkins๋ฅผ ์ด์šฉํ•œ ์ž๋™ ๋ฐฐํฌ๋ฅผ ์„ค์ •ํ•˜๋˜ ์ค‘ ๋งˆ์ง€๋ง‰์œผ๋กœ GitHub Webhook๋งŒ ์„ค์ •ํ•˜๋ฉด ๋˜๋Š”๋ฐ ๊ณ„์†ํ•ด์„œ ๋‚˜๋Š” ์•„๋ž˜์™€ ๊ฐ™์€ ์—๋Ÿฌ!

ํ•ด๊ฒฐ๋ฐฉ๋ฒ•

๊ตฌ๊ธ€์„ ์ฐพ์•„ ๋ณธ ๊ฒฐ๊ณผ 403 No valid crumb was included in the request๋Š” Jenkins์˜ CSRF์™€ ๊ด€๋ จ๋œ ๋ฌธ์ œ์˜€๋‹ค. ๊ทธ๋ž˜์„œ 'Configure Global Security'์—์„œ CSRF Protection์˜ Crumb Issuer๋ฅผ ์ถ”๊ฐ€ ํ”Œ๋Ÿฌ๊ทธ์ธ์„ ์„ค์น˜ํ•ด ์ตœ๋Œ€ํ•œ ๋А์Šจํ•˜๊ฒŒ ๋งŒ๋“ค์–ด ๋ณด์•˜์ง€๋งŒ ์ž‘๋™ํ•˜์ง€ ์•Š์•˜๋‹ค. ๊ณ„์†ํ•ด์„œ ๋ฌด์˜๋ฏธํ•œ ์‹œ๋„๊ฐ€ ์ด์–ด์กŒ๊ณ  ๊ตฌ๊ธ€์— ๋‚˜์™€์žˆ๋Š” ํ•ด๋‹น ๊ด€๋ จ๋œ ์ •๋ง ๊ฑฐ์˜ ๋ชจ๋“  ๊ธ€์„ ์‚ดํŽด ๋ณด๋˜ ์ค‘ ์–ด๋–ค ์‚ฌ์ดํŠธ์˜ ์ž‘์€ ๋ถ€๋ถ„์— Nginx ๋•Œ๋ฌธ์— ๋ฐœ์ƒํ•œ ๋ฌธ์ œ๋ผ๋Š” ๊ธ€์„ ๋ณด์•˜๋‹ค. Nginx์˜ Authentication๊ณผ ๊ด€๋ จํ•ด ๋ฌธ์ œ๊ฐ€ ์ƒ๊ธด ๊ฒƒ์ด๋ผ์„œ Payload URL์— id์™€ pw๋ฅผ ๊ฐ™์ด ์ž…๋ ฅํ•ด์ฃผ์–ด์•ผ ํ•œ๋‹ค๋Š” ๊ฒƒ์ด์—ˆ๋‹ค. ๊ทธ ๊ฒฐ๊ณผ ๋“œ๋””์–ด ์„ฑ๊ณต. Nginx๋ฅผ ์ด์šฉํ•ด์„œ ๋„์šฐ์‹œ๋Š” ๋ถ„๋“ค์€ ๊ผญ Payload URL์— ์•„์ด๋””์™€ ํŒจ์Šค์›Œ๋“œ๋ฅผ ๋„ฃ๋„๋ก ํ•˜์„ธ์š”...