Quarkusアプリの認証・アクセス権限・入力検証を実装し、安全性を見直します。秘密情報の管理、パスワード保存、アクセス制限、監査ログや依存関係の点検も扱います。
- Quarkus APIにJWTやOIDC認証を追加したいとき
- 役割別の権限と所有者確認の点検
- 入力検証とデータベース検索の見直し
1,065 件 ・ 関連度順
概要と使いどころ
Quarkusアプリの認証・アクセス権限・入力検証を実装し、安全性を見直します。秘密情報の管理、パスワード保存、アクセス制限、監査ログや依存関係の点検も扱います。
Laravelの機能をテストから実装し、モデルやAPI、認証・権限を検証するスキル。PHPUnitやPestでのテスト作成、外部サービスの模擬化、カバレッジ確認を支援します。
FastAPI のアプリ開発やレビューで、構成・入力検証・認証・権限確認・非同期処理・データベース更新・テストの設計と実装を支えるスキル。
Djangoアプリのログイン、権限、入力処理、本番設定を点検します。不正な操作やスクリプト実行への対策から、ファイル投稿とAPIの保護まで見直すスキル。
Agent skill for authentication - invoke with $agent-authentication
日本語の概要は準備中です。原文の説明を表示しています。
Discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing authentication controls during authorized security assessments.
日本語の概要は準備中です。原文の説明を表示しています。
Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer (MS-RPRN, MS-DFSNM, MS-FSRVP, MS-EVEN) via Coercer's scan/coerce/fuzz modes, feeding the coerced NTLM auth into a relay against AD CS Web Enrollment (ESC8), LDAP (RBCD), or SMB. Use in authorized engagements to complete a coercion-relay chain against a Domain Controller, or to validate coercion detections and signing/EPA mitigations.
日本語の概要は準備中です。原文の説明を表示しています。
Use when building high-performance async Python APIs with FastAPI and Pydantic V2. Invoke to create REST endpoints, define Pydantic models, implement authentication flows, set up async SQLAlchemy database operations, add JWT authentication, build WebSocket endpoints, or generate OpenAPI documentation. Trigger terms: FastAPI, Pydantic, async Python, Python API, REST API Python, SQLAlchemy async, JWT authentication, OpenAPI, Swagger Python.
日本語の概要は準備中です。原文の説明を表示しています。
Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID setup, Azure AD authentication. DO NOT USE FOR: Key Vault secrets (use azure-keyvault-expiration-audit), general Azure resource security guidance.
日本語の概要は準備中です。原文の説明を表示しています。
Install and configure Apollo.io API authentication. Use when setting up a new Apollo integration, configuring API keys, or initializing Apollo client in your project. Trigger with phrases like "install apollo", "setup apollo api", "apollo authentication", "configure apollo api key".
日本語の概要は準備中です。原文の説明を表示しています。
Select and prove the correct Adobe authentication model, entitlement, product profile, and secret lifecycle before integration work. Use when creating or repairing Adobe credentials. Trigger with "set up Adobe auth", "Adobe OAuth server-to-server", or "Adobe user authentication".
日本語の概要は準備中です。原文の説明を表示しています。
Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID setup, Azure AD authentication. DO NOT USE FOR: Key Vault secrets (use azure-keyvault-expiration-audit), general Azure resource security guidance.
日本語の概要は準備中です。原文の説明を表示しています。
Provides authentication implementation patterns for Next.js 15+ App Router using Auth.js 5 (NextAuth.js). Use when setting up authentication flows, implementing protected routes, managing sessions in Server Components and Server Actions, configuring OAuth providers, implementing role-based access control, or handling sign-in/sign-out flows in Next.js applications.
日本語の概要は準備中です。原文の説明を表示しています。
Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
日本語の概要は準備中です。原文の説明を表示しています。
Provides auth patterns for API keys, OAuth, and token management. Use when implementing or reviewing service authentication and credential handling.
日本語の概要は準備中です。原文の説明を表示しています。
Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings. Use when: (1) Password authentication fails with correct password, (2) Secret created with `<<< "value"` syntax, (3) Error like "password authentication failed" or "invalid token" despite correct value. Bash here-strings (`<<<`) add a trailing newline that corrupts secrets.
日本語の概要は準備中です。原文の説明を表示しています。
Instruments authentication, authorization, and input-handling code paths to monitor security-relevant events and states at runtime. Use this skill when developers need to add security monitoring and logging to their code, including tracking authentication attempts (login/logout), authorization decisions (access control checks), input validation failures, session management events, and other security-critical operations. Supports Python, JavaScript/TypeScript, and Java with structured logging patterns. Triggers when users ask to add security instrumentation, monitor security events, log authentication/authorization, track security-sensitive operations, or add security observability to their codebase.
日本語の概要は準備中です。原文の説明を表示しています。
Secure API authentication with JWT, OAuth 2.0, API keys. Use for authentication systems, third-party integrations, service-to-service communication, or encountering token management, security headers, auth flow errors.
日本語の概要は準備中です。原文の説明を表示しています。
Expert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user syncUse when "adding authentication, clerk auth, user authentication, sign in, sign up, user management, multi-tenancy, organizations, sso, single sign-on, clerk, authentication, auth, user-management, multi-tenancy, organizations, sso, oauth" mentioned.
日本語の概要は準備中です。原文の説明を表示しています。
Authentication and authorization expert for OAuth, sessions, JWT, MFA, and identity securityUse when "authentication flow, login system, oauth integration, jwt tokens, session management, password hashing, mfa setup, refresh tokens, social login, role-based access, authentication, authorization, oauth, oidc, jwt, sessions, mfa, passkeys, nextauth, supabase-auth, clerk" mentioned.
日本語の概要は準備中です。原文の説明を表示しています。
When the user wants to set up authentication and authorization for a web application. Use when the user mentions "auth," "login," "OAuth," "SSO," "single sign-on," "role-based access," "RBAC," "permissions," "user roles," "access control," "authentication," or "authorization." Covers OAuth 2.0 provider integration, session management, and role/permission architecture. For JWT-specific tasks, see jwt-handler. For security review, see security-audit.
日本語の概要は準備中です。原文の説明を表示しています。
Authentication & Authorization Implementation Patterns workflow skill. Use this skill when the user needs Build secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
日本語の概要は準備中です。原文の説明を表示しています。
Authentication & Authorization Implementation Patterns workflow skill. Use this skill when the user needs Build secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
日本語の概要は準備中です。原文の説明を表示しています。
Authentication & Authorization Implementation Patterns workflow skill. Use this skill when the user needs Build secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
日本語の概要は準備中です。原文の説明を表示しています。