本文へ移動
cccskills
無料GitHub で公開

mobile-auth

Use this skill when working on login, logout, session restore, tokens, route guards, or any authentication and authorization behavior.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md1.7 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

mobile-auth — Canonical Skill

Purpose

Preserve the verified JWT + refresh-token auth model and its security boundaries.

When to use

Login/logout, token storage/refresh, multi-account switch, guards, biometric or OAuth proposals (verify-first — neither is implemented).

Required reading

  • skills/mobile/AUTH.md
  • skills/mobile/API.md
  • docs/agent/API_INTEGRATION_CONTRACT.md

Relevant project locations

  • src/composables/useAuthen.ts, src/composables/useAppStorage.ts
  • src/stores/authenStore.ts, src/api/AuthenService.ts, src/router/index.ts

Mandatory rules

  1. Tokens live in Capacitor Preferences (AppAuthTokenKey_<uid> etc.) — no secure-storage plugin exists (documented risk); never copy tokens.
  2. 401 → shared refresh + retry via /api/auth/refreshTokenApi in useApi.ts; refresh-403 → removeAuthToken() + login redirect.
  3. Guard rule: noRequireAuth === true or valid authenticationToken.
  4. Frontend role checks are UI-only; backend authorization is authoritative. Never log request bodies/headers/responses carrying tokens (useApi logs url/method/status only).

Implementation workflow

  1. Trace token lifecycle (signin → store → attach → refresh → logout).
  2. Test concurrent-401, failed-refresh, resume-after-background, switch-user.
  3. Confirm logout cleanup (tokens, FCM unregister, cached user data).
  4. Verify per mobile-testing, incl. SECURITY checklist.

Verification

Auth-flow tests with mocked storage/API; no hardcoded secrets or logged tokens; device needed for resume/background proof.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use this skill when adding or changing REST API calls, HTTP client config, error handling, uploads/downloads, or network behavior.

日本語の概要は準備中です。原文の説明を表示しています。

bekaku/vue-ionic-example-app62026年10月5日 更新

Use this skill when building, syncing Capacitor, or preparing Android/iOS releases and environment configuration.

日本語の概要は準備中です。原文の説明を表示しています。

bekaku/vue-ionic-example-app62026年10月5日 更新

Use this skill when creating, modifying, or debugging Ionic Vue components, pages, forms, dialogs, or theme/safe-area UI behavior.

日本語の概要は準備中です。原文の説明を表示しています。

bekaku/vue-ionic-example-app62026年10月5日 更新

Use this skill for any Ionic Vue + Capacitor mobile work: Vue architecture, Composition API, TypeScript, state, env config, shared conventions. Required for every implementation task alongside mobile-testing.

日本語の概要は準備中です。原文の説明を表示しています。

bekaku/vue-ionic-example-app62026年10月5日 更新

Use this skill when handling inbound URLs, custom schemes, app links, universal links, or URL-bearing notification payloads.

日本語の概要は準備中です。原文の説明を表示しています。

bekaku/vue-ionic-example-app62026年10月5日 更新

Use this skill when working on camera, gallery, file pick/upload/download, file preview, sharing, or filesystem-backed media. For Preferences keys, use mobile-local-data.

日本語の概要は準備中です。原文の説明を表示しています。

bekaku/vue-ionic-example-app62026年10月5日 更新

bekaku のスキルをすべて見る

このスキルの問題を報告する