本文へ移動
cccskills
無料GitHub で公開

ns-setup-google-auth

Set up and verify Google OAuth for NowStack Mobile web and Expo clients against the shared Better Auth and Convex backend. Use for Google sign-in buttons, Google Cloud OAuth clients, callback URLs, missing GOOGLE_CLIENT_ID or GOOGLE_CLIENT_SECRET, or production Google auth rotation.

インストール方法を見る

含まれるファイル(3)

  • SKILL.md5.1 KB
  • agents/openai.yaml390 B
  • assets/codex-icon.svg446 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Setup Google Auth - NowStack Mobile

<objective> Create a deployment-specific Google OAuth Web client, store its credentials only in the matching Convex deployment, and prove that both web and mobile discover the provider through `api.auth.getEnabledAuthProviders`. </objective> <arguments> - Default: configure the current Convex development deployment. - `--prod`: create a dedicated production OAuth client and write values with `npx convex env set --prod`. Never copy development OAuth credentials into production. </arguments>

<read_first> Read the auth feature flag and the real provider implementation before changing anything:

rg -n "enableGoogleSignIn|GOOGLE_CLIENT|google|getEnabledAuthProviders|CONVEX_SITE" \
  site-config.ts convex mobile-app web-app scripts
npx convex env list | sed 's/=.*$/=<set>/'
npx convex run auth:getEnabledAuthProviders '{}'

For --prod, also run:

npx convex env list --prod | sed 's/=.*$/=<set>/'
npx convex run --prod auth:getEnabledAuthProviders '{}'

Derive {convex_site_host} from the target deployment's .convex.site URL. The callback is always:

https://{convex_site_host}/api/auth/callback/google

</read_first>

<workflow> 1. Confirm `SiteConfig.features.enableGoogleSignIn` is enabled and Google is wired in `convex/auth.ts` plus the provider-availability query. Do not render a client button from the flag alone. 2. Use the user's authenticated Google Cloud session. Prefer `gcloud` for inspection and Chrome for Google Auth Platform steps that have no reliable CLI equivalent. 3. Select or create a dedicated Google Cloud project named from the product. Do not reuse an unrelated company project. In `--prod` mode, create a distinct production OAuth client even when the project is shared. 4. Configure Google Auth Platform branding: product name, support email, contact email, external audience when appropriate, required policy acceptance, and the real privacy/terms URLs for production. Stop only for human-only consent, 2FA, or policy gates. 5. Create an OAuth 2.0 Client ID of type **Web application**. Use an unmistakable name such as `{app} development` or `{app} production` and register the exact callback URL above. 6. If the current Google UI does not reveal the original secret, open the client detail and choose **Add secret**. Capture the new secret once and never put it in chat, logs, screenshots, or git-tracked files. 7. Set the target Convex environment. `SITE_URL` is the browser origin, not the Convex site URL:
# development
npx convex env set SITE_URL "http://localhost:3111"
npx convex env set GOOGLE_CLIENT_ID "<client>.apps.googleusercontent.com"
pbpaste | npx convex env set GOOGLE_CLIENT_SECRET

# production (--prod)
npx convex env set --prod SITE_URL "https://<production-app-domain>"
npx convex env set --prod GOOGLE_CLIENT_ID "<production-client>.apps.googleusercontent.com"
pbpaste | npx convex env set --prod GOOGLE_CLIENT_SECRET

On non-macOS systems, use the platform clipboard equivalent or pipe a protected runtime variable to the same value-less convex env set command. Never put the secret literal in the command line.

  1. Do not write these values to .env, .env.local, site-config.ts, docs, shell history, or build config. </workflow>
<verification> Verify without printing secret values:
# development
npx convex run auth:getEnabledAuthProviders '{}'

# production
npx convex run --prod auth:getEnabledAuthProviders '{}'

The result must report google: true. Then:

  1. Open the signed-out web sign-in route with the repo's browser-verification workflow.
  2. Confirm the Google button is visible.
  3. Click it and confirm the redirect reaches accounts.google.com, uses the expected client ID, and carries the exact target Convex callback.
  4. On mobile, reload the Expo app against the same target Convex deployment and confirm the Google button appears. Exercise the redirect/deep-link return when the environment supports it.

If the button is absent, check the feature flag, target deployment, both Convex env values, and query result before changing UI code. </verification>

<production_invariant> A production deployment is blocked until a production-specific Google OAuth client exists, its production callback is registered, its fresh client secret is stored with --prod, and the production provider query returns google: true. Development credentials are not a production shortcut. </production_invariant>

<success_criteria>

  • Correct deployment-specific callback registered in Google Cloud.
  • Client ID and secret exist only in the matching Convex environment.
  • Provider query reports Google enabled on the target deployment.
  • Web redirect and mobile provider visibility are verified.
  • Production never reuses the development OAuth client secret. </success_criteria>

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Complete guide for building beautiful apps with Expo Router. Covers fundamentals, styling, components, navigation, animations, patterns, and native tabs.

日本語の概要は準備中です。原文の説明を表示しています。

Melvynx/saveit.now322026年10月10日 更新

convex

無料

Routes general Convex requests to the right project skill. Use when the user asks which Convex skill to use or gives an underspecified Convex app task.

日本語の概要は準備中です。原文の説明を表示しています。

Melvynx/saveit.now322026年10月10日 更新

Use when optimizing Convex database read bandwidth, documents-read cost, query indexes, full-table scans, function-level usage dashboard findings, or code that uses .filter(), unbounded .collect(), N+1 reads, or expensive reactive Convex queries.

日本語の概要は準備中です。原文の説明を表示しています。

Melvynx/saveit.now322026年10月10日 更新

Build reusable Convex components with isolated tables and app-facing wrappers. Use for defineComponent, app.use, ComponentApi, or shared backend modules.

日本語の概要は準備中です。原文の説明を表示しています。

Melvynx/saveit.now322026年10月10日 更新

Plan safe Convex schema and data migrations. Use for widen-migrate-narrow rollouts, backfills, breaking field changes, table splits, or failed schema deploys.

日本語の概要は準備中です。原文の説明を表示しています。

Melvynx/saveit.now322026年10月10日 更新

Audit Convex performance for hot reads, write contention, subscriptions, function limits, OCC conflicts, latency, read amplification, and expensive reactive queries.

日本語の概要は準備中です。原文の説明を表示しています。

Melvynx/saveit.now322026年10月10日 更新

Melvynx のスキルをすべて見る

このスキルの問題を報告する