本文へ移動
cccskills
無料GitHub で公開

auth-system-setup

When the user wants to set up authentication and authorization for a web application. Use when the user mentions "auth," "login," "OAuth," "SSO," "single sign-on," "role-based access," "RBAC," "permissions," "user roles," "access control," "authentication," or "authorization." Covers OAuth 2.0 provider integration, session management, and role/permission architecture. For JWT-specific tasks, see jwt-handler. For security review, see security-audit.

インストール方法を見る

含まれるファイル(2)

  • SKILL.md5.2 KB
  • _scores.json1.7 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Auth System Setup

Overview

Designs and implements complete authentication and authorization systems for web applications. Covers OAuth 2.0 provider integration (Google, GitHub, Microsoft), session and token management, role-based access control (RBAC), and permission architectures. Generates production-ready code, database migrations, and tests.

Instructions

1. Gather Requirements

Before generating any code, determine:

  • Tech stack: Backend framework, database, frontend framework
  • Auth method: OAuth providers, email/password, magic links, or combination
  • Roles needed: What roles exist? What can each role do?
  • Token strategy: Stateless JWT, server-side sessions, or hybrid
  • Compliance: GDPR, SOC 2, HIPAA — affects data storage and logging

2. Design the Auth Architecture

Create the auth flow diagram and data model:

  • User table: id, email, name, avatar, provider, provider_id, created_at
  • Role table: id, name, description
  • Permission table: id, resource, action (read/write/delete)
  • Role-Permission mapping: role_id, permission_id
  • User-Role mapping: user_id, role_id
  • Refresh token table: id, user_id, token_hash, family_id, expires_at, revoked_at

3. Implement OAuth Flow

For each OAuth provider:

  1. Create provider configuration (client ID, secret, scopes, callback URL)
  2. Implement the authorization redirect with state parameter and PKCE
  3. Handle the callback: exchange code for tokens, extract user profile
  4. Provision or update the user record
  5. Issue application tokens (access + refresh)

Always use PKCE for public clients. Always validate the state parameter.

4. Implement RBAC

Generate the permission-checking middleware:

authorize(resource, action) → middleware function
  1. Extract user from request (via JWT or session)
  2. Load user roles and permissions (cache with TTL)
  3. Check if any role grants the required permission
  4. Return 403 with clear error if denied

For row-level security, add ownership filters:

filterByOwnership(resource) → middleware function
  1. If user role has wildcard access, skip filter
  2. Otherwise, add WHERE clause: resource.owner_id = user.id
  3. Apply to SELECT, UPDATE, DELETE queries

5. Generate Tests

Create tests for:

  • OAuth flow: successful login, invalid state, expired code
  • Token lifecycle: issue, refresh, rotate, revoke
  • RBAC: each role accessing allowed and denied resources
  • Edge cases: expired tokens, revoked refresh tokens, role changes mid-session

Examples

Example 1: Express + PostgreSQL + Google OAuth

Prompt: "Set up Google OAuth with JWT tokens for my Express app. I need admin and user roles."

Output:

  • auth/providers/google.ts — OAuth 2.0 + PKCE flow
  • auth/middleware/authenticate.ts — JWT verification
  • auth/middleware/authorize.ts — Role checker
  • migrations/001_auth_tables.sql — Users, roles, permissions, refresh_tokens
  • auth/services/token.service.ts — JWT issuance with refresh rotation
  • auth/routes.ts — /auth/google, /auth/callback, /auth/refresh, /auth/logout
  • tests/auth.test.ts — 18 integration tests

Example 2: Django + GitHub OAuth + Multi-tenant RBAC

Prompt: "Add GitHub login to my Django app. Each organization has its own roles: owner, editor, viewer."

Output:

  • accounts/providers/github.py — OAuth integration via django-allauth
  • accounts/models.py — Organization, Membership, Role models
  • accounts/permissions.py — Per-organization permission backend
  • accounts/middleware.py — Org context middleware (from subdomain or header)
  • accounts/decorators.py — @require_org_role('editor') decorator
  • migrations/0001_multi_tenant_auth.py — Schema migration
  • tests/test_permissions.py — 22 test cases across org boundaries

Guidelines

  • Never store plain-text passwords — use bcrypt with cost factor 12+ or argon2id
  • Always use PKCE for OAuth flows, even with confidential clients
  • Rotate refresh tokens on every use — detect reuse to identify token theft
  • Set short access token TTL — 15 minutes is the standard
  • Cache permissions — reload on role change, not on every request
  • Log auth events — login, logout, failed attempts, role changes (for audit trail)
  • Rate limit auth endpoints — prevent brute force on login and token refresh
  • Use httpOnly, Secure, SameSite=Strict cookies for refresh tokens in browsers
  • Never put sensitive data in JWT payload — it's base64, not encrypted

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Scripts and configures production rendering in Autodesk 3ds Max with the V-Ray and Corona renderers: output size and files, render elements, denoising, light mix, batch and command-line rendering, and network rendering. Use when a user asks to set up a production render, render several cameras in one batch, render from the command line or on a render farm, add render passes for compositing, or cut render time for archviz and product shots.

日本語の概要は準備中です。原文の説明を表示しています。

TerminalSkills/skills1632026年10月4日 更新

Covers scripting Autodesk 3ds Max, the 3D modeling and rendering application, with MAXScript and Python (pymxs): scene manipulation, object creation, material assignment, camera and light setup, batch operations, and file I/O. Use when tasks involve automating repetitive 3ds Max workflows, batch processing scenes, running scripts headless with 3dsmaxbatch, creating custom tools, or scripting scene setup for archviz, product visualization, or VFX.

日本語の概要は準備中です。原文の説明を表示しています。

TerminalSkills/skills1632026年10月4日 更新

3proxy

無料

3proxy is a small open-source proxy server that runs HTTP/HTTPS, SOCKS4/5, SNI and TCP/UDP port-mapping proxies from one config file. Use when a user asks to set up an HTTP or SOCKS5 proxy, add proxy users and passwords, write 3proxy access rules, chain or rotate upstream (parent) proxies, limit bandwidth, connections or monthly traffic per user, run 3proxy in Docker, or fix a 3proxy.cfg that will not start.

日本語の概要は準備中です。原文の説明を表示しています。

TerminalSkills/skills1632026年10月4日 更新

Builds Agent2Agent (A2A) servers and clients, the open protocol (originally from Google, now under the Linux Foundation) that lets AI agents from different frameworks call each other. Use when the user wants to create an A2A-compliant agent, build an Agent Card, implement task management, connect agents across frameworks, set up agent discovery, handle streaming responses, implement push notifications, or orchestrate multi-agent workflows. Trigger words: a2a, agent to agent, agent2agent, a2a protocol, a2a server, a2a client, agent card, agent interoperability, agent collaboration, multi-agent, agent discovery, a2a sdk, a2a task.

日本語の概要は準備中です。原文の説明を表示しています。

TerminalSkills/skills1632026年10月4日 更新

Plans a controlled experiment (A/B test) so its result can be trusted: writes the hypothesis, picks one primary metric and the guardrails, computes sample size and run time, specifies how visitors are assigned and when exposure is logged, and reads out the result with a confidence interval. Use when someone says "set up an A/B test", "split test this page", "how many visitors do I need", "how long should the experiment run", "is this result significant", "can I stop the test early", or wants to test a headline, price, layout or onboarding change against the current version.

日本語の概要は準備中です。原文の説明を表示しています。

TerminalSkills/skills1632026年10月4日 更新

ably

無料

Ably is a hosted realtime messaging service: clients publish and subscribe to named channels over WebSockets, see who is present, replay message history, and resume after a dropped connection. Use when a user asks to "add realtime updates", "push live notifications to the browser", "show who is online", "add a chat room with typing indicators", "publish from a serverless function", or "authenticate Ably clients without exposing the API key". Covers the ably 2.x JavaScript SDK (Realtime and REST), JWT token authentication, presence, history and rewind, batch publishing, and the @ably/chat 1.x SDK.

日本語の概要は準備中です。原文の説明を表示しています。

TerminalSkills/skills1632026年10月4日 更新

TerminalSkills のスキルをすべて見る

このスキルの問題を報告する