跳到正文
FunCoding

搜索

搜索文档、Skill 和 MCP

authentication-patterns

Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Use when implementing auth, reviewing auth flows, or choosing auth providers.

数据库与数据4.7kskills/authentication-patterns/SKILL.md

安装

把这段话发给 Claude Code、Codex 或 Cursor。智能体会先检查安全性,你确认后才安装。

读取 https://funcoding.ai/skills/zebbern/claude-code-guide/authentication-patterns/install.md ,按里面的步骤帮我安装这个 Skill。

SKILL.md

Authentication Patterns Skill

Reference for implementing secure, production-ready authentication.

WHEN_TO_USE

Apply this skill when implementing authentication in a project, reviewing existing auth flows for security issues, choosing between auth providers, or migrating between auth strategies. Use the security checklist before shipping any auth-related change.

AUTH_APPROACHES

ApproachHow It WorksBest ForDrawbacks
Session-basedServer stores session in DB/Redis, client holds session ID cookieTraditional server-rendered apps, apps needing instant revocationRequires server-side storage, harder to scale horizontally without shared store
JWT (stateless)Server signs token, client sends it on each requestAPI-first apps, microservices, mobile clientsCannot revoke without blocklist, token size grows with claims
OAuth 2.0 / OIDCDelegates auth to external provider (Google, GitHub, etc.)Social login, enterprise SSO, reducing auth responsibilityMore complex flow, depends on external provider availability
Passkeys / WebAuthnCryptographic key pair, no passwordsHigh-security apps, passwordless UXLimited browser support legacy, user education needed

Decision Guide

  • Server-rendered app with simple needs → Session-based
  • SPA or mobile app calling APIs → JWT with refresh token rotation
  • Want social login or SSO → OAuth 2.0 / OIDC
  • Greenfield with modern UX goals → Passkeys + OAuth fallback

JWT_BEST_PRACTICES

Token Lifecycle

Login → Access Token (short-lived) + Refresh Token (long-lived, rotated)
  │
  ├─ Access Token: 15 min expiry, sent via httpOnly cookie or Authorization header
  │
  └─ Refresh Token: 7-30 day expiry, stored in httpOnly secure cookie
       │
       └─ On use: issue new access + new refresh token, invalidate old refresh token

Rules

  • [P0-MUST] Set short expiry on access tokens (15 minutes or less).
  • [P0-MUST] Store tokens in httpOnly, Secure, SameSite=Lax cookies — never in localStorage or sessionStorage.
  • [P0-MUST] Implement refresh token rotation — each refresh token is single-use.
  • [P0-MUST] Maintain a server-side blocklist for revoked refresh tokens.
  • [P1-SHOULD] Include only essential claims in JWT payload (sub, iat, exp, role). Keep it small.
  • [P1-SHOULD] Use asymmetric signing (RS256 or ES256) for distributed systems; symmetric (HS256) for single-service only.
  • [P1-SHOULD] Validate iss, aud, and exp claims on every request.
  • [P2-MAY] Use JWE (encrypted JWT) when token payload contains sensitive data.

Token Storage Comparison

StorageXSS SafeCSRF SafeRecommendation
httpOnly cookieYesNo (needs CSRF token)Recommended
localStorageNoYesNever use for auth tokens
sessionStorageNoYesNever use for auth tokens
In-memory (JS variable)YesYesOK for SPAs, lost on refresh

PROVIDER_PATTERNS

Comparison

ProviderTypeBest ForPricingKey Features
NextAuth / Auth.jsOSS libraryNext.js apps wanting full controlFree80+ providers, DB adapters, self-hosted
ClerkManaged serviceFast launch, pre-built UI, user managementFree tier, then per-MAUDrop-in components, user dashboard, org support
Supabase AuthManaged (part of Supabase)Apps already using Supabase for DB/storageFree tier, then per-MAURow-level security integration, magic links, SSO
LuciaOSS libraryFull control, minimal abstractionFreeSession-based, framework-agnostic, type-safe

When to Use Each

  • NextAuth / Auth.js: You want provider flexibility, self-hosting, and database session control. Best when you need custom flows.
  • Clerk: You want auth done fast with pre-built UI components. Best for MVPs and teams that don't want to build auth UI.
  • Supabase Auth: You're already using Supabase. Auth integrates with RLS policies for row-level security.
  • Lucia: You want a minimal, type-safe session library without framework lock-in.

NextAuth.js Setup Pattern

// app/api/auth/[...nextauth]/route.ts
import NextAuth from "next-auth";
import GitHub from "next-auth/providers/github";
import { PrismaAdapter } from "@auth/prisma-adapter";
import { prisma } from "@/lib/prisma";

export const { handlers, auth, signIn, signOut } = NextAuth({
  adapter: PrismaAdapter(prisma),
  providers: [
    GitHub({
      clientId: process.env.GITHUB_CLIENT_ID!,
      clientSecret: process.env.GITHUB_CLIENT_SECRET!,
    }),
  ],
  callbacks: {
    session({ session, user }) {
      session.user.id = user.id;
      return session;
    },
  },
});

SECURITY_CHECKLIST

Before Shipping Auth

  • Rate limiting: Login endpoint limited to 5-10 attempts per minute per IP.
  • CSRF protection: Anti-CSRF tokens on all state-changing requests (or use SameSite=Lax cookies).
  • Password hashing: Using bcrypt (cost 12+) or argon2id — never MD5, SHA-1, or plain SHA-256.
  • HTTPS only: All auth endpoints served over TLS. Cookies have Secure flag.
  • Input validation: Email format, password length (min 8, max 128), no SQL/NoSQL injection vectors.
  • Account enumeration: Login and registration return the same response whether account exists or not.
  • Session invalidation: Logout invalidates server-side session/refresh token, not just client cookie.
  • MFA support: TOTP (authenticator app) or WebAuthn as second factor for sensitive accounts.
  • Password reset: Time-limited tokens (1 hour), single-use, sent over secure channel.
  • Audit logging: Log auth events (login, logout, failed attempts, password changes) with timestamp and IP.

Password Hashing

// Using bcrypt
import bcrypt from "bcrypt";

const SALT_ROUNDS = 12;

async function hashPassword(password: string): Promise<string> {
  return bcrypt.hash(password, SALT_ROUNDS);
}

async function verifyPassword(password: string, hash: string): Promise<boolean> {
  return bcrypt.compare(password, hash);
}
// Using argon2 (preferred for new projects)
import argon2 from "argon2";

async function hashPassword(password: string): Promise<string> {
  return argon2.hash(password, { type: argon2.argon2id });
}

async function verifyPassword(hash: string, password: string): Promise<boolean> {
  return argon2.verify(hash, password);
}

COMMON_MISTAKES

MistakeRiskFix
Storing JWT in localStorageXSS can steal tokensUse httpOnly cookies
Long-lived JWTs (days/weeks)Stolen token is valid for extended period15 min access token + refresh rotation
Missing CSRF protectionAttackers can forge requests from other sitesSameSite=Lax cookies + CSRF token
Weak password requirementsBrute force and credential stuffingMin 8 chars, check against breached password lists
Exposing user existence on loginAccount enumerationGeneric "Invalid credentials" message
Not rotating refresh tokensStolen refresh token grants indefinite accessSingle-use refresh tokens with rotation
Hardcoding secrets in sourceCredential leak via git historyUse environment variables, never commit secrets
Missing rate limiting on loginBrute force attacks5-10 attempts/min per IP, exponential backoff
Rolling your own cryptoSubtle vulnerabilitiesUse established libraries (bcrypt, argon2, jose)
Not validating JWT claimsToken misuse across servicesAlways verify iss, aud, exp

相似的 Skill

xlsx
anthropics/skills180k

xlsx

Use this skill any time a spreadsheet file is the primary input or output. This means any task where the user wants to: open, read, edit, or fix an existing .xlsx, .xlsm, .xltx, .csv, or .tsv file (e.g., adding columns, computing formulas, formatting, charting, cleaning messy data); create a new spreadsheet from scratch or from other data sources; or convert between tabular file formats. Trigger especially when the user references a spreadsheet file by name or path — even casually (like "the xlsx in my downloads") — and wants something done to it or produced from it. Also trigger for cleaning or restructuring messy tabular data files (malformed rows, misplaced headers, junk data) into proper spreadsheets. The deliverable must be a spreadsheet file. Do NOT trigger when the primary deliverable is a Word document, HTML report, standalone Python script, database pipeline, or Google Sheets API integration, even if tabular data is involved.

数据库与数据

deprecation-and-migration
addyosmani/agent-skills103k

deprecation-and-migration

Manages deprecation and migration. Use when removing old systems, APIs, or features. Use when migrating users from one implementation to another. Use when migrating a database schema in production, such as renaming or dropping a column without downtime (expand/contract). Use when deciding whether to maintain or sunset existing code.

数据库与数据

make-plan
thedotmack/claude-mem99k

make-plan

暂无描述

数据库与数据

oh-my-issues
thedotmack/claude-mem99k

oh-my-issues

Cluster a GitHub issue backlog by root cause into a small set of plan-master issues, redirect children with a standardized comment, and bundle architectural-fix PRs that close clusters atomically. Use when an issue tracker has accumulated dozens of reports that share underlying defects, when asked to triage / consolidate / cluster / dedupe issues, when asked to build a plan series or roadmap from open issues, or when routing a new incoming bug into an existing plan.

数据库与数据

mem-search
thedotmack/claude-mem99k

mem-search

Use this when the user asks to search memory, "did we already solve this?", "how did we do X last time?", or wants work from previous sessions.

数据库与数据

handoff
thedotmack/claude-mem99k

handoff

Generate a HANDOFF.md that captures goal, current state, files touched, failed attempts, and next steps — so a fresh Claude session can continue exactly where this one left off. Use when sessions are getting long, Claude keeps retrying the same broken solution, or the user wants to step away and resume later.

数据库与数据