Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问clear审计通过

authentication-setup身份验证设置

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

249,312

周安装

10,633

GitHub Stars

88

下载量

87,344
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:authentication-setup(身份验证设置)
来源仓库:https://github.com/supercent-io/skills-template
仓库路径:skills/authentication-setup
安装命令:
npx skills add https://github.com/supercent-io/skills-template --skill authentication-setup
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/supercent-io/skills-template --skill authentication-setup

简介

具有 JWT、OAuth 和基于角色的访问控制的完整身份验证和授权系统。

  • 涵盖五种核心身份验证方法:JWT 令牌、会话管理、OAuth 2.0、密码哈希 (bcrypt/argon2) 和多因素身份验证支持
  • 包括通过数据库架构设计逐步实现用户注册、登录、令牌刷新和注销端点
  • 提供用于保护API路由的身份验证中间件和用于权限管理的基于角色的授权
  • 支持社交登录集成(Google、GitHub、Microsoft)和具有数据库撤销功能的刷新令牌管理
  • 包括安全最佳实践:环境变量管理、短期访问令牌(15 分钟)、长期刷新令牌(7 天)和审核日志记录建议

SKILL.md

Authentication Setup

When to use this skill

Lists specific situations where this skill should be triggered:

  • User Login System: When adding user authentication to a new application
  • API Security: When adding an authentication layer to a REST or GraphQL API
  • Permission Management: When role-based access control is needed
  • Authentication Migration: When migrating an existing auth system to JWT or OAuth
  • SSO Integration: When integrating social login with Google, GitHub, Microsoft, etc.

Input Format

The required and optional input information to collect from the user:

Required Information

  • Authentication Method: Choose from JWT, Session, or OAuth 2.0
  • Backend Framework: Express, Django, FastAPI, Spring Boot, etc.
  • Database: PostgreSQL, MySQL, MongoDB, etc.
  • Security Requirements: Password policy, token expiry times, etc.

Optional Information

  • MFA Support: Whether to enable 2FA/MFA (default: false)
  • Social Login: OAuth providers (Google, GitHub, etc.)
  • Session Storage: Redis, in-memory, etc. (if using sessions)
  • Refresh Token: Whether to use (default: true)

Input Example

Build a user authentication system:
- Auth method: JWT
- Framework: Express.js + TypeScript
- Database: PostgreSQL
- MFA: Google Authenticator support
- Social login: Google, GitHub
- Refresh Token: enabled

Instructions

Specifies the step-by-step task sequence to follow precisely.

Step 1: Design the Data Model

Design the database schema for users and authentication.

Tasks:

  • Design the User table (id, email, password_hash, role, created_at, updated_at)
  • RefreshToken table (optional)
  • OAuthProvider table (if using social login)
  • Never store passwords in plaintext (bcrypt/argon2 hashing is mandatory)

Example (PostgreSQL):

CREATE TABLE users (
    id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
    email VARCHAR(255) UNIQUE NOT NULL,
    password_hash VARCHAR(255),  -- NULL if OAuth only
    role VARCHAR(50) DEFAULT 'user',
    is_verified BOOLEAN DEFAULT false,
    mfa_secret VARCHAR(255),
    created_at TIMESTAMP DEFAULT NOW(),
    updated_at TIMESTAMP DEFAULT NOW()
);

CREATE TABLE refresh_tokens (
    id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
    user_id UUID REFERENCES users(id) ON DELETE CASCADE,
    token VARCHAR(500) UNIQUE NOT NULL,
    expires_at TIMESTAMP NOT NULL,
    created_at TIMESTAMP DEFAULT NOW()
);

CREATE INDEX idx_users_email ON users(email);
CREATE INDEX idx_refresh_tokens_user_id ON refresh_tokens(user_id);

Step 2: Implement Password Security

Implement password hashing and verification logic.

Tasks:

  • Use bcrypt (Node.js) or argon2 (Python)
  • Set salt rounds to a minimum of 10
  • Password strength validation (minimum 8 chars, upper/lowercase, numbers, special characters)

Decision Criteria:

  • Node.js projects → use the bcrypt library
  • Python projects → use argon2-cffi or passlib
  • Performance-critical cases → choose bcrypt
  • Cases requiring maximum security → choose argon2

Example (Node.js + TypeScript):

import bcrypt from 'bcrypt';

const SALT_ROUNDS = 12;

export async function hashPassword(password: string): Promise<string> {
    // Validate password strength
    if (password.length < 8) {
        throw new Error('Password must be at least 8 characters');
    }

    const hasUpperCase = /[A-Z]/.test(password);
    const hasLowerCase = /[a-z]/.test(password);
    const hasNumber = /\d/.test(password);
    const hasSpecial = /[!@#$%^&*(),.?":{}|<>]/.test(password);

    if (!hasUpperCase || !hasLowerCase || !hasNumber || !hasSpecial) {
        throw new Error('Password must contain uppercase, lowercase, number, and special character');
    }

    return await bcrypt.hash(password, SALT_ROUNDS);
}

export async function verifyPassword(password: string, hash: string): Promise<boolean> {
    return await bcrypt.compare(password, hash);
}

Step 3: Generate and Verify JWT Tokens

Implement a token system for JWT-based authentication.

Tasks:

  • Access Token (short expiry: 15 minutes)
  • Refresh Token (long expiry: 7–30 days)
  • Use a strong SECRET key for JWT signing (manage via environment variables)
  • Include only the minimum necessary information in the token payload (user_id, role)

Example (Node.js):

import jwt from 'jsonwebtoken';

const ACCESS_TOKEN_SECRET = process.env.ACCESS_TOKEN_SECRET!;
const REFRESH_TOKEN_SECRET = process.env.REFRESH_TOKEN_SECRET!;
const ACCESS_TOKEN_EXPIRY = '15m';
const REFRESH_TOKEN_EXPIRY = '7d';

interface TokenPayload {
    userId: string;
    email: string;
    role: string;
}

export function generateAccessToken(payload: TokenPayload): string {
    return jwt.sign(payload, ACCESS_TOKEN_SECRET, {
        expiresIn: ACCESS_TOKEN_EXPIRY,
        issuer: 'your-app-name',
        audience: 'your-app-users'
    });
}

export function generateRefreshToken(payload: TokenPayload): string {
    return jwt.sign(payload, REFRESH_TOKEN_SECRET, {
        expiresIn: REFRESH_TOKEN_EXPIRY,
        issuer: 'your-app-name',
        audience: 'your-app-users'
    });
}

export function verifyAccessToken(token: string): TokenPayload {
    return jwt.verify(token, ACCESS_TOKEN_SECRET, {
        issuer: 'your-app-name',
        audience: 'your-app-users'
    }) as TokenPayload;
}

export function verifyRefreshToken(token: string): TokenPayload {
    return jwt.verify(token, REFRESH_TOKEN_SECRET, {
        issuer: 'your-app-name',
        audience: 'your-app-users'
    }) as TokenPayload;
}

Step 4: Implement Authentication Middleware

Write authentication middleware to protect API requests.

Checklist:

  • Extract Bearer token from the Authorization header
  • Verify token and check expiry
  • Attach user info to req.user for valid tokens
  • Error handling (401 Unauthorized)

Example (Express.js):

import { Request, Response, NextFunction } from 'express';
import { verifyAccessToken } from './jwt';

export interface AuthRequest extends Request {
    user?: {
        userId: string;
        email: string;
        role: string;
    };
}

export function authenticateToken(req: AuthRequest, res: Response, next: NextFunction) {
    const authHeader = req.headers['authorization'];
    const token = authHeader && authHeader.split(' ')[1]; // Bearer TOKEN

    if (!token) {
        return res.status(401).json({ error: 'Access token required' });
    }

    try {
        const payload = verifyAccessToken(token);
        req.user = payload;
        next();
    } catch (error) {
        if (error.name === 'TokenExpiredError') {
            return res.status(401).json({ error: 'Token expired' });
        }
        return res.status(403).json({ error: 'Invalid token' });
    }
}

// Role-based authorization middleware
export function requireRole(...roles: string[]) {
    return (req: AuthRequest, res: Response, next: NextFunction) => {
        if (!req.user) {
            return res.status(401).json({ error: 'Authentication required' });
        }

        if (!roles.includes(req.user.role)) {
            return res.status(403).json({ error: 'Insufficient permissions' });
        }

        next();
    };
}

Step 5: Implement Authentication API Endpoints

Write APIs for registration, login, token refresh, etc.

Tasks:

  • POST /auth/register - registration
  • POST /auth/login - login
  • POST /auth/refresh - token refresh
  • POST /auth/logout - logout
  • GET /auth/me - current user info

Example:

import express from 'express';
import { hashPassword, verifyPassword } from './password';
import { generateAccessToken, generateRefreshToken, verifyRefreshToken } from './jwt';
import { authenticateToken } from './middleware';

const router = express.Router();

// Registration
router.post('/register', async (req, res) => {
    try {
        const { email, password } = req.body;

        // Check for duplicate email
        const existingUser = await db.user.findUnique({ where: { email } });
        if (existingUser) {
            return res.status(409).json({ error: 'Email already exists' });
        }

        // Hash the password
        const passwordHash = await hashPassword(password);

        // Create the user
        const user = await db.user.create({
            data: { email, password_hash: passwordHash, role: 'user' }
        });

        // Generate tokens
        const accessToken = generateAccessToken({
            userId: user.id,
            email: user.email,
            role: user.role
        });
        const refreshToken = generateRefreshToken({
            userId: user.id,
            email: user.email,
            role: user.role
        });

        // Store Refresh token in DB
        await db.refreshToken.create({
            data: {
                user_id: user.id,
                token: refreshToken,
                expires_at: new Date(Date.now() + 7 * 24 * 60 * 60 * 1000) // 7 days
            }
        });

        res.status(201).json({
            user: { id: user.id, email: user.email, role: user.role },
            accessToken,
            refreshToken
        });
    } catch (error) {
        res.status(500).json({ error: error.message });
    }
});

// Login
router.post('/login', async (req, res) => {
    try {
        const { email, password } = req.body;

        // Find the user
        const user = await db.user.findUnique({ where: { email } });
        if (!user || !user.password_hash) {
            return res.status(401).json({ error: 'Invalid credentials' });
        }

        // Verify the password
        const isValid = await verifyPassword(password, user.password_hash);
        if (!isValid) {
            return res.status(401).json({ error: 'Invalid credentials' });
        }

        // Generate tokens
        const accessToken = generateAccessToken({
            userId: user.id,
            email: user.email,
            role: user.role
        });
        const refreshToken = generateRefreshToken({
            userId: user.id,
            email: user.email,
            role: user.role
        });

        // Store Refresh token
        await db.refreshToken.create({
            data: {
                user_id: user.id,
                token: refreshToken,
                expires_at: new Date(Date.now() + 7 * 24 * 60 * 60 * 1000)
            }
        });

        res.json({
            user: { id: user.id, email: user.email, role: user.role },
            accessToken,
            refreshToken
        });
    } catch (error) {
        res.status(500).json({ error: error.message });
    }
});

// Token refresh
router.post('/refresh', async (req, res) => {
    try {
        const { refreshToken } = req.body;

        if (!refreshToken) {
            return res.status(401).json({ error: 'Refresh token required' });
        }

        // Verify Refresh token
        const payload = verifyRefreshToken(refreshToken);

        // Check token in DB
        const storedToken = await db.refreshToken.findUnique({
            where: { token: refreshToken }
        });

        if (!storedToken || storedToken.expires_at < new Date()) {
            return res.status(403).json({ error: 'Invalid or expired refresh token' });
        }

        // Generate new Access token
        const accessToken = generateAccessToken({
            userId: payload.userId,
            email: payload.email,
            role: payload.role
        });

        res.json({ accessToken });
    } catch (error) {
        res.status(403).json({ error: 'Invalid refresh token' });
    }
});

// Current user info
router.get('/me', authenticateToken, async (req: AuthRequest, res) => {
    try {
        const user = await db.user.findUnique({
            where: { id: req.user!.userId },
            select: { id: true, email: true, role: true, created_at: true }
        });

        res.json({ user });
    } catch (error) {
        res.status(500).json({ error: error.message });
    }
});

export default router;

Output format

Defines the exact format that deliverables should follow.

Basic Structure

Project directory/
├── src/
│   ├── auth/
│   │   ├── password.ts          # password hashing/verification
│   │   ├── jwt.ts                # JWT token generation/verification
│   │   ├── middleware.ts         # authentication middleware
│   │   └── routes.ts             # authentication API endpoints
│   ├── models/
│   │   └── User.ts               # user model
│   └── database/
│       └── schema.sql            # database schema
├── .env.example                  # environment variable template
└── README.md                     # authentication system documentation

Environment Variable File (.env.example)

# JWT Secrets (MUST change in production)
ACCESS_TOKEN_SECRET=your-access-token-secret-min-32-characters
REFRESH_TOKEN_SECRET=your-refresh-token-secret-min-32-characters

# Database
DATABASE_URL=postgresql://user:password@localhost:5432/myapp

# OAuth (Optional)
GOOGLE_CLIENT_ID=your-google-client-id
GOOGLE_CLIENT_SECRET=your-google-client-secret
GITHUB_CLIENT_ID=your-github-client-id
GITHUB_CLIENT_SECRET=your-github-client-secret

Constraints

Specifies mandatory rules and prohibited actions.

Mandatory Rules (MUST)

  1. Password Security: Never store passwords in plaintext

- Use a proven hashing algorithm such as bcrypt or argon2 - Salt rounds minimum of 10

  1. Environment Variable Management: Manage all secret keys via environment variables

- Add.env files to.gitignore - Provide a list of required variables via.env.example

  1. Token Expiry: Access Tokens should be short-lived (15 min), Refresh Tokens appropriately longer (7 days)

- Balance security and user experience - Store Refresh Tokens in the DB to enable revocation

Prohibited Actions (MUST NOT)

  1. Plaintext Passwords: Never store passwords in plaintext or print them to logs

- Serious security risk - Legal liability issues

  1. Hardcoding JWT SECRET: Do not write SECRET keys directly in code

- Risk of being exposed on GitHub - Production security vulnerability

  1. Sensitive Data in Tokens: Do not include passwords, card numbers, or other sensitive data in JWT payloads

- JWT can be decoded (it is not encrypted) - Include only the minimum information (user_id, role)

Security Rules

  • Rate Limiting: Apply rate limiting to the login API (prevents brute-force attacks)
  • HTTPS Required: Use HTTPS only in production environments
  • CORS Configuration: Allow only approved domains to access the API
  • Input Validation: Validate all user input (prevents SQL Injection and XSS)

Examples

Demonstrates how to apply the skill through real-world use cases.

Example 1: Express.js + PostgreSQL JWT Authentication

Situation: Adding JWT-based user authentication to a Node.js Express app

User Request:

Add JWT authentication to an Express.js app using PostgreSQL,
with access token expiry of 15 minutes and refresh token expiry of 7 days.

Skill Application Process:

  1. Install packages: npm install jsonwebtoken bcrypt pg npm install --save-dev @types/jsonwebtoken @types/bcrypt
  2. Create the database schema (use the SQL above)
  3. Set environment variables: ACCESS_TOKEN_SECRET=$(openssl rand -base64 32) REFRESH_TOKEN_SECRET=$(openssl rand -base64 32)
  4. Implement auth modules (use the code examples above)
  5. Connect API routes: import authRoutes from './auth/routes'; app.use('/api/auth', authRoutes);

Final Result: JWT-based authentication system complete, registration/login/token-refresh APIs working

Example 2: Role-Based Access Control (RBAC)

Situation: A permission system that distinguishes administrators from regular users

User Request:

Create an API accessible only to administrators.
Regular users should receive a 403 error.

Final Result:

// Admin-only API
router.delete('/users/:id',
    authenticateToken,           // verify authentication
    requireRole('admin'),         // verify role
    async (req, res) => {
        // user deletion logic
        await db.user.delete({ where: { id: req.params.id } });
        res.json({ message: 'User deleted' });
    }
);

// Usage example
// Regular user (role: 'user') request → 403 Forbidden
// Admin (role: 'admin') request → 200 OK

Best practices

Recommendations for using this skill effectively.

Quality Improvement

  1. Password Rotation Policy: Recommend periodic password changes

- Change notification every 90 days - Prevent reuse of the last 5 passwords - Balance user experience and security

  1. Multi-Factor Authentication (MFA): Apply 2FA to important accounts

- Use TOTP apps such as Google Authenticator or Authy - SMS is less secure (risk of SIM swapping) - Provide backup codes

  1. Audit Logging: Log all authentication events

- Record login success/failure, IP address, and User Agent - Anomaly detection and post-incident analysis - GDPR compliance (exclude sensitive data)

Efficiency Improvements

  • Token Blacklist: Revoke Refresh Tokens on logout
  • Redis Caching: Cache frequently used user data
  • Database Indexing: Add indexes on email and refresh_token

Common Issues

Common problems and their solutions.

Issue 1: "JsonWebTokenError: invalid signature"

Symptom:

  • Error occurs during token verification
  • Login succeeds but authenticated API calls fail

Cause: The SECRET keys for Access Token and Refresh Token are different, but the same key is being used to verify both.

Solution:

  1. Check environment variables: ACCESS_TOKEN_SECRET, REFRESH_TOKEN_SECRET
  2. Use the correct SECRET for each token type
  3. Verify that environment variables load correctly (initialize dotenv)

Issue 2: Frontend Cannot Log In Due to CORS Error

Symptom: "CORS policy" error in the browser console

Cause: Missing CORS configuration on the Express server

Solution:

import cors from 'cors';

app.use(cors({
    origin: process.env.FRONTEND_URL || 'http://localhost:3000',
    credentials: true
}));

Issue 3: Refresh Token Keeps Expiring

Symptom: Users are frequently logged out

Cause: Refresh Token is not properly managed in the DB

Solution:

  1. Confirm Refresh Token is saved to DB upon creation
  2. Set an appropriate expiry time (minimum 7 days)
  3. Add a cron job to regularly clean up expired tokens

References

Official Documentation

Libraries

Security Guides

Metadata

Version

  • Current Version: 1.0.0
  • Last Updated: 2025-01-01
  • Compatible Platforms: Claude, ChatGPT, Gemini

Related Skills

Tags

#authentication #authorization #JWT #OAuth #security #backend

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Claude Code

26.3%
按下载量换算22,971

OpenCode

22.8%
按下载量换算19,914

Codex

16.99%
按下载量换算14,840

Gemini CLI

12.03%
按下载量换算10,507

Antigravity

7.89%
按下载量换算6,891

Cursor

3.14%
按下载量换算2,743

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。

来源信息

继续浏览同类 Skills