技能 编程开发 认证与授权实现模式

认证与授权实现模式

v20260309
auth-implementation-patterns
指导团队使用 JWT、OAuth2、会话和 RBAC 等模式构建安全的认证与授权系统,涵盖威胁建模、密钥管理与审计,适用于 API、SSO 与多租户场景。
获取技能
127 次下载
概览

Authentication & Authorization Implementation Patterns

Build secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices.

Use this skill when

  • Implementing user authentication systems
  • Securing REST or GraphQL APIs
  • Adding OAuth2/social login or SSO
  • Designing session management or RBAC
  • Debugging authentication or authorization issues

Do not use this skill when

  • You only need UI copy or login page styling
  • The task is infrastructure-only without identity concerns
  • You cannot change auth policies or credential storage

Instructions

  • Define users, tenants, flows, and threat model constraints.
  • Choose auth strategy (session, JWT, OIDC) and token lifecycle.
  • Design authorization model and policy enforcement points.
  • Plan secrets storage, rotation, logging, and audit requirements.
  • If detailed examples are required, open resources/implementation-playbook.md.

Safety

  • Never log secrets, tokens, or credentials.
  • Enforce least privilege and secure storage for keys.

Resources

  • resources/implementation-playbook.md for detailed patterns and examples.
信息
Category 编程开发
Name auth-implementation-patterns
版本 v20260309
大小 5.95KB
更新时间 2026-03-10
语言