Skip to main content

auth-authorization-backend

Use when working on authentication, authorization, sessions, API keys, RBAC, ABAC, and tenant boundaries. Focus on least privilege, secure defaults, session safety, and auditable permission checks.

설치로 이동

소스 정보

저장소
Mr-Q526/TeamCC-Platform
최근 소스 활동
2026년 4월 15일 03:16
감지된 SKILL.md 언어
영어
스타
8
포크
1

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

파일 탐색기
4 개 파일

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
schemaVersion
2026-04-11T00:00:00.000Z
skillId
backend/auth-authorization-backend
name
auth-authorization-backend
displayName
Backend Auth Authorization
description
Use when working on authentication, authorization, sessions, API keys, RBAC, ABAC, and tenant boundaries. Focus on least privilege, secure defaults, session safety, and auditable permission checks.
aliases
["auth-authorization-backend","Backend Auth Authorization","auth authorization backend","authauthorizationbackend","后端鉴权","接口授权","租户边界","权限检查","认证","权限","RBAC","ABAC","服务端","server side","auth","authorization","登录页面"]
version
0.1.0
sourceHash
sha256:35bfe393f0b974dc59f9a35eac23fd2502d41aea90fba48098442b49df44a26b
domain
backend
departmentTags
["backend-platform"]
sceneTags
["architecture","security-audit"]
# Backend Auth Authorization Use this skill when the task involves authentication, authorization, sessions, API keys, RBAC, ABAC, and tenant boundaries. Goal: produce reliable engineering guidance and implementation steps focused on least privilege, secure defaults, session safety, and auditable permission checks. ## Working model 1. Identify the affected system, data, users, and failure modes. 2. Define invariants, inputs, outputs, ownership, and rollback needs. 3. Prefer small, auditable changes with explicit validation. 4. Call out security, performance, concurrency, and data-loss risks when relevant. 5. Finish with concrete verification steps and residual risks. ## Rules - Ground recommendations in the current codebase or runtime evidence. - Prefer explicit contracts, typed boundaries, and defensive validation. - Do not hide operational concerns behind generic best practices. - Include negative cases, edge cases, and failure behavior. - For review tasks, list findings first with file and line references when possible. - For test or performance tasks, define the workload, success criteria, and measurement method. ## Checklist - Are assumptions and ownership boundaries explicit? - Are risky changes reversible or safely deployable? - Are observability and diagnostics sufficient for production issues? - Are tests or validation steps targeted to the actual risk? - Are security and data-integrity concerns addressed?
GitHub에서 보기