用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/jeffreytse/grimoire-core --skill design-auth-flow命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
Use when comparing very differently-titled roles for compensation banding, leveling, or organizational design — score each role's inherent Know-How (knowledge, skills, experience required), Problem Solving (complexity and freedom of thinking, scored as a percentage of Know-How), and Accountability (freedom to act and magnitude of impact), because job titles and informal seniority perceptions vary inconsistently across departments and don't provide a comparable basis on their own.
Use when many people request your scarce time, mentorship, or expertise and you cannot evaluate their genuine commitment level from a conversation alone — require a specific, costly, objectively verifiable unit of self-directed output (a set number of completed attempts) before engaging, because genuine commitment is what a conversation cannot reliably reveal but a completed, verifiable body of work can.
Use when deciding how to allocate a manager's or leader's limited time across competing activities — before defaulting to whatever is most urgent, estimate each candidate activity's leverage (how many people's output it affects, for how long, and whether it requires your specific position), because a manager's actual output is the output of the organization under their influence, not their own individual task completion.
基于 SOC 职业分类
正在显示 SKILL.md
| name | design-auth-flow |
| description | Use when designing or reviewing authentication and authorization flows for web, mobile, or API systems |
| source | OAuth 2.0 RFC 6749; PKCE RFC 7636; OWASP Authentication Cheat Sheet (cheatsheetseries.owasp.org) |
| tags | ["authentication","oauth2","pkce","security","authorization","owasp"] |
| verified | true |
Design secure authentication and authorization flows using OAuth 2.0 / OIDC standards with PKCE and OWASP best practices.
Adopted by: Google, Microsoft, GitHub, Okta, Auth0 — all implement OAuth 2.0 + PKCE as the baseline Impact: OWASP reports that broken authentication is consistently in the top 3 web vulnerabilities; PKCE (RFC 7636) eliminates the authorization code interception attack that affected millions of mobile apps.
Why best: Rolling custom auth is the single highest-risk decision in software security. OAuth 2.0 + OIDC provides a peer-reviewed, widely-audited framework. PKCE extends it safely to public clients (SPAs, mobile apps) where client secrets cannot be stored securely.
code_verifier (43-128 chars); hash it to code_challenge (S256); send challenge in auth request; send verifier in token exchange.iss, aud, exp, and nbf claims. Never trust unsigned tokens or skip expiry checks.PKCE flow (SPA):
code_verifier = random(64), code_challenge = base64url(sha256(verifier))./authorize?response_type=code&code_challenge=...&code_challenge_method=S256./token — server verifies sha256(verifier) == challenge.state parameter — enables CSRF attacks on the OAuth callback.