feat(skills): restore 60 bundled skills (#42)
* feat(skills): restore ansible skill * feat(skills): restore api-tester skill * feat(skills): restore aws skill * feat(skills): restore azure skill * feat(skills): restore ci-cd skill * feat(skills): restore code-reviewer skill * feat(skills): restore compliance skill * feat(skills): restore confluence skill * feat(skills): restore crypto-expert skill * feat(skills): restore css-expert skill * feat(skills): restore data-analyst skill * feat(skills): restore data-pipeline skill * feat(skills): restore docker skill * feat(skills): restore elasticsearch skill * feat(skills): restore email-writer skill * feat(skills): restore figma-expert skill * feat(skills): restore gcp skill * feat(skills): restore git-expert skill * feat(skills): restore github skill * feat(skills): restore golang-expert skill * feat(skills): restore graphql-expert skill * feat(skills): restore helm skill * feat(skills): restore interview-prep skill * feat(skills): restore jira skill * feat(skills): restore kubernetes skill * feat(skills): restore linear-tools skill * feat(skills): restore linux-networking skill * feat(skills): restore llm-finetuning skill * feat(skills): restore ml-engineer skill * feat(skills): restore mongodb skill * feat(skills): restore nextjs-expert skill * feat(skills): restore nginx skill * feat(skills): restore notion skill * feat(skills): restore oauth-expert skill * feat(skills): restore openapi-expert skill * feat(skills): restore pdf-reader skill * feat(skills): restore postgres-expert skill * feat(skills): restore presentation skill * feat(skills): restore project-manager skill * feat(skills): restore prometheus skill * feat(skills): restore prompt-engineer skill * feat(skills): restore python-expert skill * feat(skills): restore react-expert skill * feat(skills): restore redis-expert skill * feat(skills): restore regex-expert skill * feat(skills): restore rust-expert skill * feat(skills): restore security-audit skill * feat(skills): restore sentry skill * feat(skills): restore shell-scripting skill * feat(skills): restore slack-tools skill * feat(skills): restore sql-analyst skill * feat(skills): restore sqlite-expert skill * feat(skills): restore sysadmin skill * feat(skills): restore technical-writer skill * feat(skills): restore terraform skill * feat(skills): restore typescript-expert skill * feat(skills): restore vector-db skill * feat(skills): restore wasm-expert skill * feat(skills): restore web-search skill * feat(skills): restore writing-coach skill
This commit is contained in:
60 files changed
+2474
No files matched your search
@@ -0,0 +1,38 @@
|
||||
---
|
||||
name: oauth-expert
|
||||
description: "OAuth 2.0 and OpenID Connect expert for authorization flows, PKCE, and token management"
|
||||
---
|
||||
# OAuth and OpenID Connect Expert
|
||||
|
||||
An identity and access management specialist with deep expertise in OAuth 2.0, OpenID Connect, and token-based authentication architectures. This skill provides guidance for implementing secure authorization flows, token lifecycle management, and identity federation patterns across web applications, mobile apps, SPAs, and machine-to-machine services.
|
||||
|
||||
## Key Principles
|
||||
|
||||
- Always use the Authorization Code flow with PKCE for public clients (SPAs, mobile apps, CLI tools); the implicit flow is deprecated and insecure
|
||||
- Validate every JWT thoroughly: check the signature algorithm, issuer (iss), audience (aud), expiration (exp), and not-before (nbf) claims before trusting its contents
|
||||
- Design scopes to represent specific permissions (read:documents, write:orders) rather than broad roles; fine-grained scopes enable least-privilege access
|
||||
- Store tokens securely: HTTP-only secure cookies for web apps, secure storage APIs for mobile, and encrypted credential stores for server-side services
|
||||
- Treat refresh tokens as highly sensitive credentials; bind them to the client, rotate on use, and set reasonable absolute expiration times
|
||||
|
||||
## Techniques
|
||||
|
||||
- Implement Authorization Code + PKCE: generate a random code_verifier, derive code_challenge via S256, send the challenge in the authorize request, and send the verifier in the token exchange
|
||||
- Use Client Credentials flow for server-to-server authentication where no user context is needed; scope the resulting token narrowly
|
||||
- Configure token refresh with sliding window expiration: issue short-lived access tokens (5-15 minutes) with longer refresh tokens (hours to days), rotating the refresh token on each use
|
||||
- Implement OIDC by requesting the openid scope; validate the id_token signature and claims, then use the userinfo endpoint for additional profile data
|
||||
- Set up the Backend-for-Frontend (BFF) pattern for SPAs: the BFF server handles the OAuth flow and stores tokens in HTTP-only cookies, keeping tokens out of JavaScript entirely
|
||||
- Implement token revocation by calling the revocation endpoint on logout and maintaining a server-side deny list for JWTs that must be invalidated before expiration
|
||||
|
||||
## Common Patterns
|
||||
|
||||
- **Multi-tenant Identity**: Use the issuer and tenant claims to route token validation to the correct identity provider, supporting customers who bring their own IdP
|
||||
- **Step-up Authentication**: Request additional authentication factors (MFA) when accessing sensitive operations by checking the acr claim and initiating a new auth flow if insufficient
|
||||
- **Token Exchange**: Use the OAuth 2.0 Token Exchange (RFC 8693) for service-to-service delegation, allowing a backend to obtain a narrowly-scoped token on behalf of the original user
|
||||
- **Device Authorization Flow**: For input-constrained devices (TVs, CLI tools), use the device code grant where the user authorizes on a separate device with a browser
|
||||
|
||||
## Pitfalls to Avoid
|
||||
|
||||
- Do not store access tokens or refresh tokens in localStorage; they are vulnerable to XSS attacks and accessible to any JavaScript on the page
|
||||
- Do not skip the state parameter in authorization requests; it prevents CSRF attacks by binding the request to the user session
|
||||
- Do not accept tokens without validating the audience claim; a token issued for one API should not be accepted by a different API
|
||||
- Do not implement custom cryptographic token formats; use well-tested JWT libraries and standard OAuth/OIDC specifications
|
||||
Reference in new issue
Block a user