跳到主要内容
知仓学习社ZHICANG

oauth-flow-implementer

Implement OAuth 2.0 and OpenID Connect flows for SDKs

不碰外部(只输出文字)无严重或高危命中a5c-ai/babysitter

它会碰到什么

扫了多少2 个文本文件,3 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

OAuth Flow Implementer Skill

Overview

This skill implements OAuth 2.0 and OpenID Connect authentication flows for SDKs, supporting various grant types and security best practices.

Capabilities

  • Implement authorization code flow with PKCE
  • Configure client credentials flow for server-to-server
  • Handle automatic token refresh transparently
  • Support device authorization flow for CLI/IoT
  • Implement implicit flow (legacy support)
  • Configure token storage securely
  • Handle token revocation and logout
  • Support multiple OAuth providers

Target Processes

  • Authentication and Authorization Patterns
  • Platform API Gateway Design
  • SDK Architecture Design

Integration Points

  • OAuth 2.0 providers (Auth0, Okta, etc.)
  • OpenID Connect providers
  • Custom authorization servers
  • Token storage mechanisms
  • Secure credential storage

Input Requirements

  • OAuth provider configuration
  • Required grant types
  • Scope definitions
  • Token storage requirements
  • Refresh token strategy

Output Artifacts

  • OAuth client implementation
  • Token management module
  • PKCE implementation
  • Secure storage integration
  • Authentication middleware
  • Example authentication flows

Usage Example

skill:
  name: oauth-flow-implementer
  context:
    provider: custom
    grantTypes:
      - authorization_code_pkce
      - client_credentials
      - device_code
    tokenStorage: secure-keychain
    autoRefresh: true
    scopes:
      - read
      - write
      - admin

Best Practices

  1. Always use PKCE for public clients
  2. Store tokens securely (keychain, encrypted storage)
  3. Implement automatic token refresh
  4. Handle token expiration gracefully
  5. Support token revocation
  6. Log authentication events (not tokens)

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 1,796
本站分层T1
该仓技能数2115
原文件路径library/specializations/sdk-platform-development/skills/oauth-flow-implementer/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 2115 个技能