跳到主要内容
知仓学习社ZHICANG

auth-flow

Generates authentication infrastructure with Sign in with Apple, biometrics, and Keychain storage. Use when user wants to add authentication, login,…

不碰外部(只输出文字)无严重或高危命中rshankras/claude-code-apple-skills

它会碰到什么

扫了多少2 个文本文件,13 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Auth Flow Generator

Generate a complete authentication flow with Sign in with Apple, biometric authentication (Face ID/Touch ID), and secure Keychain storage.

When This Skill Activates

Use this skill when the user:

  • Asks to "add authentication" or "add login"
  • Mentions "Sign in with Apple" or "SIWA"
  • Wants "Face ID login" or "biometric auth"
  • Asks about "Keychain" or "secure storage"
  • Mentions "user session" or "auth token"

Pre-Generation Checks

1. Project Context Detection

  • [ ] Check for existing auth implementations
  • [ ] Check for AuthenticationServices framework usage
  • [ ] Verify entitlements file exists
  • [ ] Identify source file locations

2. Conflict Detection

Search for existing auth:

Glob: **/*Auth*.swift, **/*Keychain*.swift
Grep: "ASAuthorizationController" or "LAContext"

If found, ask user:

  • Replace existing implementation?
  • Extend with additional methods?

3. Required Capabilities

Sign in with Apple requires:

  • Add "Sign in with Apple" capability in Xcode
  • Configure in App Store Connect
  • Add entitlement: com.apple.developer.applesignin

Configuration Questions

Ask user via AskUserQuestion:

  1. Authentication methods? (multi-select)
  • Sign in with Apple
  • Biometrics (Face ID/Touch ID)
  • Both
  1. Session storage?
  • Keychain (secure, persists reinstall)
  • UserDefaults (simple, cleared on reinstall)
  1. Session management?
  • Auto-refresh tokens
  • Manual refresh
  • No token refresh needed

Generation Process

Step 1: Create Core Files

Generate these files:

  1. AuthenticationManager.swift - Core auth orchestration
  2. KeychainManager.swift - Secure storage
  3. SignInWithAppleManager.swift - SIWA handling
  4. BiometricAuthManager.swift - Face ID/Touch ID

Step 2: Create SwiftUI Components

Based on configuration:

  • SignInWithAppleButton.swift - SwiftUI button wrapper
  • AuthenticationView.swift - Complete auth UI

Step 3: Determine File Location

Check project structure:

  • If Sources/ exists → Sources/Auth/
  • If App/ exists → App/Auth/
  • Otherwise → Auth/

Entitlements Required

Sign in with Apple

<!-- YourApp.entitlements -->
<key>com.apple.developer.applesignin</key>
<array>
    <string>Default</string>
</array>

Keychain Sharing (optional)

<key>keychain-access-groups</key>
<array>
    <string>$(AppIdentifierPrefix)com.yourcompany.shared</string>
</array>

Info.plist Required

Face ID Usage Description

<key>NSFaceIDUsageDescription</key>
<string>Use Face ID to securely sign in to your account</string>

Output Format

After generation, provide:

Files Created

Sources/Auth/
├── AuthenticationManager.swift      # Core orchestration
├── KeychainManager.swift            # Secure storage
├── SignInWithAppleManager.swift     # SIWA delegate
├── BiometricAuthManager.swift       # Face ID/Touch ID
├── AuthenticationState.swift        # Auth state model
└── Views/
    ├── SignInWithAppleButton.swift  # SwiftUI button
    └── AuthenticationView.swift     # Complete UI

Integration Steps

App Entry Point:

@main
struct MyApp: App {
    @State private var authManager = AuthenticationManager()  // AuthenticationManager is @Observable

    var body: some Scene {
        WindowGroup {
            if authManager.isAuthenticated {
                ContentView()
            } else {
                AuthenticationView()
            }
        }
        .environment(authManager)
    }
}

Sign in with Apple Button:

SignInWithAppleButtonView { result in
    switch result {
    case .success(let user):
        print("Signed in: \(user.id)")
    case .failure(let error):
        print("Failed: \(error)")
    }
}

Biometric Auth:

Button("Unlock with Face ID") {
    Task {
        if await BiometricAuthManager.shared.authenticate() {
            // Authenticated
        }
    }
}

Required Setup

  1. Xcode Capabilities:
  • Add "Sign in with Apple" capability
  • Enable Keychain Sharing (if needed)
  1. App Store Connect:
  • Configure Sign in with Apple for your App ID
  1. Info.plist:
  • Add NSFaceIDUsageDescription

Testing Instructions

Sign in with Apple:

  • Use Simulator for basic testing
  • Test on device for full flow
  • Use sandbox Apple ID for testing

Biometrics:

  • Simulator: Features > Face ID > Enrolled
  • Test enrolled/not enrolled states
  • Test failed authentication

References

  • auth-patterns.md - Security best practices
  • templates/ - All template files
  • Apple Docs: Authentication Services, LocalAuthentication

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。