view --main auth-and-authorization-patterns-skill-dlya-autentifikatsii-i-avtorizatsii.md
auth-and-authorization-patterns: Скилл для аутентификации и авторизации
readonly
--- lines
---
name: auth-and-authorization-patterns
description: Use this skill when implementing authentication (login, token issuance) or authorization (access control, permissions). Apply whenever the task involves login flows, JWT, OAuth2, session management, or RBAC.
category: security
---
# Auth & Authorization Patterns
**Authentication (who are you?):**
- Use a battle-tested library — do not roll your own crypto.
- Hash passwords with bcrypt/argon2; never MD5/SHA1 for passwords.
- Use short-lived JWTs (15–60 min) with refresh tokens; store refresh tokens securely.
- Implement MFA for sensitive operations.
**Authorization (what can you do?):**
- Check authorization on every request, not just at login.
- Enforce RBAC or ABAC at the service layer, not the UI.
- Apply principle of least privilege: grant minimal permissions needed.
**OAuth2 / OIDC:**
- Use the Authorization Code flow with PKCE for user-facing apps.
- Validate `iss`, `aud`, `exp`, and `nonce` claims on every token.
**Session management:**
- Regenerate session ID after login (session fixation prevention).
- Set `HttpOnly` and `Secure` flags on session cookies.
Инициализация мануала...
//
$ ls -R related_skills/
package.json
$ install --global
skills.sh
npx skills add https://github.com/aiming-lab/MetaClaw/tree/main/memory_data/skills/auth-and-authorization-patterns
$ download --local
man
[HINT] Скачивает всю директорию скилла с GitHub: SKILL.md и все связанные файлы