Communitygithub.com

YepAPI/skills

Authentication security — bcrypt/argon2 hashing, brute force protection, secure password resets.

Qu'est-ce que skills ?

skills is a Claude Code agent skill that authentication security — bcrypt/argon2 hashing, brute force protection, secure password resets.

Compatible avec~Claude Code~Codex CLI~Cursor
npx skills add https://github.com/YepAPI/skills/tree/HEAD/skills/auth-security

Demander à votre IA préférée

Ouvre une nouvelle conversation avec cette compétence d'agent déjà préchargée.

Documentation

Authentication Security

Rules

  • Hash passwords with bcrypt (cost factor 12+) or argon2id — never store plaintext or use SHA/MD5
  • Rate limit login endpoints: max 5 attempts per minute per IP, 10 per account per hour
  • Implement exponential lockout: 1s, 2s, 4s, 8s... after failed attempts, hard lock at 10 failures for 15 min
  • Password reset tokens: cryptographically random, single-use, expire in 1 hour max
  • Return generic errors: "Invalid email or password" — never reveal which field is wrong
  • Enforce minimum password length of 8 characters, check against breached password lists (HaveIBeenPwned API)
import bcrypt from "bcrypt";

// Hash on signup
const hash = await bcrypt.hash(password, 12);

// Verify on login
const valid = await bcrypt.compare(password, storedHash);
if (!valid) {
  await incrementFailedAttempts(userId);
  return res.status(401).json({ error: "Invalid email or password" });
}
await resetFailedAttempts(userId);
// Brute force lockout check
async function checkLockout(userId: string) {
  const attempts = await getFailedAttempts(userId);
  if (attempts.count >= 10) {
    const lockoutEnd = attempts.lastAttempt + 15 * 60 * 1000;
    if (Date.now() < lockoutEnd) throw new Error("Account temporarily locked");
  }
}

Avoid

  • Storing passwords in plaintext, base64, or reversible encryption
  • SHA-256 for passwords — it's fast, which means brute-forceable
  • Revealing whether an email exists during login or password reset
  • Password reset links that never expire or can be reused
  • Allowing unlimited login attempts from a single IP

Individual skills in this repo

This repo contains 20 individual skills — each has its own dedicated page.

YepAPI/skills

WCAG 2.1 AA — semantic HTML, keyboard navigation, screen readers.

YepAPI/skills

CRUD generators, data tables, user management, role-based access, and bulk operations.

YepAPI/skills

Tool-use patterns, multi-step reasoning, agent orchestration, and structured outputs.

YepAPI/skills

Chat UI components, streaming responses with AI SDK, context window management, and RAG patterns.

YepAPI/skills

Monitor what ChatGPT and Gemini say about your brand using YepAPI.

YepAPI/skills

Web analytics integration — event tracking, custom dashboards, privacy-first.

YepAPI/skills

Framer Motion — transitions, scroll animations, layout animations.

YepAPI/skills

OpenAPI 3.1 from Zod schemas, interactive docs with Swagger/Scalar, versioning, and example requests for every endpoint.

YepAPI/skills

Session auth, social providers, CSRF protection, and secure cookie patterns.

YepAPI/skills

Queue workers with BullMQ/Inngest/Trigger.dev, job retries, dead letter queues, concurrency.

YepAPI/skills

Link building research and backlink audit using YepAPI.

YepAPI/skills

MDX blog setup, RSS feed generation, sitemap.xml, structured data/JSON-LD, and related posts.

YepAPI/skills

Redis caching, CDN cache headers, stale-while-revalidate, cache invalidation, React Query.

YepAPI/skills

Recharts/Chart.js data visualization — bar, line, area, pie charts.

YepAPI/skills

Commander.js, interactive prompts with Clack, spinners, colors, config files, exit codes, and npm publishing.

YepAPI/skills

cmdk integration, Cmd+K trigger, fuzzy search, grouped actions, keyboard navigation, and dynamic action registration.

YepAPI/skills

Threaded comments, @mentions, reactions, moderation queue, optimistic UI, and cursor pagination.

YepAPI/skills

Competitive analysis between domains using YepAPI.

YepAPI/skills

Blog engine setup, CMS integration, SEO-optimized content workflows, and editorial calendars.

YepAPI/skills

Experiment setup, variant splitting, statistical significance, and feature flag integration.

Skills associés