Communitygithub.com

YepAPI/skills

Google/GitHub/Discord OAuth flows, PKCE, token refresh, and session management.

skills とは?

skills is a Claude Code agent skill that google/GitHub/Discord OAuth flows, PKCE, token refresh, and session management.

対応~Claude Code~Codex CLI~Cursor
npx skills add https://github.com/YepAPI/skills/tree/HEAD/skills/oauth-providers

お気に入りのAIに質問する

このエージェントスキルを事前に読み込んだ状態で新しいチャットを開きます。

ドキュメント

OAuth Providers

Rules

  • Use Authorization Code flow with PKCE for public clients (SPAs, mobile) — never Implicit flow
  • Server-side code exchange for web apps — the client secret never leaves the server
  • State parameter: generate random state, store in session/cookie, verify on callback — prevents CSRF
  • Google OAuth: scopes openid email profile, use id_token for user info
  • GitHub OAuth: scope read:user user:email, exchange code at https://github.com/login/oauth/access_token
  • Discord OAuth: scope identify email, token endpoint at https://discord.com/api/oauth2/token
  • Token refresh: store refresh_token server-side, refresh before access_token expires
  • Session management: create app session on successful OAuth callback, don't store OAuth tokens in cookies
  • Link accounts: allow users to connect multiple providers to one account via accounts table

Patterns

// OAuth callback handler
export async function GET(req: Request) {
  const { searchParams } = new URL(req.url);
  const code = searchParams.get("code");
  const state = searchParams.get("state");

  // Verify state matches stored value
  if (state !== cookies().get("oauth_state")?.value) {
    return new Response("Invalid state", { status: 400 });
  }

  // Exchange code for tokens
  const tokens = await exchangeCodeForTokens(code);
  const userInfo = await fetchUserInfo(tokens.access_token);

  // Create or link account, create session
  const user = await upsertUser(userInfo);
  await createSession(user.id);

  return redirect("/dashboard");
}

Avoid

  • Storing client secrets in frontend code — always exchange tokens server-side
  • Skipping the state parameter — CSRF attacks are real
  • Storing raw OAuth tokens in cookies — use server-side sessions
  • Forgetting to handle the "user already exists with that email" case when linking providers

Individual skills in this repo

This repo contains 20 individual skills — each has its own dedicated page.

YepAPI/skills

WCAG 2.1 AA — semantic HTML, keyboard navigation, screen readers.

YepAPI/skills

CRUD generators, data tables, user management, role-based access, and bulk operations.

YepAPI/skills

Tool-use patterns, multi-step reasoning, agent orchestration, and structured outputs.

YepAPI/skills

Chat UI components, streaming responses with AI SDK, context window management, and RAG patterns.

YepAPI/skills

Monitor what ChatGPT and Gemini say about your brand using YepAPI.

YepAPI/skills

Web analytics integration — event tracking, custom dashboards, privacy-first.

YepAPI/skills

Framer Motion — transitions, scroll animations, layout animations.

YepAPI/skills

OpenAPI 3.1 from Zod schemas, interactive docs with Swagger/Scalar, versioning, and example requests for every endpoint.

YepAPI/skills

Authentication security — bcrypt/argon2 hashing, brute force protection, secure password resets.

YepAPI/skills

Session auth, social providers, CSRF protection, and secure cookie patterns.

YepAPI/skills

Queue workers with BullMQ/Inngest/Trigger.dev, job retries, dead letter queues, concurrency.

YepAPI/skills

Link building research and backlink audit using YepAPI.

YepAPI/skills

MDX blog setup, RSS feed generation, sitemap.xml, structured data/JSON-LD, and related posts.

YepAPI/skills

Redis caching, CDN cache headers, stale-while-revalidate, cache invalidation, React Query.

YepAPI/skills

Recharts/Chart.js data visualization — bar, line, area, pie charts.

YepAPI/skills

Commander.js, interactive prompts with Clack, spinners, colors, config files, exit codes, and npm publishing.

YepAPI/skills

cmdk integration, Cmd+K trigger, fuzzy search, grouped actions, keyboard navigation, and dynamic action registration.

YepAPI/skills

Threaded comments, @mentions, reactions, moderation queue, optimistic UI, and cursor pagination.

YepAPI/skills

Competitive analysis between domains using YepAPI.

YepAPI/skills

Experiment setup, variant splitting, statistical significance, and feature flag integration.

関連スキル