Communitygithub.com

YepAPI/skills

RBAC authorization — middleware guards, deny by default, resource-level permission checks.

skills 是什么?

skills is a Claude Code agent skill that rBAC authorization — middleware guards, deny by default, resource-level permission checks.

兼容平台~Claude Code~Codex CLI~Cursor
npx skills add https://github.com/YepAPI/skills/tree/HEAD/skills/rbac-authorization

在你喜欢的 AI 中提问

打开一个已预加载此 Agent Skill 的新对话。

文档

RBAC Authorization

Rules

  • Check permissions on EVERY route with middleware — never make authorization optional
  • Deny by default: if no explicit permission is granted, access is denied
  • Server-side enforcement: hiding UI elements is NOT security, check on the server
  • Define role hierarchy: admin > editor > viewer — higher roles inherit lower permissions
  • Resource-level checks: verify can(user, "edit", resource) — not just role-based access
  • Audit all permission checks — log who accessed what and when, especially for admin actions
  • Separate authentication (who are you?) from authorization (what can you do?)
// Permission check helper
type Action = "read" | "create" | "update" | "delete";
type Resource = { ownerId: string; [key: string]: any };

function can(user: { id: string; role: string }, action: Action, resource?: Resource): boolean {
  const permissions: Record<string, Action[]> = {
    admin: ["read", "create", "update", "delete"],
    editor: ["read", "create", "update"],
    viewer: ["read"],
  };
  const allowed = permissions[user.role];
  if (!allowed?.includes(action)) return false;
  // Resource-level check: editors can only modify their own resources
  if (resource && action !== "read" && user.role !== "admin") {
    return resource.ownerId === user.id;
  }
  return true;
}
// Express middleware guard
function requirePermission(action: Action) {
  return (req, res, next) => {
    if (!req.user) return res.status(401).json({ error: "Unauthenticated" });
    if (!can(req.user, action, req.resource)) {
      return res.status(403).json({ error: "Forbidden" });
    }
    next();
  };
}

app.put("/api/posts/:id", loadResource, requirePermission("update"), updatePost);

Avoid

  • Checking permissions only in the UI — attackers call your API directly
  • Allowing access unless explicitly denied — always deny by default
  • Using a single isAdmin boolean — roles should be granular and extensible
  • Forgetting resource-level checks — "editor" should not mean "can edit everyone's content"
  • Skipping authorization on "internal" endpoints — they become public eventually

Individual skills in this repo

This repo contains 20 individual skills — each has its own dedicated page.

YepAPI/skills

WCAG 2.1 AA — semantic HTML, keyboard navigation, screen readers.

YepAPI/skills

CRUD generators, data tables, user management, role-based access, and bulk operations.

YepAPI/skills

Tool-use patterns, multi-step reasoning, agent orchestration, and structured outputs.

YepAPI/skills

Chat UI components, streaming responses with AI SDK, context window management, and RAG patterns.

YepAPI/skills

Monitor what ChatGPT and Gemini say about your brand using YepAPI.

YepAPI/skills

Web analytics integration — event tracking, custom dashboards, privacy-first.

YepAPI/skills

Framer Motion — transitions, scroll animations, layout animations.

YepAPI/skills

OpenAPI 3.1 from Zod schemas, interactive docs with Swagger/Scalar, versioning, and example requests for every endpoint.

YepAPI/skills

Authentication security — bcrypt/argon2 hashing, brute force protection, secure password resets.

YepAPI/skills

Session auth, social providers, CSRF protection, and secure cookie patterns.

YepAPI/skills

Queue workers with BullMQ/Inngest/Trigger.dev, job retries, dead letter queues, concurrency.

YepAPI/skills

Link building research and backlink audit using YepAPI.

YepAPI/skills

MDX blog setup, RSS feed generation, sitemap.xml, structured data/JSON-LD, and related posts.

YepAPI/skills

Redis caching, CDN cache headers, stale-while-revalidate, cache invalidation, React Query.

YepAPI/skills

Recharts/Chart.js data visualization — bar, line, area, pie charts.

YepAPI/skills

Commander.js, interactive prompts with Clack, spinners, colors, config files, exit codes, and npm publishing.

YepAPI/skills

cmdk integration, Cmd+K trigger, fuzzy search, grouped actions, keyboard navigation, and dynamic action registration.

YepAPI/skills

Threaded comments, @mentions, reactions, moderation queue, optimistic UI, and cursor pagination.

YepAPI/skills

Competitive analysis between domains using YepAPI.

YepAPI/skills

Experiment setup, variant splitting, statistical significance, and feature flag integration.

相关技能