auth-handbook
Installation
SKILL.md
Instructions
Design authentication and authorization for Next.js App Router without inventing a vendor SDK. Read auth-sessions.md before proposing cookie or OAuth changes.
When to Use
- Use when designing sessions, OAuth/OIDC callbacks, middleware auth gates, or RBAC placement.
- Prefer
env-config-agentfirst if secrets /NEXT_PUBLIC_*leakage is the main issue. - Prefer
security-headersafter cookies settle if CSP is breaking login or OAuth popups. - Prefer passkeys-only deep work only when the user explicitly asks (out of scope here).
- Sessions: prefer httpOnly
SecureSameSitecookies for browser sessions; store only opaque session id server-side; never expose session secrets inNEXT_PUBLIC_*(seeenv-config-agent). Use the strategy table in auth-sessions.md. - CSRF: for cookie-based sessions, use SameSite=Lax default; for cross-site POSTs, explicit CSRF token or the pattern documented by the auth library already in the repo.
- OAuth / OIDC: validate
state; use PKCE for public clients; fixed redirect URI allowlist; exchange code server-side only. - RBAC: enforce permissions in Server Actions, Route Handlers, and data access layers - never rely on hiding UI buttons alone.
- Passwords: if applicable, bcrypt/argon2 via an established server library; never log passwords; rate-limit credential endpoints (gateway or middleware).
- Middleware: coarse checks only (session presence); heavy auth logic stays in server modules so Edge bundles stay small when middleware runs on Edge.
- Failure modes: document infinite redirect loops (middleware vs layout fighting) and Secure-cookie-on-http-localhost before shipping.