auth-hardening
Installation
SKILL.md
Auth Hardening
Overview
NextAuth v5 (Auth.js) gets the cookie/CSRF/session-signing basics right by default — the actual gap on real projects is almost always missing per-route authorization checks, because middleware-level route protection feels like it covers everything and doesn't. Middleware can gate page navigation; it does not gate every API route, server action, and route handler, each of which needs its own explicit check.
Workflow
- Session strategy — for most products,
strategy: 'jwt'is the default and fine for stateless scaling on Render. Switch tostrategy: 'database'(session table via Prisma adapter) only when session revocation needs to be immediate (e.g., "log this user out everywhere right now" for a compromised account) — JWT sessions can't be invalidated server-side before expiry without a denylist.