auth-hardening

Installation
SKILL.md

Auth Hardening

Overview

NextAuth v5 (Auth.js) gets the cookie/CSRF/session-signing basics right by default — the actual gap on real projects is almost always missing per-route authorization checks, because middleware-level route protection feels like it covers everything and doesn't. Middleware can gate page navigation; it does not gate every API route, server action, and route handler, each of which needs its own explicit check.

Workflow

  1. Session strategy — for most products, strategy: 'jwt' is the default and fine for stateless scaling on Render. Switch to strategy: 'database' (session table via Prisma adapter) only when session revocation needs to be immediate (e.g., "log this user out everywhere right now" for a compromised account) — JWT sessions can't be invalidated server-side before expiry without a denylist.
Installs
1
First Seen
Aug 7, 2026
auth-hardening — stylusnexus/agent-plugins