@tank/auth-patterns
Installation
SKILL.md
Auth Patterns
Core Philosophy
- Authentication is not authorization — Solve them separately. Authentication proves identity; authorization enforces what that identity may do.
- Default deny — All resources are denied unless explicitly permitted. Never default allow.
- Shortest lifetime possible — Access tokens: 5-15 minutes. Sessions: idle + absolute timeout. Backup codes: one use. Shorter lifetime = smaller breach window.
- Validate every input, every time — JWT signature, expiry, issuer, audience, nonce. Skipping one check is the vulnerability.
- Store nothing sensitive client-side — Tokens in HttpOnly cookies, secrets in secret managers, TOTP seeds encrypted at rest.