All skills
gogf avatar

/goframe-v2

@911705d
by GoFramegogf/skills81 stars
3

GoFrame v2 development skill. Use only when the target Go project uses or is explicitly adopting GoFrame v2: the nearest go.mod requires github.com/gogf/gf/v2, existing Go files import github.com/gogf/gf/v2 or any github.com/gogf/gf/v2/... component package, or the user asks to scaffold, migrate, or build with GoFrame. Trigger for GoFrame-backed Go work such as APIs/controllers/services, middleware, routing/config, ORM/DAO/DO/entity/database operations, gf CLI/codegen, HTTP/gRPC services, and microservice conventions. Do not trigger for generic Go projects without GoFrame evidence, frontend-only work, shell scripts, or unrelated infrastructure tasks.

Use this Skill: https://skilld.dev/gh/gogf/skills/goframe-v2

This session only. Nothing lands on disk.

exampleshttpserverbasic-authREADME.ZH.MD

≈919 tokens on demand. Your agent reads this file only when SKILL.md points to it.

HTTP 服务器基本认证

介绍

本示例展示了如何使用 GoFrame 框架实现 HTTP 基本认证(Basic Authentication)。基本认证是一种简单的认证机制,允许服务器在授予对受保护资源的访问权限之前请求客户端提供凭据。

示例展示了如何:

  • 设置带有受保护资源的基本 HTTP 服务器
  • 使用 GoFrame 内置的 BasicAuth 方法实现基本认证
  • 处理认证成功和失败的情况
  • 自定义认证领域(realm)消息

环境要求

目录结构

basic-auth/
├── README.MD     # 英文文档
├── README.ZH.MD  # 中文文档
├── go.mod        # Go 模块文件
└── main.go       # 主程序入口

功能特点

  • 简单且安全的 HTTP 基本认证
  • 自动处理认证头部
  • 可自定义认证领域消息
  • 清晰分离认证逻辑

安装设置

  1. 克隆仓库:

    git clone https://github.com/gogf/examples.git
    cd examples/httpserver/basic-auth
  2. 安装依赖:

    go mod tidy
  3. 运行应用:

    go run main.go

使用方法

  1. 启动服务器:

    go run main.go
  2. 服务器将在 8000 端口启动。

  3. 访问受保护的资源:

  4. 认证成功后,您将看到消息:"Authentication successful!"

实现细节

服务器使用 GoFrame 的 BasicAuth 方法实现 HTTP 基本认证。该方法:

  1. 检查请求是否包含有效的基本认证凭据
  2. 如果凭据缺失或无效,它会自动:
    • 设置带有指定领域的 WWW-Authenticate 头部
    • 返回 401 未授权状态码
    • 使浏览器显示认证对话框
  3. 如果认证成功,它返回 true 并允许处理程序继续处理受保护的内容

实现非常简洁,只需要很少的代码:

if r.BasicAuth("user", "pass", "Please enter username and password") {
    // 认证成功后的处理
    r.Response.Write("Authentication successful!")
}
// 如果认证失败,BasicAuth 方法会自动处理响应

注意事项

  • 基本认证以 base64 编码传输凭据,在纯 HTTP 上不安全
  • 在生产环境中,始终将基本认证与 HTTPS 结合使用
  • 本示例中的凭据是硬编码的,仅用于演示目的;在实际应用中,应使用安全的凭据存储

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk MEDIUM
  • Gen Agent Trust Hub16d

    The skill provides a comprehensive development guide and code examples for the GoFrame v2 framework. While highly informative for Go developers, it contains several examples with hardcoded placeholder secrets, tokens, and specific local file paths to sensitive configuration files (like Kubernetes credentials). These elements are provided for demonstration purposes but represent insecure practices if used in production without modification.

  • Socket16d

    5 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    227/949 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 911705d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 4 months ago.

Steadyupdated 4 months ago
  • Go
  • Database
  • goframe
  • orm
  • http
  • grpc
  • microservices
  • crud
  • scaffolding
  • middleware

README badge

README badge for gogf/skills

Provides instruction and conventions for developing with GoFrame v2, a modular Go framework for building HTTP and gRPC services, microservices, and database operations using its ORM, CLI tooling, and project scaffolding. Use this skill when the target project has GoFrame v2 as a dependency or when the user requests scaffolding, migrations, or service development with GoFrame conventions.

Generated from the current SKILL.md.

When should I use this skill?
Use this skill only when your Go project uses GoFrame v2, indicated by github.com/gogf/gf/v2 in go.mod or imports. Do not use for generic Go projects, frontend work, or infrastructure tasks unrelated to GoFrame.
Should I manually set created_at and updated_at fields?
No. GoFrame automatically writes created_at on insert and updated_at on insert/update/save. Manually setting these fields is redundant and violates project conventions.
What should I use for database operations instead of g.Map?
Always use DO objects from internal/model/do/. DO struct fields are interface{}, unset fields remain nil and are automatically ignored by the ORM.
How does soft delete work in GoFrame?
Call Delete() on the DAO; GoFrame automatically converts it to UPDATE SET deleted_at = NOW(). Queries automatically filter out soft-deleted rows without requiring manual WhereNull conditions.
Where should I implement business logic?
Implement business logic directly in the service/ directory. Do not use the logic/ directory unless explicitly requested.

Generated from the current SKILL.md. These answers refresh after source changes.