All skills
sailscastshq avatar

/authentication

@bf19e10

Authentication patterns for The Boring JavaScript Stack — session-based auth with password, magic links, passkeys (WebAuthn), two-factor authentication (TOTP/email/backup codes), password reset, and OAuth. Use this skill when implementing or modifying any authentication flow in a Sails.js application.

Use this Skill: https://skilld.dev/gh/sailscastshq/boring-stack/authentication

This session only. Nothing lands on disk.

README.md

≈480 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Authentication Skills for Claude Code

Build secure authentication flows for The Boring JavaScript Stack with Claude Code.

Installation

npx skills add sailscastshq/boring-stack/skills/authentication

Usage

After installing, Claude will automatically apply authentication best practices when you work on auth-related code:

"Add magic link login to my app"

"Set up passkey authentication with WebAuthn"

"Add two-factor authentication with TOTP and backup codes"

"Integrate Google OAuth for social login"

Skills Included

  • getting-started - Auth architecture, User model, policies, session management
  • password-auth - Signup, login, password hashing, remember me, validation
  • magic-links - Passwordless auth with secure token generation and verification
  • passkeys - WebAuthn registration and authentication with @simplewebauthn
  • two-factor - TOTP (authenticator app), email codes, backup codes
  • password-reset - Forgot password flow with secure token lifecycle
  • oauth - Google and GitHub OAuth via sails-hook-wish

Auth Methods

The Boring JavaScript Stack supports multiple authentication methods:

Method Library Template
Password bcrypt (sails-hook-organics) Mellow + Ascent
Magic Links Custom token helpers Mellow + Ascent
Passkeys @simplewebauthn/server Ascent
TOTP 2FA speakeasy Ascent
Email 2FA Custom code generation Ascent
OAuth sails-hook-wish Mellow + Ascent

Links

License

MIT

Source: SKILL.md on GitHub

2 warnings17d4 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill provides secure and comprehensive authentication patterns for Sails.js applications using The Boring JavaScript Stack, including password, magic link, passkey, and two-factor authentication.

  • Socket17d

    3 alerts: gptAnomaly, gptSecurity

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    10/10 files flagged

Signed by skilld at bf19e10. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 8 months ago
Other metadata
metadata
{
  "author": "sailscastshq",
  "version": "1.0.0",
  "tags": "authentication, auth, login, signup, password, magic-link, passkey, webauthn, 2fa, totp, oauth, boring-stack"
}

README badge

README badge for sailscastshq/boring-stack/authentication