认证 Quickstart
- 作者仓库星标 0
- 作者仓库 skills-registry
Auth Quickstart: Zero to Running Service
Scaffold a complete FastAPI service with ab0t-auth baked in from the start.
When to Use This vs auth_fastapi_skill
| Situation | Use |
|---|---|
| No code exists yet | This skill |
| Existing service needs auth added | auth_fastapi_skill |
| Need to understand permission design in depth | auth_fastapi_skill |
| Need scenario walkthroughs by industry | auth_service_ab0t |
Scaffold Workflow
Step 1: Gather Requirements
Ask the user for:
- Service name — human-readable (e.g., "Invoice Service")
- Service slug — lowercase identifier (e.g.,
invoices). Used in permissions, audience, file names. - Domain resources — the nouns (e.g., invoices, payments, customers)
- Actions per resource — the verbs (e.g., read, write, create, delete, send, approve)
- Maintainer email — for
.permissions.json
If the user is vague, suggest reasonable defaults and confirm.
Step 2: Copy and Customize Template
The template lives in assets/template/. Copy the entire directory to the user's target path, then replace all placeholders:
| Placeholder | Replace with |
|---|---|
__SERVICE_NAME__ |
Human-readable name |
__SERVICE_SLUG__ |
Lowercase slug |
__SERVICE_DESCRIPTION__ |
One-line description |
__MAINTAINER_EMAIL__ |
Contact email |
Files to customize:
.permissions.json— Replace starter permissions with real ones derived from the user's resources and actions. Follow the{slug}.{action}.{resource}format. Setadmin.impliesto include all lower permissions. Never implycross_tenant.app/auth.py— Replace starter type aliases (Reader,Writer,Admin) with domain-specific aliases matching the permissions. Example for an invoice service:InvoiceReader = Annotated[AuthenticatedUser, Depends( require_permission(auth, "invoices.read", check=belongs_to_org))] InvoiceSender = Annotated[AuthenticatedUser, Depends( require_permission(auth, "invoices.send", check=belongs_to_org))]app/api/items.py— Rename to match the primary resource (e.g.,invoices.py). Replace the example routes with real ones using the domain-specific type aliases. Keep the same auth patterns (list with filter, get with Phase 2, create without Phase 2, delete with Phase 2, admin-only).app/main.py— Update the router import and prefix to match the renamed module.app/config.py— Add any service-specific settings.
Step 3: Verify Structure
After customization, the project should have:
my-service/
├── app/
│ ├── __init__.py
│ ├── main.py # FastAPI app with auth lifespan
│ ├── config.py # Pydantic settings
│ ├── auth.py # AuthGuard, type aliases, Phase 2, check callbacks
│ └── api/
│ ├── __init__.py
│ ├── health.py # Unauthenticated health check
│ └── {resource}.py # Auth-protected CRUD routes
├── .permissions.json # Permission definitions for registration
├── .env.example # Environment variable reference
├── .gitignore # Excludes credentials/, .env, etc.
├── requirements.txt # Dependencies including ab0t-auth
└── Dockerfile # Production container
Step 4: Run Locally
cd my-service
python -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
cp .env.example .env # Edit values
# Development with auth bypass
AB0T_AUTH_DEBUG=true AB0T_AUTH_BYPASS=true uvicorn app.main:app --reload
Verify:
GET /healthreturns{"status": "ok"}(no auth)GET /items/returns data with bypass user (auth bypassed)- Routes return proper 401/403 JSON when bypass is off and no token is provided
Step 5: Guide Next Steps
After the scaffold is running, point the user to references/next-steps.md for:
- Adding more permissions and type aliases
- Adding check callbacks (suspension, quota)
- Wiring up Phase 2 ownership verification with a real database
- Registering with the auth service
- Multi-tenancy setup
- Middleware for blanket auth
- Production checklist
For deep dives, reference the auth_fastapi_skill:
- permissions-design.md — full schema and design principles
- route-patterns.md — all 7 route protection patterns
- implementation-details.md — all 19 type aliases, check callbacks
- registration.md — auth service registration walkthrough
Permission Design Quick Reference
Format: {slug}.{action} or {slug}.{action}.{resource}
| Action | Meaning | Risk |
|---|---|---|
read |
View without side effects | low |
write |
Modify existing records | medium |
create |
Create new records | medium |
delete |
Permanently remove | high |
execute |
Run user-provided code | high |
admin |
Full org-level access (implies lower perms) | critical |
cross_tenant |
Cross-org access (NEVER implied by admin) | critical |
Common Mistakes
- Forgetting to rename placeholders — grep for
__SERVICEafter scaffolding to catch any missed replacements - Skipping Phase 2 — every route with
/{id}in the path needsverify_resource_access()after the DB fetch - Implying
cross_tenantfromadmin— never do this; it must be a conscious separate grant - Unscoped list queries — always use
get_user_filter(user)for list/search routes - 404 after 403 — always check resource exists (404) before checking access (403)
<!-- tomevault:4.0:skill_md:2026-05-22 -->Source: ab0t-com/auth_wrapper — distributed by TomeVault.
- 流狐分类
- 运维部署
- 作者声明 Agent
- 未找到明确声明;不据此推断已兼容或已测试
- 静态检查
- 88 / 100 · 启发式扫描,不代表运行安全
- 作者 / 版本 / 许可
- @tomevault-io · 未声明 license
- 流狐 Token 估算
- 低消耗
- 流狐接入估算
- 需手动接入
- 是否需要外部 API Key
- 未发现要求
- 检测到的系统要求
- Docker
- 底层运行要求
- Python · Docker
- 检测到的文件与系统行为
-
- 只读
- 允许写入 / 修改
- Shell 执行
- 读取环境变量
- 检测到的网络行为
- 允许外网请求
- 安装命令数
- 无(仅作为资料)
档案由构建时根据 SKILL.md 与安装命令自动衍生,可能与作者实际意图存在差异。
需要注意: 未限定 allowed-tools,默认拥有全部工具权限。
作者没有在当前 SKILL.md 中定义固定输出样例。 Scaffold Workflow
Ask the user for: Service name — human-readable (e.g., "Invoice Service") Service slug — lowercase identifier (e.g., invoices). Used in permissions, audience, file names.
The template lives in assets/template/. Copy the entire directory to the user's target path, then replace all placeholders: Placeholder · Replace with SERVICENAME · Human-readable name
After customization, the project should have:
Verify: GET /health returns {"status": "ok"} (no auth) GET /items/ returns data with bypass user (auth bypassed)
After the scaffold is running, point the user to references/next-steps.md for: Adding more permissions and type aliases Adding check callbacks (suspension, quota)
# Auth Quickstart: Zero to Running Service
Scaffold a complete FastAPI service with ab0t-auth baked in from the start.
## When to Use This vs auth_fastapi_skill
| Situation | Use |
|-----------|-----|
| No code exists yet | **This skill** |
| Existing service needs auth added | auth_fastapi_skill |
| Need to understand permission design in depth | auth_fastapi_skill |
| Need scenario walkthroughs by industry | auth_service_ab0t |
## Scaffold Workflow
### Step 1: Gather Requirements
Ask the user for:
1. **Service name** — human-readable (e.g., "Invoice Service")
2. **Service slug** — lowercase identifier (e.g., `invoices`). Used in permissions, audience, file names.
3. **Domain resources** — the nouns (e.g., invoices, payments, customers)
4. **Actions per resource** — the verbs (e.g., read, write, create, delete, send, approve)
5. **Maintainer email** — for `.permissions.json`
If the user is vague, suggest reasonable defaults and confirm.
### Step 2: Copy and Customize Template
The template lives in `assets/template/`. Copy the entire directory to the user's target path, then replace all placeholders:
| Placeholder | Replace with |
|-------------|-------------|
| `__SERVICE_NAME__` | Human-readable name |
| `__SERVICE_SLUG__` | Lowercase slug |
| `__SERVICE_DESCRIPTION__` | One-line description |
| `__MAINTAINER_EMAIL__` | Contact email |
**Files to customize:**
1. **`.permissions.json`** — Replace starter permissions with real ones derived from the user's resources and actions. Follow the `{slug}.{action}.{resource}` format. Set `admin.implies` to include all lower permissions. Never imply `cross_tenant`.
… 作者原文负责流程事实;流狐只索引当前章节、要点、文件与命令。
章节 -> When to Use This vs authfastapiskill → Scaffold Workflow → Step 1: Gather Requirements → Step 2: Copy and Customize Template → Step 3: Verify Structure → Step 4: Run Locally
要点 -> This skill · Service name · Service slug · Domain resources · Actions per resource · Maintainer email · Files to customize · .permissions.json
文件/命令 -> invoices · .permissions.json · assets/template/ · SERVICENAME · SERVICESLUG · SERVICEDESCRIPTION · MAINTAINEREMAIL · {slug}.{action}.{resource}
内容 SHA-256 -> 477887f38123
方法与流程
适用与边界
原文中的明确线索
invoices、.permissions.json、assets/template/、SERVICENAME、SERVICESLUG、SERVICEDESCRIPTION、MAINTAINEREMAIL、{slug}.{action}.{resource}