Agent Skills › fmaclen/canutin › auth-system

auth-system

GitHub

基于PocketBase的前端认证系统,涵盖用户登录注册、Token管理、路由守卫及会话状态同步,确保受保护页面的安全访问。

.agents/skills/auth-system/SKILL.md fmaclen/canutin

Trigger Scenarios

需要实现或修改用户登录注册功能 处理前端路由权限控制和鉴逻辑 配置PocketBase认证相关客户端代码

Install

npx skills add fmaclen/canutin --skill auth-system -g -y
More Options

Non-standard path

npx skills add https://github.com/fmaclen/canutin/tree/master/.agents/skills/auth-system -g -y

Use without installing

npx skills use fmaclen/canutin@auth-system

指定 Agent (Claude Code)

npx skills add fmaclen/canutin --skill auth-system -a claude-code -g -y

安装 repo 全部 skill

npx skills add fmaclen/canutin --all -g -y

预览 repo 内 skill

npx skills add fmaclen/canutin --list

SKILL.md

Frontmatter
{
    "name": "auth-system",
    "description": "PocketBase-based auth - users collection, context store, protected route guard"
}

Authentication System

Overview

Canutin uses PocketBase's built-in users auth collection. The frontend auth state lives in src/lib/auth.svelte.ts. There is no external IdP.

Key Files

File Purpose
src/lib/auth.svelte.ts Auth context store (login, logout, state)
src/lib/pocketbase.svelte.ts PocketBase client wrapper
src/routes/(guest)/auth/ Login and signup pages
src/routes/(app)/+layout.svelte Protected route guard
src/routes/(guest)/+layout.ts Guest route layout

Collections

  • users — PocketBase auth collection. Email + password with emailVisibility controlled per record.
  • _superusers — PocketBase built-in superadmin collection (dev only).

Types are generated in src/lib/pocketbase.schema.ts.

Route Protection

  • src/routes/(app)/ — requires an authenticated user. (app)/+layout.svelte redirects to the auth page when authStore is unauthenticated.
  • src/routes/(guest)/ — public routes (auth forms, landing).

Login Flow

  1. User submits email + password on the auth form.
  2. authStore.login(email, password) calls pb.collection('users').authWithPassword(...).
  3. PocketBase SDK persists the token in localStorage via its default auth store.
  4. Context store updates; (app)/+layout.svelte stops redirecting.

Signup Flow

  1. User submits email + password + confirmation.
  2. pb.collection('users').create(...) then authWithPassword to immediately log in.

Saved sessions

An expired saved token must clear both the SDK auth store and currentUserId before startup finishes. Otherwise the route guard admits an unauthenticated session and presents incomplete financial totals. The guard waits for auth loading to finish before mounting protected routes. Foreground and online recovery also check token expiry. Every StaleSync refresh checks again before fetching financial records, including refreshes triggered by realtime events.

New user tokens last 14 days. Startup and visible/online returns renew a still-valid session through the same validateSession() path before the return-triggered financial refetch. Overlapping signals share one renewal request. Expired sessions require login; renewal does not revive expired tokens.

Renewal uses an isolated SDK auth store, then commits only if the original token and session version still match. Logout, teardown, and a new login invalidate pending renewal results. Network failures retain a still-valid session and log the failure, allowing data sync to retry when connectivity returns. A newer valid token for the same user, received from another tab, also allows data sync to continue.

Dev Credentials

  • Superadmin (auto-upserted by scripts/pb-server.ts): superadmin@example.com / 123qweasdzxc
  • Test users created via seedUser(name) in e2e/pocketbase.helpers.ts use DEFAULT_PASSWORD (123qweasdzxc) and a generated email like alice.<8-char-id>@example.com.

Testing

  • E2E tests use seedUser + the login helper in e2e/playwright.helpers.ts.
  • Never hardcode passwords in tests — always reference DEFAULT_PASSWORD.

Anti-patterns

  • Rolling a custom session store — trust the PocketBase SDK's auth store
  • Storing tokens outside the SDK — it handles persistence and refresh
  • Protecting a route via manual checks — use the (app) group layout
  • Using superadmin@example.com in production — dev only, never ship

See Also

Version History

  • 28eb754 Current 2026-09-23 01:21

Same Skill Collection

.agents/skills/architecture/SKILL.md
.agents/skills/code-quality/SKILL.md
.agents/skills/code-review/SKILL.md
.agents/skills/deployment/SKILL.md
.agents/skills/failure-discipline/SKILL.md
.agents/skills/failures-and-logs/SKILL.md
.agents/skills/frontend-design/SKILL.md
.agents/skills/issue-writing/SKILL.md
.agents/skills/local-servers/SKILL.md
.agents/skills/pb-import/SKILL.md
.agents/skills/pb-migrate/SKILL.md
.agents/skills/pocketbase/SKILL.md
.agents/skills/realtime/SKILL.md
.agents/skills/setup/SKILL.md
.agents/skills/svelte5/SKILL.md
.agents/skills/testing/SKILL.md
.agents/skills/verify/SKILL.md
.agents/skills/commits-and-prs/SKILL.md

Metadata

Files
0
Version
b491bd7
Hash
0f32ce7e
Indexed
2026-09-23 01:21

ホーム - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-09-28 17:41
浙ICP备14020137号-1