Agent skill

Configuration Authentication User Transforms

by greenpau in greenpau/caddy-security

Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules.

Apache-2.0Auto-check passedBackend & APIs

Install Configuration Authentication User Transforms

skills CLI
$ npx skills add greenpau/caddy-security --skill configuration-authentication-user-transforms -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install greenpau/caddy-security configuration-authentication-user-transforms --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-authentication-user-transforms .claude/skills/configuration-authentication-user-transforms && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuration-authentication-user-transforms
GitHub stars
2.3k
Token cost
~3k tokens
SKILL.md length
1,279 words
Files
2
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules.

  • Authentication-time policy
  • SKILL.md covers Matchers and actions, GitHub identity matchers, Unconditional matching and Conditional authentication, plus 1 more section
  • Calls go
  • Stored account rules belong to configuration-users

What it does

Configuration Authentication User Transforms is an agent skill from greenpau/caddy-security. Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules. Use for authentication-time policy; stored account rules belong to configuration-users.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Backend & APIs, covering Authentication. It works with GitHub. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.

When your agent uses it

  • Authentication-time policy
  • Stored account rules belong to configuration-users

Example prompts

  • “/configuration-authentication-user-transforms”

What it can do on your machine

Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuration Authentication User Transforms loads about 3k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 1,279 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 1,279 words, ~2,982 tokens.

Download SKILL.mdSave it as .claude/skills/configuration-authentication-user-transforms/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
configuration-authentication-user-transforms
description
Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules. Use for authentication-time policy; stored account rules belong to configuration-users.

Configuration Authentication User Transforms

Use for transform user or transform users inside an authentication portal. caddyfile_authn_transform.go forwards the complete block to the selected module's pkg/authn/transformer/parser; provisioning resolves individual arguments and compiles the result again. Inspect go list -m -json github.com/greenpau/go-authcrunch before relying on sibling source. The published v1.3.8 supports the grammar below.

The surrounding portal configuration owns wiring; static users own stored challenge rules. The authentication flow contract owns login and profile API behavior. Load those details only when changing the corresponding boundary, rather than reloading the portal router for a transform.

Matchers and actions

Every block needs at least one matcher and one action. Conditions combine as match-all. Ordinary bare match retains the historical exact match spelling in adapted JSON; match any stays unconditional and match github retains its provider-specific spelling, including malformed statements for shared validation. Classification uses the shared parser, so a claim value containing the word match remains an action. These are alternative statements inside a transform, not a complete config:

caddyfile
match any
match realm local
field email exists
field picture not exists
partial match email @example.com
no regex match any role ^authp/(admin|user)$
action add role authp/user
action overwrite roles authp/user
action drop matched role
action delete org
require mfa
deny
ui link "User Profile" /auth/profile/ icon "las la-cog" target_blank

ACL strategies are exact, partial, prefix, suffix, and regex, with optional no and any according to pkg/acl/condition.go. Field aliases come from pkg/acl/acl.go: for example role/group/groups → roles, mail → email, and subject → sub. amr is a list of verified methods.

action is optional before add, overwrite, delete and drop; it does not prefix require. block and deny are synonyms. Actions and matching transforms retain declaration order. overwrite accepts known claim fields; delete also removes custom fields. Custom claims use add with an explicit type:

caddyfile
add matrix_id "@{claims.sub}:matrix.example.com" as string
add teams "operations team" support as string list
add nested metadata label with "literal value" as string
add nested empty as map

A custom scalar needs exactly one value. List aliases are list, string_list and the two keywords string list. Nested paths need at least one key; values follow with, and an empty map uses as map. Nested values are literal; ordinary string/list actions expand claim placeholders. Follow pkg/authn/transformer/parser/custom_fields.go and its runtime consumer rather than inferring grammar from JSON.

{env.*} and whole-value secrets:<id>:<key> resolve during Caddy provisioning. {claims.*} templates survive that pass only in transform arguments and expand at authentication time in action values. ACL matcher values remain literal. Quotes, spaces and secrets remain a single argument; empty resolved tokens and unknown Caddy placeholders in configured arguments fail provisioning. Encoded native JSON actions and matchers must each contain one line; reject CR/LF before decoding so a later CSV record cannot disappear. Resolved multiline transform values also fail shared validation. Caddy does not recursively expand inserted replacement data. See runtime resolution.

GitHub identity matchers

Inside a portal, require both a stable account ID and organization membership:

caddyfile
transform user {
	match github id exact 12345678
	match github org exact acme
	action add role authp/admin
}

For alternatives, use separate blocks. An organization-only block can use regex:

caddyfile
transform user {
	match github org regex ^(acme|acme-labs)$
	action add role authp/user
}

The four forms are match github id exact <id>, match github id regex <pattern>, match github org exact <login> and match github org regex <pattern>. Each accepts exactly one operand. Quote patterns containing spaces or Caddy delimiters. Exact IDs are canonical positive uint64 decimals: zero, signs, leading zeros, fractions, exponent notation and overflow are rejected. Organization operands are login names, not display names or numeric organization IDs. Matching is case-sensitive; regex uses Go regexp search semantics. Anchor whole-value matches; request case folding with (?i). Distinct conditions in one block are ANDed. One organization condition succeeds if any eligible organization matches. Missing claims never satisfy these positive matchers, even regex .*. Duplicate conditions for the same field, invalid regex and malformed arguments fail shared validation without exposing operands.

Organization matching requires the existing provider-body setting:

caddyfile
user_org_filters .*

Use narrower filters for eligible organizations. With no filter, lookup is disabled and organization conditions cannot match. The lookup reads one page of public membership from GitHub's organizations_url; it adds neither pagination nor private membership discovery. Adding read:org alone does not change that endpoint. See GitHub's list-user-organizations API and the provider claim contract.

github_id is a lossless string derived from /user's numeric ID; metadata.id remains numeric and sub remains github.com/<login>. Renaming an account leaves ID matching stable. An absent ID does not match; a supplied malformed ID rejects login. github_orgs contains filtered organization logins; existing github.com/<org>/members groups remain available. The portal establishes trust from the selected backend's driver, not realm names, origin, roles or groups. Both claims are read-only to transform actions, including nested writes.

The shared compiler owns lowering and validation for Caddyfile and persisted JSON configurations. Never implement a second GitHub parser in Caddy or rewrite serialized matchers. Lower-level exact match github_id ... and regex match github_orgs ... remain supported. A direct transformer factory caller must supply trusted provider claims; arbitrary caller-created maps do not establish authenticated GitHub identity.

Show full SKILL.md (546 more words)Show less

Unconditional matching

match any applies without requiring token timestamps in selected AuthCrunch v1.3.11. It is supported with portal refresh, OIDC and System API keys as well as ordinary access-only login. The earlier Caddy compatibility restriction is removed. Use realm matchers when policy should apply only to selected backends; do not fabricate exp or rewrite matchers to make unconditional rules run.

TestPortalTransformMatchAnyIdentityContext and TestPortalTransformMatchAnyEncoding check timed and untimed claims through Caddy resolution, including quoted and runtime-resolved native JSON matchers. The testcase_authenticate_with_match_any_refresh and testcase_authenticate_with_match_any_system fixtures adapt and resolve. The challenge TLS journey checks unconditional factor selection and claims in login and refresh, successful OIDC identity revalidation, and Basic rejection without the required proof. System API E2E checks unconditional transformed claims and rejects password-only assertions when the policy requires TOTP. Malformed multiline transforms still reject replacement without disturbing the serving app. See the dependency qualification.

Conditional authentication

Inside a portal, this policy prefers an enrolled security key, then an enrolled TOTP token, then the account password:

caddyfile
transform user {
	match realm local
	require auth challenges u2f
	require auth challenges totp if u2f not available
	require auth challenges password if u2f and totp not available
}

Rule bodies are parsed by pkg/authchal/parser:

text
<method> [<method>...] [if <method> [and <method>...] not available]
<method> [or <method>...] [if <method> [and <method>...] not available]

Methods are password, totp, u2f, and mfa. Adjacent methods require all; or selects the first available alternative. mfa represents an available second factor. Conditions require the named credentials to be unavailable. Do not mix an or choice with adjacent-method requirements. Duplicate rules, unknown methods and email methods/conditions are rejected: the portal has no email checkpoint. Method keywords are literal configuration, not placeholders.

The first eligible rule across matching transforms replaces backend/user challenge selection. Credential availability comes from server-owned inventory, never roles, amr, or transformed claims. If a matched conditional policy has no eligible rule, authentication fails; it does not fall back to a password. Without a matching conditional policy, stored user rules/defaults apply.

Legacy require password|mfa|totp|u2f remains additive after selection; it can force MFA enrollment when appropriate. Replacing the backend policy can remove the password checkpoint: a TOTP-only or U2F-only rule is a deliberate policy choice. Use adjacent password totp when both proofs are required.

Successful tokens receive authoritative AMR evidence: password → pwd, TOTP → otp, WebAuthn/U2F → hwk. Transform actions cannot fabricate completed methods. Direct Basic and API-key login, portal refresh, OP sessions and OIDC refresh reevaluate current policy and cannot bypass unmet requirements. Request-context matchers (such as issuer/address) evaluate current request context, including backchannel requests; use stable realm/identity selectors unless that context dependence is intentional.

Validation

caddyfile_authn_transform_test.go covers shared parsing, custom claims, canonical JSON, conditional selection, errors and runtime replacement. testcase_authenticate_with_challenges supplies adapt/resolution fixtures. TestCaddyAuthenticationChallengesE2E exercises actual verified Caddy TLS: root/nested mounts, HTML/JSON and native clients, TOTP/U2F-only selection, password fallback, AMR authorization, refresh/OIDC, Basic/API-key rejection, no eligible rule, stored policies and profile edits. WebAuthn uses signed assertions and rejects wrong origin and signature. Keep these boundaries when extending syntax.

TestPortalTransformGithubMatchers and TestPortalTransformGithubRejects check provider syntax, quote boundaries, persisted matchers, ordinary ACL compatibility, shared errors and reserved claims. The testcase_authenticate_with_github_transforms adaptation fixture contains all four forms. TestCaddyGithubTransformsE2E adapts and provisions Caddy, follows OAuth code exchange over verified local TLS, independently verifies the signed portal token and checks a protected route. It covers exact/regex matches and misses, AND semantics, renamed and large IDs, missing/malformed claims, filtered/empty/denied organization lookup and a different driver using a realm named github. Fixed provider URLs terminate at a bounded loopback CONNECT proxy in an isolated subprocess; no production endpoint or trust overrides are added.

© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .codex/skills/configuration-authentication-user-transforms of greenpau/caddy-security.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit a48553d

Compare with similar skills

Configuration Authentication User Transforms next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuration Authentication User Transforms compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuration Authentication User Transforms this skillgreenpau/caddy-security2.3k—~3kAutomated safety check: PassApache-2.0
Jwx Guide V4lestrrat-go/jwx2.4k—~5.3kAutomated safety check: PassMIT
GitHub OAuth Nango IntegrationAgentWorkforce/relay8661 repos~3.4kAutomated safety check: PassApache-2.0
JWTkataras/jwt212—~1.5kAutomated safety check: PassMIT
Auth Setupbutterbase-ai/butterbase-skills534—~2.2kAutomated safety check: PassMIT
Apikerhodgef/apiker127—~1.4kAutomated safety check: PassMIT

Similar skills

  • Jwx Guide V4

    lestrrat-go/jwx

    Guide for developing Go applications with github.com/lestrrat-go/jwx v4 — parse/sign JWTs, work with JWS/JWE/JWK, pick algorithms, and avoid the common footguns.

    2.4k GitHub stars~5.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • GitHub OAuth Nango Integration

    AgentWorkforce/relay

    A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling

    866 GitHub starsUsed in 1 repo~3.4k tokens
    Backend & APIsAuto-check passed
  • JWT

    kataras/jwt

    Development guide for the jwt JSON Web Token library for Go (github.com/kataras/jwt).

    212 GitHub stars~1.5k tokensUpdated 25 days ago
    Backend & APIsAuto-check passed
  • Auth Setup

    butterbase-ai/butterbase-skills

    A skill your agent uses when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys

    534 GitHub stars~2.2k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Apiker

    hodgef/apiker

    Develop, review, and extend the Apiker library — a framework for building serverless REST APIs on Cloudflare Workers + Durable Objects.

    127 GitHub stars~1.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Auth

    microsoft/apm

    Official

    Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth'…

    4k GitHub stars~756 tokensUpdated today
    Backend & APIsAuto-check passed

More from greenpau/caddy-security

All 29 skills in this repo
  • Authentication Portal API

    greenpau/caddy-security

    Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.

    2.3k GitHub stars~2.9k tokensUpdated 3 days ago
    Auto-check passed
  • Coding Directives

    greenpau/caddy-security

    Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.

    2.3k GitHub stars~4.1k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration

    greenpau/caddy-security

    Build or review caddy-security Caddyfiles and select focused configuration skills.

    2.3k GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration HTTP Integrations

    greenpau/caddy-security

    Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.

    2.3k GitHub stars~3.2k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration State

    greenpau/caddy-security

    Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.

    2.3k GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed

Works with

Categories

Questions about Configuration Authentication User Transforms

What does Configuration Authentication User Transforms do?

Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules. Configuration Authentication User Transforms is an agent skill from greenpau/caddy-security. Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules.

When should I use Configuration Authentication User Transforms?

Configuration Authentication User Transforms fits situations like: authentication-time policy; stored account rules belong to configuration-users.

How do I install Configuration Authentication User Transforms in Claude Code?

Run `npx skills add greenpau/caddy-security --skill configuration-authentication-user-transforms -a claude-code`. Or copy the skill folder (.codex/skills/configuration-authentication-user-transforms in greenpau/caddy-security) into .claude/skills/configuration-authentication-user-transforms in your project. Claude Code loads it when a task matches its description.

How do I install Configuration Authentication User Transforms in Codex?

Run `npx skills add greenpau/caddy-security --skill configuration-authentication-user-transforms -a codex`. Or copy the skill folder (.codex/skills/configuration-authentication-user-transforms in greenpau/caddy-security) into .agents/skills/configuration-authentication-user-transforms in your project. Codex loads it when a task matches its description.

Can I use Configuration Authentication User Transforms in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-authentication-user-transforms -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-authentication-user-transforms, .gemini/skills/configuration-authentication-user-transforms, .github/skills/configuration-authentication-user-transforms and .opencode/skills/configuration-authentication-user-transforms in your project.

What does Configuration Authentication User Transforms need to run?

Going by SKILL.md and its folder, Configuration Authentication User Transforms needs the command-line tools its instructions call (go).

Does Configuration Authentication User Transforms access the network?

SKILL.md names 1 domain. As links in the text: docs.github.com. This is read from the text; nothing was executed.

Is Configuration Authentication User Transforms safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configuration Authentication User Transforms use?

Configuration Authentication User Transforms is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuration Authentication User Transforms use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Configuration Authentication User Transforms?

Skills that share tags, products or a category with Configuration Authentication User Transforms: Jwx Guide V4 (lestrrat-go/jwx, 2.4k stars), GitHub OAuth Nango Integration (AgentWorkforce/relay, 866 stars), JWT (kataras/jwt, 212 stars) and Auth Setup (butterbase-ai/butterbase-skills, 534 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuration Authentication User Transforms?

greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,251 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.

Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.