Springboot Security
affaan-m/ECC
Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
Spring Boot 授权与企业组织架构模块一键叠加技能,组织权限领域的唯一权威技能。面向已使用 springboot-init-skill 生成的项目,标准化落地 RBAC、方法级鉴权、角色-菜单绑定、组织架构、岗位/租户、四级数据权限、个人鉴权与菜单回填接口。触发词:"Spring 授权模块","Spring Boot 权限模块","RBAC…
$ npx skills add jiushiwon/wg-skills --skill springboot-auth-module-skill -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jiushiwon/wg-skills springboot-auth-module-skill --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jiushiwon/wg-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/vibeCoding/backend/java/springboot-module/springboot-auth-module-skill .claude/skills/springboot-auth-module-skill && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "springboot-auth-module-skill" agent skill from https://github.com/jiushiwon/wg-skills/tree/main/vibeCoding/backend/java/springboot-module/springboot-auth-module-skill into .claude/skills/springboot-auth-module-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "springboot-auth-module-skill", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jiushiwon/wg-skills/tree/main/vibeCoding/backend/java/springboot-module/springboot-auth-module-skillType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jiushiwon/wg-skills --skill springboot-auth-module-skill -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jiushiwon/wg-skills springboot-auth-module-skill --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jiushiwon/wg-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/vibeCoding/backend/java/springboot-module/springboot-auth-module-skill .agents/skills/springboot-auth-module-skill && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "springboot-auth-module-skill" agent skill from https://github.com/jiushiwon/wg-skills/tree/main/vibeCoding/backend/java/springboot-module/springboot-auth-module-skill into .agents/skills/springboot-auth-module-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "springboot-auth-module-skill", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jiushiwon/wg-skills --skill springboot-auth-module-skill -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jiushiwon/wg-skills springboot-auth-module-skill --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jiushiwon/wg-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/vibeCoding/backend/java/springboot-module/springboot-auth-module-skill .cursor/skills/springboot-auth-module-skill && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "springboot-auth-module-skill" agent skill from https://github.com/jiushiwon/wg-skills/tree/main/vibeCoding/backend/java/springboot-module/springboot-auth-module-skill into .cursor/skills/springboot-auth-module-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "springboot-auth-module-skill", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jiushiwon/wg-skills.git --path vibeCoding/backend/java/springboot-module/springboot-auth-module-skill--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jiushiwon/wg-skills --skill springboot-auth-module-skill -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jiushiwon/wg-skills springboot-auth-module-skill --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jiushiwon/wg-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/vibeCoding/backend/java/springboot-module/springboot-auth-module-skill .gemini/skills/springboot-auth-module-skill && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "springboot-auth-module-skill" agent skill from https://github.com/jiushiwon/wg-skills/tree/main/vibeCoding/backend/java/springboot-module/springboot-auth-module-skill into .gemini/skills/springboot-auth-module-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "springboot-auth-module-skill", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jiushiwon/wg-skills springboot-auth-module-skillInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jiushiwon/wg-skills --skill springboot-auth-module-skill -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jiushiwon/wg-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/vibeCoding/backend/java/springboot-module/springboot-auth-module-skill .github/skills/springboot-auth-module-skill && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "springboot-auth-module-skill" agent skill from https://github.com/jiushiwon/wg-skills/tree/main/vibeCoding/backend/java/springboot-module/springboot-auth-module-skill into .github/skills/springboot-auth-module-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "springboot-auth-module-skill", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jiushiwon/wg-skills --skill springboot-auth-module-skill -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jiushiwon/wg-skills springboot-auth-module-skill --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jiushiwon/wg-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/vibeCoding/backend/java/springboot-module/springboot-auth-module-skill .opencode/skills/springboot-auth-module-skill && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "springboot-auth-module-skill" agent skill from https://github.com/jiushiwon/wg-skills/tree/main/vibeCoding/backend/java/springboot-module/springboot-auth-module-skill into .opencode/skills/springboot-auth-module-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "springboot-auth-module-skill", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
springboot-auth-module-skillSpring Boot 授权与企业组织架构模块一键叠加技能,组织权限领域的唯一权威技能。面向已使用 springboot-init-skill 生成的项目,标准化落地 RBAC、方法级鉴权、角色-菜单绑定、组织架构、岗位/租户、四级数据权限、个人鉴权与菜单回填接口。触发词:"Spring 授权模块","Spring Boot 权限模块","RBAC…
Springboot Auth Module Skill is an agent skill from jiushiwon/wg-skills. Spring Boot 授权与企业组织架构模块一键叠加技能,组织权限领域的唯一权威技能。面向已使用 springboot-init-skill 生成的项目,标准化落地 RBAC、方法级鉴权、角色-菜单绑定、组织架构、岗位/租户、四级数据权限、个人鉴权与菜单回填接口。触发词:"Spring 授权模块","Spring Boot 权限模块","RBAC 模块","角色菜单权限","企业组织架构","组织架构","部门管理","角色权限","菜单管理","数据权限","springboot-auth-module","添加权限模块","帮我加一个 Spring 鉴权模块"。
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `README.md`, `api-contract-auth.md` and `references/skeleton.md`).
It sits in Backend & APIs, covering Authorization and RBAC and Backend development. It works with Spring Boot. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit a4a640b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are java and sql).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Springboot Auth Module Skill loads about 2.7k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 80 tokens; SKILL.md has 534 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jiushiwon/wg-skills at commit a4a640b, republished under its Apache-2.0 licence (© jiushiwon). 534 words, ~2,661 tokens.
.claude/skills/springboot-auth-module-skill/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.为 Spring Boot 项目叠加一套企业级授权与组织架构能力,不是重新生成新项目。
⚠️ 唯一权威声明
组织架构 / 部门管理 / 角色权限 / RBAC / 菜单管理 / 数据权限 六类需求,本技能是唯一权威。
springboot-org-permission-module-skill已废弃并转发至本技能(历史上两个技能的表名、枚举、字段全部冲突,导致同一需求生成结果不可预测)。 不要再从其他技能生成组织权限代码。
springboot-init-skill / springboot-skill 骨架上,添加可运行且可鉴权的 RBAC + 组织架构模块。springboot-init-skill 已经提供的 JWT、统一响应、Swagger 等基础设施。1. 现有项目的 Spring 包名是什么?(默认从 springboot-init-skill 推断,如 com.koala.myapp)
2. 表前缀是什么?(默认 wg)
3. 是否需要数据权限(全部 / 本部门 / 本部门及以下 / 仅本人)?(默认 4 档全开)| # | 能力 | 说明 |
|---|---|---|
| 1 | 租户(Tenant) | 多租户数据隔离,支持独立组织架构 |
| 2 | 组织架构(Org) | 单表树形部门,parent_id 递归 + parent_ids 路径列 |
| 3 | 岗位(Post) | 用户可绑定一个或多个岗位 |
| 4 | 用户(SysUser) | 扩展基础 User,关联租户、部门、岗位、角色 |
| 5 | 角色(Role) | RBAC 核心,支持四级数据权限范围 |
| 6 | 菜单/权限(Menu) | 树形菜单 + 权限标识(permission),用于前端路由与按钮级鉴权 |
| 7 | 角色-菜单绑定 | 多对多,控制角色可见菜单与接口权限 |
| 8 | 用户-角色绑定 | 多对多,一个用户可拥有多个角色 |
| 9 | 方法级鉴权 | @EnableMethodSecurity + @PreAuthorize("hasAuthority('...')"),每个受控端点必须显式声明 |
| 10 | 数据权限 | 四级:全部 / 本部门 / 本部门及以下 / 仅本人,必须可作用于任意业务表 |
| 11 | 个人鉴权 | 登录 / 登出 / 修改密码 / 当前用户详情 / 获取菜单树 |
| 12 | 回填接口 | 角色菜单、用户角色、用户岗位的回填查询接口 |
| 13 | 接口契约 | 生成 api-contract-auth.md,与前端对齐 |
src/main/java/{{basePackage}}/auth/
├── common/
│ ├── AuthConstants.java # 权限常量(避免魔法字符串)
│ └── DataScope.java # 数据权限枚举(4 档,见下)
├── controller/
│ ├── AuthController.java # 登录 / 登出 / 当前用户 / 菜单树 / 改密
│ ├── UserController.java # 用户 CRUD + 绑定角色/岗位(含回填)
│ ├── RoleController.java # 角色 CRUD + 绑定菜单(含回填)
│ ├── MenuController.java # 菜单树 CRUD
│ ├── OrgController.java # 组织架构树 CRUD
│ ├── PostController.java # 岗位 CRUD
│ └── TenantController.java # 租户 CRUD
├── dto/ # 请求/响应 DTO(禁止实体直出)
├── entity/ # 实体
├── repository/ # Spring Data JPA
├── service/ # 业务逻辑
└── permission/
├── AuthorityLoader.java # 按 userId 装载权限标识 + 角色码
├── PermissionEvaluator.java # 数据权限档位解析
└── DataScopeFilter.java # 数据权限过滤 Specification
src/main/resources/db/migration/
├── V10__init_auth_module.sql # 授权模块表结构(含 parent_ids)
api-contract-auth.md # 接口契约
docs/auth-module-guide.md # 接入与扩展指南{prefix}_sys_tenant 租户
{prefix}_sys_org 组织(单表树)
{prefix}_sys_post 岗位
{prefix}_sys_user 用户
{prefix}_sys_role 角色
{prefix}_sys_menu 菜单
{prefix}_sys_user_role 用户-角色
{prefix}_sys_user_post 用户-岗位
{prefix}_sys_role_menu 角色-菜单例外清单为空。 「用户表叫
{prefix}_user」是历史误用,已作废 —— 见红线 R1。
menu_type 取值(统一采用业界惯例 M/C/F):
| 值 | 含义 | 说明 |
|---|---|---|
M | 目录 | 只做分组,不对应页面组件,path 通常是 /system 这类前缀 |
C | 菜单 | 对应一个页面组件,可带 permission |
F | 按钮 | 不带路径,只承载 permission |
兼容:读取时
B视为F;写入时只允许M/C/F。 注意:M是目录、C是菜单。写成M=菜单 C=目录是错的(历史文档曾这样写,已纠正)。
三段式 模块:资源:动作,全小写,用短横线连接多词动作。
system:user:list system:user:create system:user:edit
system:user:delete system:user:reset-pwd system:user:assign-role
system:role:list system:role:assign-menu system:menu:list
system:org:list system:app:list account:bind:list
dashboard:home:view example:product:list规则:
user:list)或一段。system:user:list 与 GET /api/users 的 system:user:list 是同一条),避免"路由写 view、接口写 list"这类错位。router 的 meta.permission、前端 v-permission、后端 @PreAuthorize、DB {prefix}_sys_menu.permission 必须逐字一致(交付前做三方 diff,见下方自检)。@Configuration
@EnableMethodSecurity // ← 必须开启,否则 @PreAuthorize 静默失效
public class SecurityConfig { }// 每个受控端点必须显式声明;"仅 authenticated()" 视为未完成
@PreAuthorize("hasAuthority('system:user:list')")
@GetMapping
public ApiResponse<PageResponse<UserVO>> page(...) { }JWT 过滤器必须把真实权限装进 SecurityContext(只装 ROLE_USER 会导致全量 403):
var authorities = new ArrayList<GrantedAuthority>();
authorityLoader.roleCodes(userId).forEach(c -> authorities.add(new SimpleGrantedAuthority("ROLE_" + c)));
authorityLoader.permissions(userId).forEach(p -> authorities.add(new SimpleGrantedAuthority(p)));
var auth = new UsernamePasswordAuthenticationToken(userId, null, authorities);| 数据范围 | 含义 | 使用场景 |
|---|---|---|
ALL | 全部数据 | 超级管理员 |
DEPT_ONLY | 本部门数据 | 部门经理 |
DEPT_AND_BELOW | 本部门及以下子部门 | 区域负责人 |
SELF_ONLY | 仅本人数据 | 普通员工 |
多角色取最宽档位(ALL > DEPT_AND_BELOW > DEPT_ONLY > SELF_ONLY)。
历史版本只实现
ALL/SELF_ONLY两档并把其余档位静默折叠为SELF_ONLY—— 这是缺陷,不是简化。四档必须全部可达。
必须可作用于任意业务表:DataScopeFilter 提供通用入口,业务表只要有 creator_id / org_id 就能接入,禁止只对用户表生效。
references/skeleton.md 生成 auth/ 下全部源码(含方法级鉴权与四档数据权限的真实实现)与迁移文件。api-contract-auth.md 与 docs/auth-module-guide.md。V10__init_auth_module.sql 初始化表结构;User 实体,改名为 SysUser 并迁移到 {prefix}_sys_user;/api/auth/menus 获取当前用户菜单树。{ code, message, data },成功 code === 0;错误码沿用 springboot-init-skill 的负数表(-1001 校验 / -1002 未登录 / -1003 无权限 / -1004 不存在 / -1005 冲突 / -2000 系统)。accessToken / pageSize / menuType / dataScope / menuIds / createdAt)。POST /api/auth/login 返回 { accessToken, refreshToken, tokenType, expiresIn }。GET /api/auth/me 返回用户 + 角色 + 部门 + 岗位 + 权限。GET /api/auth/menus 返回当前用户可见的树形菜单。GET /api/roles/{id}/menus → List<Long>GET /api/users/{id}/roles → List<Long>GET /api/users/{id}/posts → List<Long>| 文档 | 位置 | 说明 |
|---|---|---|
| 接口契约 | api-contract-auth.md | 含登录、当前用户、菜单树、回填、CRUD 全量接口 |
| 接入指南 | docs/auth-module-guide.md | 表结构、权限码表、数据权限、与 springboot-init-skill 集成步骤 |
| # | 检查 | 判定 |
|---|---|---|
| 1 | grep -c "@PreAuthorize" 覆盖率 | 每个受控端点都有;0 命中 = 未完成 |
| 2 | @EnableMethodSecurity 是否开启 | 未开启 → @PreAuthorize 静默失效 |
| 3 | JWT 过滤器是否装配真实权限 | 只装 ROLE_USER = 未完成 |
| 4 | 表名是否全部 {prefix}_sys_* | 出现 {prefix}_user = 违反 R1 |
| 5 | DataScope 是否 4 档且均有可达分支 | 2 档 = 未完成 |
| 6 | 三方权限码 diff(DB ⟷ 路由 meta ⟷ v-permission ⟷ @PreAuthorize) | 必须零差集 |
| 7 | 是否有实体直接作为 @RequestBody / 响应体 | 有 = 违反 R5 |
| 8 | 回填接口是否交付 | 缺 → 前端"分配菜单/角色"会覆盖清空 |
| # | 红线 | 理由 |
|---|---|---|
| R1 | 表名全部 {prefix}_sys_*。禁止 {prefix}_user 特例 | 历史破例导致同一个库三种前缀 |
| R2 | 必须交付方法级鉴权:@EnableMethodSecurity + 每个受控端点的 @PreAuthorize + SecurityContext 装配真实权限。只写 anyRequest().authenticated() 视为未完成 | 否则任何登录用户可删用户/角色/菜单、重置他人密码 |
| R3 | 数据权限必须四级可达,且必须能作用于业务表;多角色取最宽档位 | 静默折叠档位 = 权限失效 |
| R4 | 管理类端点禁止 permitAll。只有 /api/auth/login、/api/health、Swagger 可放行 | 绑定/应用管理类接口 extern 放行会泄露 |
| R5 | 禁止实体直接作为入参/出参,一律 DTO | 防止 mass assignment(可注入 appSecret/ownerId/createTime) |
| R6 | 权限码三段式,且 page 与 list 同码;按钮码不复用为路由码 | 防止"路由写 view、接口写 list"错位 |
| R7 | menu_type 只允许 M(目录) / C(菜单) / F(按钮) | 与业界惯例一致,避免跨项目迁移出错 |
| R8 | 所有删除为软删除(deleted_at) | 统一审计口径 |
| R9 | 菜单树使用 parent_id + sort_order,禁止嵌套集合 | 便于任意层级扩展 |
| R10 | 必须交付三个回填接口 | 缺一个,对应分配功能就会覆盖清空 |
| R11 | 所有注释、文档用中文 | 目标用户是中文开发者 |
| R12 | 不重复生成 Spring Boot 基础骨架 | 职责边界 |
| R13 | 菜单 menu_type=C 必须同时有 path 与 component;menu_type=F 必须有三段式 permission(^[a-z][a-z0-9_]*:[a-z][a-z0-9_]*:[a-z][a-z0-9_-]+$) | 「按钮没码」= 永远没权;「菜单没路径」= 前端 404 |
| R14 | menu_type=C 的 path 全树不能重复(含自己排除、软删除项排除) | 同一 path 挂两个菜单 → 路由跳转随机 |
| R15 | 菜单管理 UI 必须能从前端路由表回填 path/component/name/permission(推荐 <base-select> 直接读 router.options.routes) | 防止「DB 菜单」与「router 静态路由」双源漂移 |
用户可绑多个角色,所有「可见菜单 / 按钮权限」都来自这些角色的并集。 三层防线保证不重复、不遗漏、且对前端透明:
┌──────────────────────────────────────────────────────────┐
│ 用户 → 多个角色 → 多个 wg_sys_role_menu │
└──────────────────────────────────────────────────────────┘
│
┌───────────────────┼───────────────────┐
▼ ▼ ▼
① 菜单 ID 去重 ② 权限码去重 ③ 树形拼装去重
JPA findAllById AuthService.me() buildMenuTree()
按主键 IN 去重 Set→List.toList() byId Map 不重复挂载
│ │ │
▼ ▼ ▼
GET /api/auth/menus GET /api/auth/me 渲染 sidebar 自动无重复SysRoleMenuRepository.findMenuIdsByUserId:不主动去重(IN 子查询本身就只返回一份主键,外层 findAllById 再去一次)findPermissionsByUserId:AuthService.me() 里 new HashSet<>(...) 显式去重后再 new ArrayList<>(...) 返回buildMenuTree:Map<Long, MenuNode> 按 id 索引,重复 id 不会重复挂到 parent.childrenpermissions 已是去重 List,直接 permissions.value = info.permissions 覆盖,不做合并也就不会重复<base-card> + <AdminSidebar> 接收 MenuNode[],按 id 渲染,重复 id 不会重复出现校验(自动化测试不写,但必须能跑通的):
-- 用户 admin 同时绑定了 super_admin(id=1)和 user_admin(id=2)
-- 其中 super_admin 拥有所有 45 条菜单,user_admin 拥有 41 条(不含应用管理 36..40)
-- 期望:admin 看到 45 条(不是 86 条去重 → 仍 45),common_user 看到 6 条
SELECT COUNT(DISTINCT m.id)
FROM wg_sys_menu m
JOIN wg_sys_role_menu rm ON m.id = rm.menu_id
JOIN wg_sys_user_role ur ON ur.role_id = rm.role_id
WHERE ur.user_id = 1 AND m.deleted_at IS NULL;fastapi-auth-module-skill 保持 API 字段完全一致,方便前后端跨语言复用。【考拉搞AI】,带你全面进入 VibeCoding 的世界~
Spring 授权模块、Spring Boot 权限模块、RBAC 模块、角色菜单权限、
企业组织架构、组织架构、部门管理、角色权限、菜单管理、数据权限、
springboot-auth-module、添加权限模块、帮我加一个 Spring 鉴权模块© jiushiwon, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in vibeCoding/backend/java/springboot-module/springboot-auth-module-skill of jiushiwon/wg-skills.
Open the folder on GitHubat commit a4a640b
Springboot Auth Module Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Springboot Auth Module Skill this skilljiushiwon/wg-skills | 110 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Springboot Securityaffaan-m/ECC | 274k | 5 repos | ~2k | Automated safety check: Pass | MIT | |
| Spring Boot Security JWTgiuseppe-trisciuoglio/developer-kit | 355 | — | ~3.9k | Automated safety check: Notes | MIT | |
| Multi Tenancyrrezartprebreza/spring-boot-skills | 296 | — | ~576 | Automated safety check: Pass | MIT | |
| Multi Tenancyrrezartprebreza/spring-boot-skills | 296 | — | ~632 | Automated safety check: Pass | MIT | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT |
affaan-m/ECC
Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
giuseppe-trisciuoglio/developer-kit
Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…
rrezartprebreza/spring-boot-skills
A skill your agent uses when implementing tenant resolution, database or schema isolation, tenant-aware JPA, reactive tenant context, migrations, caching, jobs, or authorization in Spring Boot 3.
rrezartprebreza/spring-boot-skills
A skill your agent uses when implementing tenant resolution, database or schema isolation, Hibernate 7 tenancy, reactive tenant context, migrations, caches, jobs, or authorization in Spring Boot 4.
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
piomin/claude-ai-spring-boot
Spring Boot 3.x development - REST APIs, JPA, Security, Testing, and Cloud-native patterns.
jiushiwon/wg-skills
A skill your agent uses when generating UI for a specific scenario (mobile/PC/官网/管理端/营销页/文档/金融/原生/3D), when refactoring an existing HTML/Vue/React project to a unified design system, when extracting…
jiushiwon/wg-skills
A skill your agent uses when 用户想用一句话生成流程图、工作流图解、开发流程图、AI 流程图或任何步骤型图解,支持多风格输出(flat icon / 暖白手账风 / dark / cute),并提供现成模板一键出图。
jiushiwon/wg-skills
This skill should be used when the user wants to create a standardized uni-app project for WeChat mini-program, H5, and App from scratch.
jiushiwon/wg-skills
FastAPI 项目一键初始化技能。面向零基础小白,提供环境探测、自动安装、完整 Web 骨架生成、SSE 流式框架、JWT 鉴权、统一响应封装、文件上传接口、一键启动/重启脚本、Swagger 文档,内置 MySQL(默认)/ PostgreSQL / MongoDB 数据库选择。用户只需说"帮我搭一个 FastAPI 项目"即可一条命令完成从零到跑的完整链路。触发词:"FastAPI…
jiushiwon/wg-skills
FFmpeg 多媒体处理技能 — 将自然语言描述转为正确的 ffmpeg 命令,覆盖视频剪辑、转码、水印、合成、提取、生成等操作。内置一键安装脚本(Windows/Mac/Linux)。触发词:ffmpeg、视频剪辑、视频裁剪、视频转码、视频压缩、去水印、加水印、视频拼接、视频合成、提取音频、视频转…
jiushiwon/wg-skills
A skill your agent uses when designing or reviewing the request layer of a frontend project (web / uni-app / mini-program), including request.ts wrappers, interceptors, deduplication, mocks, error…
Works with
Categories
Spring Boot 授权与企业组织架构模块一键叠加技能,组织权限领域的唯一权威技能。面向已使用 springboot-init-skill 生成的项目,标准化落地 RBAC、方法级鉴权、角色-菜单绑定、组织架构、岗位/租户、四级数据权限、个人鉴权与菜单回填接口。触发词:"Spring 授权模块","Spring Boot 权限模块","RBAC…. Springboot Auth Module Skill is an agent skill from jiushiwon/wg-skills.
Springboot Auth Module Skill fits situations like: tasks that involve Authorization and RBAC; tasks that involve Backend development.
Run `npx skills add jiushiwon/wg-skills --skill springboot-auth-module-skill -a claude-code`. Or copy the skill folder (vibeCoding/backend/java/springboot-module/springboot-auth-module-skill in jiushiwon/wg-skills) into .claude/skills/springboot-auth-module-skill in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jiushiwon/wg-skills --skill springboot-auth-module-skill -a codex`. Or copy the skill folder (vibeCoding/backend/java/springboot-module/springboot-auth-module-skill in jiushiwon/wg-skills) into .agents/skills/springboot-auth-module-skill in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jiushiwon/wg-skills --skill springboot-auth-module-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/springboot-auth-module-skill, .gemini/skills/springboot-auth-module-skill, .github/skills/springboot-auth-module-skill and .opencode/skills/springboot-auth-module-skill in your project.
SKILL.md names no scripts, command-line tools or credentials: Springboot Auth Module Skill is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Springboot Auth Module Skill is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Springboot Auth Module Skill: Springboot Security (affaan-m/ECC, 274k stars), Spring Boot Security JWT (giuseppe-trisciuoglio/developer-kit, 355 stars), Multi Tenancy (rrezartprebreza/spring-boot-skills, 296 stars) and Multi Tenancy (rrezartprebreza/spring-boot-skills, 296 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jiushiwon (a GitHub user) maintains it in jiushiwon/wg-skills, which has 110 GitHub stars. The repository holds 121 skills in this directory. The repository was last updated on October 4, 2026.
Source: jiushiwon/wg-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.