AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Cosec Integration

skill-ahoo-wang-skills-cosec-integration · by Ahoo-Wang

Use when adding CoSec to a Spring Boot application, choosing WebFlux/WebMVC/Gateway modules, configuring JWT authentication, authorization filters, local policies, Redis policy caching, social login, IP enrichment, OpenAPI, or OpenTelemetry integration.

No reviews yet
0 installs
28 views
0.0% view→install

Install

$ agentstack add skill-ahoo-wang-skills-cosec-integration

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-ahoo-wang-skills-cosec-integration)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Cosec Integration? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

CoSec Integration Guide

This skill guides you through integrating CoSec into a Spring Boot application. CoSec is a reactive, multi-tenant RBAC + Policy-based security framework built on Spring Boot and Project Reactor.

Step 1: Add Dependencies

CoSec modules are published to Maven Central under the me.ahoo.cosec group. Use the BOM for version management.

Gradle (Kotlin DSL)

// gradle/libs.versions.toml
[versions]
cosec = "4.3.6"  // check latest at https://central.sonatype.com/artifact/me.ahoo.cosec/cosec-bom

[libraries]
cosec-bom = { module = "me.ahoo.cosec:cosec-bom", version.ref = "cosec" }
cosec-spring-boot-starter = { module = "me.ahoo.cosec:cosec-spring-boot-starter" }
cosec-webflux = { module = "me.ahoo.cosec:cosec-webflux" }
cosec-webmvc = { module = "me.ahoo.cosec:cosec-webmvc" }
cosec-gateway = { module = "me.ahoo.cosec:cosec-gateway" }
cosec-jwt = { module = "me.ahoo.cosec:cosec-jwt" }
cosec-cocache = { module = "me.ahoo.cosec:cosec-cocache" }
cosec-social = { module = "me.ahoo.cosec:cosec-social" }
cosec-ip2region = { module = "me.ahoo.cosec:cosec-ip2region" }
cosec-opentelemetry = { module = "me.ahoo.cosec:cosec-opentelemetry" }
cosec-openapi = { module = "me.ahoo.cosec:cosec-openapi" }
// build.gradle.kts
dependencies {
    implementation(platform(libs.cosec.bom))
    implementation(libs.cosec.spring.boot.starter)
    implementation(libs.cosec.webflux)   // for WebFlux apps
    // implementation(libs.cosec.webmvc)  // for Servlet apps
    // implementation(libs.cosec.gateway) // for Spring Cloud Gateway
    implementation(libs.cosec.jwt)       // JWT token handling
    // implementation(libs.cosec.cocache) // Redis policy caching
}

Maven


    
        
            me.ahoo.cosec
            cosec-bom
            4.3.6
            pom
            import
        
    

    
        me.ahoo.cosec
        cosec-spring-boot-starter
    
    
        me.ahoo.cosec
        cosec-webflux
    
    
        me.ahoo.cosec
        cosec-jwt
    

Module Selection Guide

| Use Case | Required Modules | |----------|-----------------| | Basic WebFlux app | cosec-spring-boot-starter + cosec-webflux | | Servlet/WebMVC app | cosec-spring-boot-starter + cosec-webmvc | | API Gateway | cosec-spring-boot-starter + cosec-gateway | | JWT authentication | add cosec-jwt | | Redis policy caching | add cosec-cocache | | Social OAuth login | add cosec-social | | IP geolocation conditions | add cosec-ip2region | | Authorization tracing | add cosec-opentelemetry | | OpenAPI/Swagger integration | add cosec-openapi |

Step 2: Configure application.yaml

cosec:
  enabled: true                        # master switch (default: true)
  authentication:
    enabled: true                      # enable authentication
  authorization:
    enabled: true                      # enable authorization (default: true)
    local-policy:
      enabled: true                    # load policies from local JSON files
      locations: classpath:cosec-policy/*-policy.json
      init-repository: true            # push local policies to repository on startup
  jwt:
    algorithm: hmac256                 # hmac256, hmac384, hmac512, rsa256, etc.
    secret: your-256-bit-secret-key    # required for HMAC algorithms

Property Reference

| Property | Default | Description | |----------|---------|-------------| | cosec.enabled | true | Master enable/disable switch | | cosec.authentication.enabled | — | Enable/disable authentication | | cosec.authorization.enabled | true | Enable/disable authorization | | cosec.authorization.local-policy.enabled | false | Load policies from local JSON files | | cosec.authorization.local-policy.locations | classpath:cosec-policy/*-policy.json | Resource patterns for policy files | | cosec.authorization.local-policy.init-repository | false | Push local policies to repository on startup | | cosec.jwt.algorithm | — | JWT algorithm (hmac256, rsa256, etc.) | | cosec.jwt.secret | — | JWT secret key (for HMAC algorithms) | | cosec.ip2region.enabled | false | Enable IP geolocation | | cosec.openapi.enabled | false | Enable OpenAPI integration |

Step 3: Create Policy Files

Place policy JSON files in src/main/resources/cosec-policy/. Files must match the pattern *-policy.json.

Minimal Example — Public Health Endpoint

{
  "id": "(health-probe)",
  "name": "Health Probe",
  "type": "global",
  "tenantId": "(platform)",
  "statements": [
    {
      "name": "actuator",
      "action": [
        "/actuator/health",
        "/actuator/health/readiness",
        "/actuator/health/liveness"
      ]
    }
  ]
}

Typical Example — API with Auth

{
  "id": "api-policy",
  "name": "API Policy",
  "type": "global",
  "tenantId": "(platform)",
  "statements": [
    {
      "name": "PublicEndpoints",
      "action": ["/auth/login", "/auth/register"]
    },
    {
      "name": "AuthenticatedApi",
      "action": "/api/**",
      "condition": { "authenticated": {} }
    },
    {
      "name": "AdminEndpoints",
      "action": "/admin/**",
      "condition": { "inRole": { "value": "admin" } }
    }
  ]
}

See the cosec-policy-author skill for full policy JSON reference.

Step 4: Spring Boot Application

No special annotations or configuration classes needed. CoSec auto-configures everything based on classpath and properties.

@SpringBootApplication
class MyApp

fun main(args: Array) {
    runApplication(*args)
}

The auto-configuration automatically registers:

  • ReactiveAuthorizationFilter (WebFlux) or AuthorizationFilter (WebMVC) or AuthorizationGatewayFilter (Gateway)
  • SecurityContextParser for extracting security context from requests
  • SimpleAuthorization for policy evaluation
  • LocalPolicyLoader / LocalPolicyInitializer for loading local policy files
  • JWT token converter and verifier (if cosec-jwt is on classpath)
  • Request parsers for both reactive and servlet environments

Gateway Server Reference

The cosec-gateway-server module is a complete reference implementation. Key configuration:

# application.yaml
cosec:
  authentication:
    enabled: false          # Gateway relies on token injection from upstream
  jwt:
    algorithm: hmac256
    secret: FyN0Igd80Gas8stTavArGKOYnS9uLWGA_
  authorization:
    local-policy:
      enabled: true
      init-repository: true

Gateway-specific dependencies:

implementation(libs.cosec.cocache)        // Redis caching
implementation(libs.cosec.gateway)         // Gateway filter
implementation(libs.cosec.opentelemetry)   // Tracing
implementation(libs.cosec.ip2region)       // IP geolocation
implementation("org.springframework.cloud:spring-cloud-starter-gateway-server-webflux")

Disabling Features

Use conditional properties to disable specific features:

cosec:
  enabled: false              # disable everything
  authorization:
    enabled: false            # disable only authorization
  jwt:
    # not configuring jwt disables JWT auto-config
  ip2region:
    enabled: false

Each auto-configuration class has a corresponding @ConditionalOn*Enabled annotation that checks these properties.

Troubleshooting

  • 403 on all requests: Check that policy files exist and match the locations pattern. Enable debug logging: logging.level.me.ahoo.cosec.authorization.SimpleAuthorization=debug
  • JWT token not recognized: Verify cosec.jwt.secret and cosec.jwt.algorithm match what the token issuer uses
  • Policies not loading: Ensure cosec.authorization.local-policy.enabled=true and files are in the correct classpath location
  • Root user bypasses everything: This is by design. Root user ID defaults to "cosec" (configurable via cosec.root system property)

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.