AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

New Middleware

skill-zuoyebang-aiweave-new-middleware · by zuoyebang

根据 middleware.md 生成 Gin 认证中间件。

No reviews yet
0 installs
45 views
0.0% view→install

Install

$ agentstack add skill-zuoyebang-aiweave-new-middleware

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-zuoyebang-aiweave-new-middleware)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
3mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of New Middleware? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

根据 $ARGUMENTS 生成认证中间件。

> 公共步骤模板见 [skills-spec/01skillauthoring_guide.md](path) §A-§E。本 Skill 特定内容如下。

第 0 步:拒绝规则与依赖前置

  • ⛔ 拒绝(§A.1):N/A(中间件通常不触发暂不实现模块)
  • 状态检查(§A.2):读 BUILD_STATUS.md §2 中 middleware 行
  • 依赖(§A.3):依赖的 helpers / Redis Key / 配置项必须就绪

第 1 步:读取设计文档(公共必读见 §B)

  • 主文档:docs/architecture/middleware.md 对应中间件规格
  • 额外必读:
  • docs/architecture/routing.md §1 中间件链
  • 签名类中间件 → docs/architecture/{核心校验链}_flow.md §1 签名算法
  • docs/architecture/render_functions.md(错误响应格式)

第 2 步:识别中间件类型

| 类型 | 关键逻辑 | |------|---------| | 内网 IP 白名单 | 检查 ctx.ClientIP() 是否属于内网段 | | 签名校验 | MD5 / HMAC + 时间窗口校验 | | 角色权限 | 提取 X-{Actor}-Role + 接口权限矩阵 |

第 3 步:生成中间件文件

文件路径:middleware/{name}.go

package middleware

import (
    "{project}/components"
    "{project}/helpers"
    "{project}/pkg/gin"
    "{project}/pkg/golib/v2/tlog"
)

func {Name}() gin.HandlerFunc {
    return func(ctx *gin.Context) {
        // 1. {步骤 1}
        // 2. {步骤 2}
        // ...
        // N. ctx.Set("{key}", {value})
        ctx.Next()
    }
}

错误响应处理(关键)

  • 与外部协议对齐的路由组(Internal)→ ctx.AbortWithStatusJSON(200, gin.H{"status":...,"message":...,"data":nil})
  • 标准内部路由组(UserSelf/Admin)→ base.RenderJsonAbort(ctx, components.ErrorXxx)
  • 不要混用!

第 4 步:文档同步(公共项见 §C)

  • 确认 middleware.md 规格与实现一致
  • 确认 routing.md §1 中间件链描述一致
  • 更新 BUILD_STATUS 状态

第 5 步:测试同步(4 类用例标准见 §D)

中间件本身不对应单接口测试,必须通过覆盖该路由组的下游接口测试间接覆盖:

| 中间件类型 | 测试覆盖 | |----------|---------| | 签名校验类 | test/cases/internal/{module}_{action}_test.go(含签名错误 / 时间过期 / 缺参数等) | | 调用方身份注入类 | test/cases/operator/common_test.go(IP 白名单 / {actor-id} 注入) | | 角色权限校验类 | test/cases/admin/common_test.go(多角色权限矩阵) |

第 6 步:验证(公共格式见 §E)

go build ./middleware/...
go vet ./middleware/...
cd test && go test -v ./cases/{scope}/...

> 🧩 AIWeave 骨架 · 作者 XuRuibo · Apache-2.0 · 模板文件,复制到工程后按业务语义填充

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.