CtrlK
BlogDocsLog inGet started
Tessl Logo

caddy-security

github.com/greenpau/caddy-security

SkillAddedReview
authentication-portal-api

.codex/skills/authentication-portal-api/SKILL.md

Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS. Use for HTTP contracts; portal Caddyfile wiring belongs to configuration-authentication.

72

break-fix-troubleshooting

.codex/skills/break-fix-troubleshooting/SKILL.md

Diagnose caddy-security deployment and runtime failures from configs, logs, versions, and HTTP evidence. Use for focused fixes, unresolved support handoffs, or preparing break-fix issue reports.

67

coding-directives

.codex/skills/coding-directives/SKILL.md

Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation. Use for app/plugin boundaries, authcrunch integration, errors, logging, and code conventions.

66

configuration

.codex/skills/configuration/SKILL.md

Build or review caddy-security Caddyfiles and select focused configuration skills. Use for security app declarations and authenticate/authorize route wiring.

64

configuration-authentication

.codex/skills/configuration-authentication/SKILL.md

Configure authentication portals, backend selection, redirect trust, refresh, and portal wiring. Delegates cookies, UI, transforms, crypto, and OIDC provider details to focused skills.

60

configuration-authentication-cookies

.codex/skills/configuration-authentication-cookies/SKILL.md

Configure portal cookie names, prefixes, domains, paths, attributes, and refresh overrides. Use for cookie precedence and coordination with authorization token discovery.

65

configuration-authentication-cross-device

.codex/skills/configuration-authentication-cross-device/SKILL.md

Configure and verify optional cross-device portal login, QR activation, explicit approval, browser binding, cancellation, and lifecycle through Caddy. Native login and external provider configuration retain their own owners.

64

configuration-authentication-ui

.codex/skills/configuration-authentication-ui/SKILL.md

Configure portal UI templates, static assets, themes, languages, links, and custom CSS/JS/HTML. Use for branding and refresh-aware templates; transform-generated links belong to user transforms.

62

configuration-authentication-user-transforms

.codex/skills/configuration-authentication-user-transforms/SKILL.md

Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules. Use for authentication-time policy; stored account rules belong to configuration-users.

66

configuration-authorization

.codex/skills/configuration-authorization/SKILL.md

Configure authorization policies, ACLs, bypasses, identity headers, JWT verification, remote Basic/API-key auth, and direct OAuth without a portal.

61

configuration-credentials

.codex/skills/configuration-credentials/SKILL.md

Configure reusable named username/password credentials for messaging consumers, including optional domains and runtime values. LDAP bind credentials belong to identity stores.

66

configuration-crypto

.codex/skills/configuration-crypto/SKILL.md

Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys. Use for signing/verification compatibility and rotation.

68

configuration-http-integrations

.codex/skills/configuration-http-integrations/SKILL.md

Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata. Use for path conflicts, split hosts, public JWKS, and route ordering.

68

configuration-identity-stores

.codex/skills/configuration-identity-stores/SKILL.md

Configure local or LDAP identity stores, realms, databases, binds, TLS trust, searches, and group mappings. Delegates static account entries to configuration-users.

65

configuration-logging

.codex/skills/configuration-logging/SKILL.md

Configure AuthCrunch diagnostic skip rules and explain the Caddy middleware logger boundary. Use for component/message filtering; access logs and authorization outcomes are separate concerns.

66

configuration-messaging

.codex/skills/configuration-messaging/SKILL.md

Configure email and file messaging providers, SMTP transport, sender/authentication, templates, and registration delivery wiring. Use to distinguish parsed settings from actual delivery behavior.

70

configuration-oauth-applications

.codex/skills/configuration-oauth-applications/SKILL.md

Register named OAuth clients, manage private registration storage, and configure portal OIDC providers. Owns security oauth/oidc provisioning commands; external login providers and security local are separate.

56

configuration-oauth-providers

.codex/skills/configuration-oauth-providers/SKILL.md

Configure external OAuth/OIDC login providers, credentials, scopes, issuer/audience trust, JWKS, PKCE, and portal enablement. Named relying-party registrations and portal OPs belong to OAuth applications.

63

configuration-registrations

.codex/skills/configuration-registrations/SKILL.md

Configure local user signup, domain/MX rules, terms, confirmation, dropbox storage, and messaging. Use for registration versus account activation; OAuth client registration is separate.

63

configuration-runtime-resolution

.codex/skills/configuration-runtime-resolution/SKILL.md

Configure and validate Caddy runtime placeholders, secret lookups, encoded instructions, and resolved fixtures. Use to determine which fields resolve and preserve exact values; manager blocks belong to secrets.

60