Sa-Token Development Assistant
Paste the following prompt into your AI chat to install this skill:
Follow https://skillhub.cn/install/skillhub.md to install @user_a36dc51e/sa-token-dev
About this skill
Problems it addresses
Sa-Token issues often come from choosing the wrong architecture path, not from missing API knowledge. A project may fail to start when both sa-token-spring-boot-starter and sa-token-reactor-spring-boot-starter are included. Annotations like @SaCheckPermission may stay inactive without SaInterceptor. Front-end/back-end separation can break if tokenValue is not returned. Spring Boot 3.x may fail on Redis config when the old spring.redis prefix is used. Banned accounts may remain online if kickout is skipped. JWT is often assumed by default even when Sa-Token only needs simple-uuid plus Redis.
How the skill works
It starts with dependency discovery: search pom.xml or build.gradle for sa-token, spring-security, and shiro. If Sa-Token exists, the skill activates. If no auth framework exists, it asks whether to introduce Sa-Token. If Spring Security or Shiro is already present, it steps out. Then it scans C1-C6 trigger signals such as JWT, stateless, SSO, login, permission, microservice, and multi-account. When triggered, it outputs a choice list rather than code, confirming token style, Cookie/Header flow, authorization granularity, SSO mode, gateway statefulness, and multi-system strategy. After the user confirms, it uses the decision route to read local references/ files such as 01-setup.md, 03-permission.md, 05-interceptor-route.md, 07-redis-frontsep.md, 12-sso-oauth2.md, and 13-micro-service.md. Before coding, it checks 10-antipattern.md and core constraints, then performs a binary pre-output checklist for SaInterceptor, Redis prefix, setError(), and checkDisable().
Scope and caveats
It targets Java/Spring Boot projects, recommends 1.46.0+, and supports 1.40.x+. It does not target Go, Python, Node.js, pure custom JWT, or migration from Spring Security/Shiro. SaSession is not HttpSession; StpInterface is required for permission and role checks; backends must revalidate permissions; filter exceptions need .setError(). JWT is not the default: use simple-uuid plus Redis for stateful flows, and StpLogicJwtForStateless only for stateless needs. When upgrading to 1.46.0, check StpInterface.isDisabled three-parameter changes, loginId colon restrictions, and JWT extraData reserved fields. Avoid Hutool 5.8.13/5.8.14 with sa-token-jwt.
Use Cases
- Debug inactive Sa-Token annotations in Spring Boot and add interceptor registration plus whitelist rules.
- Design login tokenValue return, satoken header flow, and shared Redis sessions for front-end/back-end separation.
- Configure unified gateway authorization for microservices with Reactor starter, Same-Token, or internal isolation.
- Plan multi-client login systems with StpKit, independent timeouts, kickout/ban, and secondary auth.
Best For
- Java engineers maintaining Spring Boot login, authorization, and session behavior.
- Architects configuring unified gateway authorization and internal service isolation for microservices.
- Tech leads implementing SSO, OAuth2, multi-client login, or secondary authentication.
- Backend developers debugging Sa-Token annotation, Redis prefix, and account ban issues.
Related Skills
Automatically indexes Gradle-cached AAR/JAR dependency classes and returns library coordinates, versions, and public APIs by fully qualified name, using only the Python standard library.
Codifies AMT and YourMT3 training conventions, script patterns, hyperparameters, precision, checkpoints, and NaN safeguards.
Retrieve relevant chunks from a customer-managed PKM dataset by dataset_id and return concise, source-annotated answers.
Convert PRDs, user stories, or functional specs into prioritized test-point checklists covering functional, business-rule, boundary, exception, and non-functional dimensions.