auth-store-debug

โดย vercel

Auth and store debugging for vercel-openclaw: admin-secret mode, Sign in with Vercel, session cookies, CSRF, LOCAL_READ_ONLY, Redis vs memory store, keyspace…

npx skills add https://github.com/vercel-labs/vercel-openclaw --skill auth-store-debug

Auth Store Debug

Use this skill when request authorization, session behavior, store persistence, or metadata shape is the likely problem.

Evidence First

Collect:

  • Auth mode and Vercel/local environment from admin/preflight surfaces.
  • Request method, route, status, and whether bearer or cookie auth was used.
  • GET /api/admin/logs filtered for auth., store., session., preflight..
  • Store backend reported by deployment contract.
  • Sanitized metadata shape when needed. Never print secrets, session keys, Redis URLs, or cookies.

Critical Splits

  • Deployment Protection auth vs app auth.
  • Bearer admin-secret auth vs encrypted session cookie auth.
  • CSRF applies to cookie-based mutations, not bearer mutations.
  • LOCAL_READ_ONLY=1 intentionally blocks admin mutations locally.
  • Redis connects only on deployed Vercel runtimes; local/CI use memory store even if Redis envs exist.
  • OPENCLAW_INSTANCE_ID changes namespace and does not migrate old state.

Fix Boundaries

  • Auth: src/server/auth/{admin-auth,admin-secret,session,vercel-auth,route-auth}.ts.
  • Store: src/server/store/{store,redis-store,memory-store,keyspace}.ts, src/shared/types.ts.
  • Routes: only the affected route handler.
  • Docs/env contract: .env.example, README.md, CONTRIBUTING.md, CLAUDE.md.

Verification

node scripts/verify.mjs --steps=test,typecheck
pnpm check:verify-contract
lat check

Run pnpm check:verify-contract when env vars, auth mode docs, or operator instructions change.

Skills เพิ่มเติมจาก vercel

benchmark-sandbox
vercel
เรียกใช้สถานการณ์ประเมินผลของ vercel-plugin ใน Vercel Sandboxes แทนแผง WezTerm ในเครื่อง จัดเตรียม microVM ชั่วคราวที่ติดตั้ง Claude Code และปลั๊กอินไว้ล่วงหน้า…
official
emil-design-eng
vercel
ทักษะนี้เข้ารหัสปรัชญาของ Emil Kowalski เกี่ยวกับการตกแต่ง UI การออกแบบคอมโพเนนต์ การตัดสินใจเรื่องแอนิเมชัน และรายละเอียดที่มองไม่เห็นซึ่งทำให้ซอฟต์แวร์รู้สึกดี
official
vercel-react-best-practices
vercel
แนวทางปฏิบัติที่ดีที่สุดในการเพิ่มประสิทธิภาพ React และ Next.js จากทีมวิศวกรรมของ Vercel ควรใช้ทักษะนี้เมื่อเขียน ตรวจสอบ หรือปรับโครงสร้างโค้ด React/Next.js…
official
vercel-react-best-practices
vercel
แนวทางปฏิบัติที่ดีที่สุดในการเพิ่มประสิทธิภาพ React และ Next.js จากทีมวิศวกรรมของ Vercel ควรใช้ทักษะนี้เมื่อเขียน ตรวจสอบ หรือปรับโครงสร้าง React/Next.js…
official
write-guide
vercel
ผลิตคู่มือทางเทคนิคที่สอนกรณีการใช้งานในโลกจริงผ่านตัวอย่างแบบค่อยเป็นค่อยไป แนวคิดจะถูกนำเสนอเมื่อผู้อ่านต้องการเท่านั้น
official
release
vercel
ปลั๊กอิน Vercel สำหรับการปล่อย — รัน gates, เพิ่มเวอร์ชัน, สร้าง artifacts, คอมมิต และพุช ใช้เมื่อถูกขอให้ "release", "ship", "bump and push" หรือ "cut a release
official
deepsec
vercel
รัน DeepSec กับโปรเจกต์ Vercel ที่เช็คเอาท์จาก dev3000 ใช้สำหรับการตั้งค่า DeepSec แบบคลิกเดียว การบูตสแตรปบริบทโปรเจกต์ การประมวลผลรอบแรกแบบมีขอบเขต และ…
official
backport-pr
vercel
ย้อนกลับ pull request ของ Next.js ที่รวมแล้วจาก canary ไปยังสาขารุ่นก่อนหน้า เช่น next-16-2 ใช้เมื่อผู้ใช้ขอให้ย้อนกลับ, cherry-pick, หรือเปิด...
official