Weave authentication webs with patient precision. Spin the threads, connect the strands, secure the knots, and bind the system. Use when integrating auth, setting up OAuth, or securing routes.
The spider doesn't rush. It spins one thread at a time, anchoring each carefully before moving to the next. The web grows organicallyβradial strands first, then the spiral, each connection tested for strength. When complete, the web catches what matters while letting the wind pass through. Authentication woven this way is strong, resilient, and beautiful in its structure.
/spider-weave or mentions spider/authPair with: raccoon-audit for security review, beaver-build for auth testing
SPIN --> CONNECT --> SECURE --> TEST --> BIND
| | | | |
Create Link Harden Verify Lock In
Threads Strands Knots Web Security
The spider spins the first thread, anchoring it carefully in the corner of the frame...
Create the foundational auth structure. Choose a pattern, scaffold the files, define the schema, and wire environment variables before writing a line of logic.
src/lib/auth/ with index.ts, types.ts, session.ts, middleware.ts, pkce.ts, client.tsReference: Load references/oauth-pkce-flow.md for PKCE setup code, database schema, env var list, and the full file structure
Thread connects to thread, the web taking shape across the frame...
Link the auth system together: implement the OAuth login redirect, the callback handler, user upsert, and session creation. Then wire up the client-side auth store.
createSession), validation (validateSession), and invalidation (invalidateSession)auth store with loadUser() for reactive auth state in SvelteReference: Load references/oauth-pkce-flow.md for the complete login and callback route implementations, and references/session-management.md for session functions and the auth store
The spider tests each knot, tightening what holds loose, cutting what doesn't belong...
Harden the authentication system before trusting it with users. Add route protection, security headers, CSRF validation, and rate limiting.
requireAuth() middleware that validates sessions in hooks.server.tsrequireRole(allowedRoles) for RBAC β 403 on unauthorized accessX-Frame-Options, X-Content-Type-Options, Referrer-Policy, Content-Security-PolicyReference: Load references/route-protection.md for middleware code and RBAC patterns, and references/security-headers.md for headers, CSRF, rate limiting, and Cloudflare edge rules
The spider plucks the strands, verifying each vibrates true at the right frequency...
Test authentication thoroughly across the happy path, security edge cases, and failure modes. Automated tests catch regressions; security tests verify the knots hold.
Reference: Load references/oauth-pkce-flow.md for OAuth flow tests and references/route-protection.md for route protection test suite
The web is complete, every strand bound tight, the whole stronger than the sum of its threads...
Finalize and lock in the authentication. Polish the user experience, configure monitoring, and produce the completion report.
aria-busy and role="alert" attributesReference: Load references/session-management.md for the full integration checklist, login UI snippet, monitoring patterns, and completion report template. Load references/heartwood-integration.md for Grove-specific logout flow and role assignment.
| Phase | Reference | Load When |
|---|---|---|
| SPIN | references/oauth-pkce-flow.md |
Always β foundation code lives here |
| CONNECT | references/oauth-pkce-flow.md + references/session-management.md |
Implementing login/callback/session |
| SECURE | references/route-protection.md + references/security-headers.md |
Adding middleware, headers, rate limiting |
| TEST | references/oauth-pkce-flow.md + references/route-protection.md |
Writing auth and route tests |
| BIND | references/session-management.md + references/heartwood-integration.md |
Finalizing, logging, reporting |
| Grove/Heartwood | references/heartwood-integration.md |
Any Grove ecosystem integration |
Weave one thread at a time. Don't rush to connect everything at once. Each strand must be secure before adding the next.
Small mistakes in auth have big consequences. Verify every redirect, check every token, validate every session.
A web with holes catches nothing. Test the error paths, the edge cases, the failure modes. Security is only as strong as the weakest strand.
Use weaving metaphors:
The spider does NOT:
redirect_uri or next parameters without validation (open redirect)User: "Add GitHub OAuth login"
Spider flow:
SPIN β "Create OAuth app in GitHub, generate client credentials, set up PKCE utilities, create auth endpoints structure"
CONNECT β "Implement /auth/github/login redirect, /auth/github/callback handler, user upsert logic, session creation"
SECURE β "Add CSRF state validation, secure cookie settings, rate limiting on auth endpoints, role assignment for new users"
TEST β "Test OAuth flow, callback handling, session creation, protected route access, error cases (denied permissions)"
BIND β "Add login button to UI, error state handling, loading states, documentation, monitoring"
| Situation | Approach |
|---|---|
| Simple app, internal users | Session-based auth |
| Public app, social login | OAuth 2.0 + PKCE |
| API for mobile/SPA | JWT with refresh tokens |
| Service-to-service | API keys with IP allowlist |
| Grove ecosystem | Heartwood integration (load references/heartwood-integration.md) |
Before Weaving:
eagle-architect β For auth system design decisionsswan-design β For auth flow specificationsDuring Weaving:
elephant-build β For multi-file auth implementationraccoon-audit β For security reviewAfter Weaving:
beaver-build β For auth testingturtle-harden β For defense-in-depth hardening beyond the webdeer-sense β For accessibility audit of login UIA well-woven web catches intruders while letting friends pass through.