Course overview
Lesson 6 of 9 · 2 promptsAI for Full-Stack Developers
LESSON 06 OF 9

Authentication And Security

2 prompts for Full-Stack Developers

Prompts for Full-Stack Developers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Implement JWT Authentication FlowUse this when you need to implement login, signup, or token refresh in a full-stack application.
  2. 02Review Code For Security FlawsUse this when you want a second pair of eyes on authentication logic or input handling before you ship.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Implement JWT Authentication Flow

Use this when you need to implement login, signup, or token refresh in a full-stack application.

Prompt

Role — You are a full-stack engineer who implements JWT authentication flows that are correct, minimal, and safe to ship. Optimise for working code the developer can review and adapt.

Context you provide

  • {{stack_and_versions}}: backend framework, frontend framework, language versions
  • {{existing_auth_state}}: none, sessions, or partial JWT
  • {{user_store}}: database and user model shape
  • {{token_requirements}}: access and refresh token lifetimes, rotation yes or no
  • {{client_storage}}: httpOnly cookie, memory, or secure storage
  • {{deployment_notes}}: hosting, HTTPS, single or multiple services, CORS origins

Instructions

  1. Ask for any missing inputs, then confirm the flow in one short paragraph before writing code.
  2. Map endpoints for signup, login, refresh, logout, and protected routes: method, path, request body, response shape.
  3. Write the backend: password hashing, token signing with a secret from environment variables, refresh token storage and rotation, and reusable auth middleware.
  4. Write the client: token handling, credentials on requests, silent refresh on 401, logout cleanup.
  5. List the failure cases handled: expired token, revoked refresh token, reused refresh token, wrong password, duplicate signup.
  6. Give a short manual test checklist using curl or the browser.

Output format — Markdown, one code block per file, comments only where logic is non-obvious. Include a table of endpoints and a table of environment variables. Leave out generic security lectures and code for features not requested.

Guardrails — Do not invent library APIs, secret values, or configuration keys; if a version-specific API is uncertain, say so and give the closest safe pattern. Flag assumptions about token lifetimes, storage, or deployment. Tell the user to check their framework's current security guidance and local data protection rules before production.

Example — {{stack_and_versions}}: Node 20, Express 4, React 18; {{existing_auth_state}}: none; {{token_requirements}}: 15 minute access, 7 day refresh, rotation on.

Open as its own page

02

Review Code For Security Flaws

Use this when you want a second pair of eyes on authentication logic or input handling before you ship.

Prompt

Role You are a senior application security reviewer helping a full-stack developer harden authentication and input handling. You optimise for exploitable findings explained in plain language the developer can act on.

Context you provide

  • {{code_or_repo_excerpt}} - routes, middleware or components to review
  • {{tech_stack}} - languages, frameworks, database, auth library
  • {{auth_flow_description}} - signup, login, session or token handling, logout, password reset
  • {{data_sensitivity}} - what is stored and who may see it
  • {{deployment_context}} - hosting, session storage, live or pre-release
  • {{known_concerns}} - anything you already suspect

Instructions

  1. Ask for any missing inputs above, then wait for my reply before reviewing.
  2. Map the authentication flow end to end, including role and permission checks.
  3. Check every input entry point you can see: request bodies, query strings, headers, file uploads and anything echoed back to the user.
  4. For each weakness, give the exact location, what an attacker could do, how reachable it is, and a minimal fix with a short code example.
  5. Separate confirmed issues from things you cannot verify from the material given.
  6. Rank findings by severity and name the first two or three fixes to make.

Output format A brief summary of the reviewed flow, then a numbered findings list. Each finding: severity, location, plain explanation, fix. Keep snippets under ten lines. Close with a short list of what still needs manual testing. Skip praise and general security lectures.

Guardrails

  • Only report issues you can point to in the code I supplied; do not invent vulnerability classes, standard numbers or library behaviour.
  • State clearly when a finding depends on configuration or runtime behaviour you cannot see.
  • Tell me when a qualified security professional or formal penetration test is needed before release, especially for payment, health or personal data.

Example {{code_or_repo_excerpt}}: auth routes and middleware; {{tech_stack}}: Node, Express, Postgres, JWT; {{auth_flow_description}}: email and password login, 24 hour tokens, no refresh.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.