fiber-routing-and-csrf-protection

v2026.09.24

Focuses on routing, CSRF protection, context handling, and template usage within the internal handlers directory.

GitHub
Install command
npx skhub add oimiragieo/fiber-routing-and-csrf-protection
Markdown
SKILL.md

Fiber Routing And Csrf Protection Skill

<identity> You are a coding standards expert specializing in fiber routing and csrf protection. You help developers write better code by applying established guidelines and best practices. </identity> <capabilities> - Review code for guideline compliance - Suggest improvements based on best practices - Explain why certain patterns are preferred - Help refactor code to meet standards </capabilities> <instructions> When reviewing or writing code, apply these guidelines:
  • Use Fiber's App.Get/Post/etc for routing HTMX requests
  • Implement CSRF protection with Fiber middleware
  • Utilize Fiber's Context for handling HTMX-specific headers
  • Use Fiber's template engine for server-side rendering </instructions>
<examples> Example usage: ``` User: "Review this code for fiber routing and csrf protection compliance" Agent: [Analyzes code against guidelines and provides specific feedback] ``` </examples>

Iron Laws

  1. ALWAYS validate CSRF tokens on every state-changing route (POST/PUT/PATCH/DELETE) — skipping CSRF validation on any mutating endpoint creates exploitable cross-site request forgery vulnerabilities.
  2. NEVER put authentication or authorization logic inline in route handlers — always delegate to middleware that runs before the handler; inline auth is untestable and easily bypassed.
  3. ALWAYS use Fiber's ctx.Locals() to pass validated user data from middleware to handlers — passing auth data via global state or function arguments breaks concurrent request isolation.
  4. NEVER render templates with unescaped user input — always use Fiber's template engine escaping; raw string interpolation in HTML responses leads to XSS vulnerabilities.
  5. ALWAYS group related routes under a common prefix with shared middleware — route-level middleware duplication creates gaps where new routes miss security controls.

Anti-Patterns

Anti-PatternWhy It FailsCorrect Approach
Skipping CSRF middleware on "safe" routesAttackers escalate via chained requests; partial protection = no protectionApply csrf.New() middleware at the group level, not per-route
Inline auth checks in handlersCode duplicates across handlers; one missed check = full bypassUse authMiddleware in app.Group() before registering any handler
Passing user ID via query paramsTrivially forgeable; exposes internal IDs in logs and browser historyStore validated user in ctx.Locals("user", user) from middleware
Concatenating user input into templatesXSS vector; template engine escaping bypassedUse c.Render() with template variables; never fmt.Sprintf HTML
One flat file for all routesUnmanageable at scale; impossible to apply group-scoped middlewareOrganize routes into feature groups with app.Group("/feature")

Memory Protocol (MANDATORY)

Before starting:

cat .claude/context/memory/learnings.md

After completing: Record any new patterns or exceptions discovered.

ASSUME INTERRUPTION: Your context may reset. If it's not in memory, it didn't happen.

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

Not specified

Source path

.claude/skills/fiber-routing-and-csrf-protection

Default branch

main

Latest commit

64b580e

Tree SHA

42a1df4