TechnicalCollectible prompt

Sign-in with user roles and protected pages

Add secure sign-in with roles checked on the server and in the database, not just hidden buttons.

LovableClaude CodeCursor

Curated by Nvoka

Nvoka wordmark logo
Nvoka wordmark logoTechnical

Sign-in with user roles and protected pages

Add sign-in with role-based permissions to my {{tech_stack}} app. The roles are {{user_roles}}. Protect {{page_or_feature}} and anything else that shows private data. Read the existing code first and show me a short plan before changing files. Sign-in: - Email and password with email verification, plus a passwordless email link; add Google sign-in only if it fits the project - Password reset, sign out, and a return to the page someone was trying to reach - Forms that allow pasting and password managers, with the right autocomplete settings - One generic message for failed sign-ins, so it never reveals whether an email has an account - Rate limits on sign-in, sign-up and password reset Roles: - Stored in their own table that only admins can change, never in a profile field or user metadata the user can edit - Checked on the server and enforced by database access rules on every table, not just by hiding buttons - An invite flow for adding staff, and a safe way to create the first admin - Tell me if a role change needs a fresh session before it takes effect Test every role against every protected page and action, including direct requests to the API. When you're done, list the files changed, a table of who can do what, how to test it, and anything you assumed.
Technicalnvoka.com/library/nvoka-sign-in-with-roles-and-protected-pagesScan to open
Technical

Sign-in with user roles and protected pages

Add secure sign-in with roles checked on the server and in the database, not just hidden buttons.

Nvoka logo

Curated by Nvoka

LovableClaude CodeCursorCodex
Add to my library

Make it yours

Fill in the blanks and change any word. Only your copy changes, never the card.

Fill in the blanks

0 of 3 filled

Your prompt

Add sign-in with role-based permissions to my {{tech_stack}} app. The roles are {{user_roles}}. Protect {{page_or_feature}} and anything else that shows private data. Read the existing code first and show me a short plan before changing files. Sign-in: - Email and password with email verification, plus a passwordless email link; add Google sign-in only if it fits the project - Password reset, sign out, and a return to the page someone was trying to reach - Forms that allow pasting and password managers, with the right autocomplete settings - One generic message for failed sign-ins, so it never reveals whether an email has an account - Rate limits on sign-in, sign-up and password reset Roles: - Stored in their own table that only admins can change, never in a profile field or user metadata the user can edit - Checked on the server and enforced by database access rules on every table, not just by hiding buttons - An invite flow for adding staff, and a safe way to create the first admin - Tell me if a role change needs a fresh session before it takes effect Test every role against every protected page and action, including direct requests to the API. When you're done, list the files changed, a table of who can do what, how to test it, and anything you assumed.
See all