skills/README.md
2026-05-10 21:06:23 +02:00

52 lines
1.7 KiB
Markdown

# LLM Skill Marketplace
Go + Postgres marketplace where authenticated users can upload LLM skill files, sell them, and buyers can unlock and copy/download purchased skills.
## Stack
- Backend: Go (`go run .`)
- Frontend: vanilla HTML/CSS/JS
- Database: Postgres
- Auth: external OIDC JWT validation via JWKS
- Config: environment variables with `.env` support
## Run
1. Copy `.env.example` to `.env` and set values.
2. Start Postgres and create the target database.
3. Install dependencies:
```bash
go mod tidy
```
4. Start server:
```bash
go run .
```
5. Open `http://localhost:8080`.
## Local dev mode (no auth setup)
Set `DEV_MODE=true` in `.env` (enabled by default in `.env.example`).
In this mode, protected routes always authenticate as:
- `sub`: `demo-user-001`
- `email`: `demo@example.com`
- `name`: `Demo User`
OIDC variables are not required when `DEV_MODE=true`.
## Auth flow
When `DEV_MODE=false`, login is handled directly by the app:
- `GET /auth/login` redirects to your OIDC provider
- `GET /auth/callback` exchanges code for access token using `OIDC_CLIENT_ID` + `OIDC_CLIENT_SECRET`
- Access token is stored in secure HttpOnly session cookie
- Protected routes validate that token via JWKS
- `GET /auth/logout` clears the local session (and optionally redirects to provider logout URL)
## Key routes
- `GET /dashboard`: upload form
- `GET /skills`: browse listings and buy
- `GET /my-skills`: purchased skills and copy/download access
- `GET /auth/login`: start OIDC login
- `GET /auth/callback`: OIDC callback
- `GET /auth/logout`: logout
- `POST /api/upload`: upload and list a skill
- `POST /api/purchase`: buy a skill
- `GET /api/my-skills`: owned purchased list
- `GET /uploads/:id`: download unlocked skill file