CaioXDeveloper/fastify-secure-api ? reverse-engineered prompt

Reverse engineered prompt

Build me a small secure API in TypeScript with Fastify that I can use as a starter for a real backend. It should have login with an HttpOnly signed cookie session, a matching CSRF token flow, role based access for admin and user, and a simple rate limit on login. I want stable JSON errors with a code and message, plus a health route, a me route, a users route that needs permission, and a couple admin routes protected by role and CSRF.

Use a simple in memory user store with seeded admin and user accounts from env, and hash passwords safely. Keep it ready to run locally with a clear env example and sensible defaults, but make it easy to swap the storage layer later. Also make sure the API is safe by default, with security headers, cookie settings, and localhost binding. If you need to check current Fastify docs for the best way to do something, go ahead and look them up.

Are you gonna build this?

make sure you review the code using coderabbit

Try freeSponsored — opens CodeRabbit in a new tab