ion

ion

I know this is a really basic question, but I am having trouble figuring out how to authorize channel join events.

The phx.gen.channel template includes a private authorized?/1 function. If I want to find the user’s id to check their authorization role (I’m using phauxth), do I go about that by pattern matching the current_user from the payload argument? Or, can I check the socket directly for the current_user? If so, how? Just trying to check against socket.assigns.current_user but don’t know how… :grinning:

  # Add authorization logic here as required.
  defp authorized?(_payload) do
    true
  end

which is called in:

  def join("room:lobby", payload, socket) do
    if authorized?(payload) do
      {:ok, socket}
    else
      {:error, %{reason: "unauthorized"}}
    end
  end

Marked As Solved

kokolegorille

kokolegorille

In the user_socket.ex, I do something like this

  def connect(%{"token" => token}, socket) do
    with {:ok, user_id} <- verify_token(token),
      user <- Accounting.get_user(user_id) do
      
      {:ok, assign(socket, :current_user, user)}
    else
      {:error, _reason} ->
        :error
    end
  end

I decode a token (a phoenix token), with this helper

  @salt "blah salt"
  @max_age 86400

  def verify_token(token), do:
    Phoenix.Token.verify(BlahWeb.Endpoint, @salt, token, max_age: @max_age)

Then, in the channel, I know I will get a user

  def join("user:" <> id, _params, socket) do
    if String.to_integer(id) === socket.assigns.current_user.id do
      {:ok, socket}
    else
      {:error, %{reason: "Not authorized"}}
    end
  end

In your case, You might just check for socket.assigns.current_user

Also Liked

kokolegorille

kokolegorille

That is what I do, I use socket.assigns.current_user as my authentication param…

ion

ion OP

I do the authentication in user_socket to get the user id.

Now in room_channel, to authorize the user, would it be a good idea to set the argument of authorized?/1 as socket.assigns.current_user?

def join("room:" <> room_id, payload, socket) do
 if authorized?(socket.assigns.current_user) do
  {:ok, socket}
 else
  {:error, "nope not authorized"}
 end
end

.

defp authorized?(useridpayload) do
 useridpayload = String.to_integer(useridpayload)
  ... repo get user role pseudocode..
  case role do
   "admin" -> true
   "user" -> true
    _ -> false
  end 
 end
ion

ion OP

Thanks for your help!

Where Next? Top

Trending in Questions Top

RSP87
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
nseaSeb
Hello, I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
asweet-confluent
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
ryanwinchester
apply_graft/2 doesn’t rewrite an add_many sub-workflow’s deps on an add step. Grafted jobs cancel with “upstream job was deleted” Version...
New

Other Trending Topics Top

JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New

Latest on Elixir Forum

Elixir Forum

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews