adrian

adrian

Hello,

I am creating my first Ash Json API with Phoenix.

I am playing with swagger, and I have some questions.

  1. How can I add authentication and authorization? Is it derived from AshAuthentication policies?
  2. How can I get the bearer to test the API authorization?

If I define a policy like this one:

  policies do
    policy always() do
      forbid_if always()
    end
  end

Note I am using this policy only for testing purposes

  1. In the GET action for listing all the items without any API key, it returns a 200 response with an empty list. Shouldn’t be a 401 instead?

I want to return 401 to all API calls that are not authorized using a bearer, and a 403 response to HTTP calls not allowed—for example, a resource owned by another actor.

Thanks!

Showing Posts 1 to 2

zachdaniel

zachdaniel

Creator of Ash

If you want to forbid anyone without a bearer token that is best done in a plug in your router.

Are you using AshAuthentication?

Read actions apply policies by filtering by default. This protects from various security problems.You can change that by setting access_type :strict in the policy, but I suggest sticking with the default.

If you want to enforce in each resource or domain (policies can also go on the domain) you can add a policy like this:

policies do
  policy actor_absent() do
    access_type :strict
    forbid_if always()
  end

  ...rest of policies
end
adrian

adrian OP

Thanks @zachdaniel !

— All posts loaded —

Where Next? Top

Trending in Questions Top

RSP87
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
nseaSeb
Hello, I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
RemyXRenard
I’m seeing that a list inside a Kino.DataTable will be interpreted as a charlist, even if the Kino.configure() is set to charlists: :as_l...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
samoloth
Hi, I’ve just set up an application with ash_authentication. There is only magic link strategy for now, so there is no confirmation add o...
New
FlyingNoodle
If a change or preparation module uses Ash.Changeset.get_argument/2 or Ash.Query.get_argument/2 (or any of the other get_argument functio...
New

Other Trending Topics Top

JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews