kokolegorille

kokolegorille

Hello everyone,

I am trying to read a cookie I put on the connection after login. I set it like this…

  defp put_refresh_cookie(conn, token) do
    conn
    |> put_resp_cookie("refresh", token, sign: true, http_only: true, secure: true, max_age: 604800)
    # |> put_resp_cookie("refresh", token, sign: false, http_only: true, secure: true, max_age: 604800)
  end

and I try to read it back in a refresh action of an API controller with…

refresh_cookie = conn.req_cookies["refresh"]

If I use sign: false in put_resp_cookie, I can read it back without problem. With sign: true, the value is not equivalent

How can I read it back when using sign: true?

Thanks in advance

Showing Posts 1 to 3

al2o3cr

al2o3cr

The trick is mentioned in the docs for put_resp_cookie - the corresponding fetch_cookies call needs to specify which cookies are signed/encrypted.

For instance, here’s a spot that does it in phx.gen.auth’s code:

kokolegorille

kokolegorille OP

Thank You for your response…

I saw this fetch_cookies and used this code

conn = fetch_cookies(conn, signed: ~w(refresh))
refresh_cookie = conn.req_cookies["refresh"]
IO.inspect refresh_cookie, label: "COOKIE"
TokenHelpers.verify_token(refresh_cookie)
|> IO.inspect(label: "VERIFY")

But it does not seems to return the same value as passed, and when I verify the token, it fails

This is the token I pass

TOKEN: "SFMyNTY.g2gDdAAAAAJ3AmlkbQAAACRmYWMyZWU2MC0wMjRkLTQwOWItYmYxNi1kMTUxNmI4ZmFhNTl3BG5hbWVtAAAABWFkbWlubgYAUnkQEI4BYgABUYA.P0wcEGTxqV5_X-7JDOybsJ1oVzXfsFc2erYPKVxH7_g"
VERIFY: {:ok, %{id: "fac2ee60-024d-409b-bf16-d1516b8faa59", name: "admin"}}

This is the value I receive as the cookie

AFTER COOKIE: "SFMyNTY.g2gDbQAAAKNTRk15TlRZLmcyZ0RkQUFBQUFKM0FtbGtiUUFBQUNSbVlXTXlaV1UyTUMwd01qUmtMVFF3T1dJdFltWXhOaTFrTVRVeE5tSTRabUZoTlRsM0JHNWhiV1Z0QUFBQUJXRmtiV2x1YmdZQVVua1FFSTRCWWdBQlVZQS5QMHdjRUdUeHFWNV9YLTdKRE95YnNKMW9Welhmc0ZjMmVyWVBLVnhIN19nbgYAUnkQEI4BYgAJOoA.anW9pNkQ8yNy_bzRYl2RyKtIU2w_F2z1by9JfV8n-eo"
VERIFY: {:error, :invalid}

I will look at the phx.gen.auth code to see how they do

kokolegorille

kokolegorille OP

I need to get the cookie like this

refresh_cookie = conn.cookies["refresh"]

and not like this…

refresh_cookie = conn.req_cookies["refresh"]

I thought it would be the same, but it’s not.

Thank You for the help

— All posts loaded —

Where Next? Top

Trending in Questions Top

Blokh
Hey guys, I’ve got a huge CSV ( around 10 GB ) that needs to be processed hourly Do you guys have any suggestions what is the best prac...
New
kszambelanczyk
Hello! Could someone please give me a help/sample code, how to delete a file from s3 using waffle/waffle_ecto from Phoenix app. I creat...
New
Onor.io
I have what I’ve heard referred to as a “lookup table” in my database. This is a way of assigning codes to common values. One common lo...
New
Trolleger
What approach to take when sending live updates to “random” users Hi! I have a question, I have a little chat app, and when I create a DM...
New
RemyXRenard
I’m seeing that a list inside a Kino.DataTable will be interpreted as a charlist, even if the Kino.configure() is set to charlists: :as_l...
New
matt-savvy
Anyone here using Honeybadger? My Honeybadger account is being overwhelmed with noise from some bots. Seeing a lot of Bandit.HTTPError...
New
samoloth
Hi, I’ve just set up an application with ash_authentication. There is only magic link strategy for now, so there is no confirmation add o...
New

Other Trending Topics Top

mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
Damirados
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge & Solve. They are GUI (Emerge) and State management (S...
New
netoum
Corex is an accessible, unstyled UI component library for Phoenix that integrates Zag.js state machines using Vanilla JavaScript and Live...
New
wintermeyer
There are three potential reasons for members of this forum to have a look at https://vutuv.de You are tired or annoyed of LinkedIn. Yo...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews