mbuhot

mbuhot

Ash Authentication - User Invitation Flow

Hi :wave:

I’d like to add a user invitation flow to an application currently using AshAuthentication with the password strategy.

The flow would work something like:

  • An existing Admin user will create the initial User resource
  • AshAuthentication generates a token with ~48h expiry
  • Invitation email is sent to new user including token in a URL
  • User clicks and lands on a page allowing them to set their password
  • Once password set, user is authenticated and redirected to a page in the app

Is this something I can achieve with the password strategy? It’s fairly similar to triggering a password-reset, but has a few differences in the email content, token expiry and UI.

Any suggestions much appreciated, thanks!

Most Liked

jimsynz

jimsynz

Ash Core Team

I’d suggest looking at the way that the password strategy handles the reset flow - it should be relatively simple to duplicate and modify it to support invites.

My only question is whether this should be a different strategy entirely - ie separate from the password strategy. It seems to me that you may want to invite users to sign up with other strategies also. My gut feeling is that you can use the token resource to store invites (you can store arbitrary data in the extra_data field) that way you can rely on the existing expiration and expunge logic. Perhaps there should also be a setting that disables registration without the invite token?

mbuhot

mbuhot

We ended up using a short-term solution where the password reset flow was adapted to implement an invitation.

Some code details that may be helpful for anyone looking to do the same...

Action on the User resource to generate a token and send invitation:

    update :send_invitation_email do
      require_atomic? false

      change after_action(fn _changeset, user, _ctx ->
               # Generate a password reset token
               {:ok, strategy} = AshAuthentication.Info.strategy(__MODULE__, :password)

               {:ok, token} =
                 AshAuthentication.Strategy.Password.reset_token_for(strategy, user)

               # Send token in Invitation email
               {:ok, email_result} =
                 MyApp.Notifications.UserInvitationEmail.send(
                   recipients: user,
                   token: token
                 )

               {:ok, user}
             end)
    end

Email links to a custom UI presenting a “Set Your Password” message in place of the usual “Reset Password”

I had to work around having multiple password reset routes in the same scope by inlining the reset_route macro:

  scope "/", MyAppWeb do
    pipe_through([:browser, :browser_ash_authentication])

    reset_route(
      live_view: MyAppWeb.PasswordResetLive,
      overrides: [MyAppWeb.AuthOverrides, AshAuthentication.Phoenix.Overrides.Default]
    )

    # Can't have multiple reset_route - inlining macro here to approximate it.
    scope "/accept-invitation", alias: false do
      live_session :accept_invitation,
        session: %{
          "overrides" => [MyAppWeb.AuthOverrides, AshAuthentication.Phoenix.Overrides.Default],
          "otp_app" => nil
        } do
        live("/:token", MyAppWeb.AcceptInviteLive, :accept_invitation, as: :auth)
      end
    end

    ... more routes
  end

The custom UI eventually calls the reset action with:

result =
  MyApp.User
  |> AshAuthentication.Info.strategy!(:password)
  |> AshAuthentication.Strategy.action(:reset, %{
    "reset_token" => token,
    "password" => password,
    "password_confirmation" => password_confirmation
  })
jimsynz

jimsynz

Ash Core Team

What about non-password strategies? ie allowing someone to accept an invite and then sign in with github for example.

Where Next?

Popular in Questions Top

vegabook
I’m brand new to Phoenix and I have stripped one of the demo applications to the bone. I just want to get an svg up on the screen. Here i...
New
baxterw3b
Hi guys, i’m new in the Elixir world, and i have to say, that i love it! i’m having some problem to understand anonymous functions with ...
New
lanycrost
Hi everyone! I need implement if…else if…else condition from my elixir code, and anymore of this control flow structures not work proper...
New
sergio_101
I am VERY much an elixir newbie. I have taken one elixir course and one phoenix course on Udemy. During that course, I saw the instructor...
New
romenigld
I am trying to run a deploy with docker and I successfully runned with this command: docker build -t romenigld/blog-prod . but when I t...
New
fayddelight
I tried installing elixir 1.11.2 erlang 23.3.4 via asdf in my zsh shell. Enabled the versions locally and globally. When I list them ...
New
senggen
Erlang/OTP 25 [erts-13.2.2] [source] [64-bit] [smp:8:8] [ds:8:8:10] [async-threads:1] 15:22:35.803 [error] gen_event {lager_file_backend...
New

Other popular topics Top

electic
Hi, I am new to Elixir. I am trying to use the DateTime component to insert a date into MySQL however the there seems to be no way to fo...
New
minhajuddin
I have seen a lot of code which picks the first element from a list using Enum.at(0) instead of List.first. Is there a reason why people ...
New
grych
Hi folks, Few months ago I have announced the proof-of-concept of the library to manipulate the browsers DOM objects directly from Elixi...
639 54006 488
New
vonH
In asking this question I am more interested about the expressiveness of the language itself and less concerned about the availability of...
New
hariharasudhan94
Lets say I have map like this fetching from my database %{"_id" => #BSON.ObjectId<58eb1a7a9ad169198c3dXXXX>, "email" => ...
New
sergio_101
I am VERY much an elixir newbie. I have taken one elixir course and one phoenix course on Udemy. During that course, I saw the instructor...
New

We're in Beta

About us Mission Statement