sezaru

sezaru

I have this policy that I use to identify if the user is himself or not:

defmodule Core.Ash.Policies.Self do
  @moduledoc false

  use Ash.Policy.FilterCheck

  @impl Ash.Policy.Check
  def describe(opts) do
    field = Keyword.get(opts, :field, :id)

    "record #{field} matches actor id"
  end

  @impl Ash.Policy.FilterCheck
  def filter(_actor, _context, opts) do
    field = Keyword.get(opts, :field, :id)

    expr(^ref(field) == ^actor(:id))
  end
end

This works fine for read actions, but it will fail for create/update/destroy actions. To fix that I made these changes:

defmodule Core.Ash.Policies.Self do
  @moduledoc false

  use Ash.Policy.FilterCheck

  defoverridable strict_check: 3

  @impl Ash.Policy.Check
  def describe(opts) do
    field = Keyword.get(opts, :field, :id)

    "record #{field} matches actor id"
  end

  @impl Ash.Policy.FilterCheck
  def filter(_actor, _context, opts) do
    field = Keyword.get(opts, :field, :id)

    expr(^ref(field) == ^actor(:id))
  end

  @impl Ash.Policy.Check
  def strict_check(actor, %{changeset: %Ash.Changeset{action_type: :create} = changeset}, opts) do
    field = Keyword.get(opts, :field, :id)

    {:ok, Ash.Changeset.get_attribute(changeset, field) == actor.id}
  end

  def strict_check(actor, %{changeset: %Ash.Changeset{} = changeset}, opts) do
    field = Keyword.get(opts, :field, :id)

    {:ok, Ash.Changeset.get_data(changeset, field) == actor.id}
  end

  def strict_check(actor, authorizer, opts) do
    super(actor, authorizer, opts)
  end
end

Now it seems to work fine, but I’m not sure if this is the best way to do that. Any thoughts?

Showing Posts 1 to 1

zachdaniel

zachdaniel

Creator of Ash

they should work for update/destroy actions, but not for create actions. I would not suggest using FilterCheck and overriding strict_check, because there are callbacks you need for your version to work consistently around atomic updates. You would want to rework this as a full Ash.Policy.Check module.

I don’t really see how you can have an actor that is creating themselves, but assuming they were creating something else and you wanted to check ownership, you could do:

policy_group some_shared_condition() do
  policy action_type(:create) do
    authorize_if relating_to_actor(:owner)
  end

  policy action_type([:read, :update, :destroy]) do
    authorize_if relates_to_actor_via(:owner)
  end
end
— All posts loaded —

Where Next? Top

Trending in Questions Top

RSP87
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
nseaSeb
Hello, I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
asweet-confluent
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
ryanwinchester
apply_graft/2 doesn’t rewrite an add_many sub-workflow’s deps on an add step. Grafted jobs cancel with “upstream job was deleted” Version...
New

Other Trending Topics Top

JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New

Latest on Elixir Forum

Elixir Forum

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews