Onek

Onek

Ash Policies and AshJsonApi

Hopefully a simple one where I’m just not understanding the documentation properly between policies and AshJsonAPI.

I have a resource with two attributes where we use one of the attributes to reference a value that is held in our Actor struct. Note our “user” isn’t captured as a resource in Ash and we’re instead ad-hoc creating the Actor struct in a plug further up the pipeline.

attribute :name, :string
attribute :owner_id, :string

This resource is exposed via AshJsonAPI and I’d like to put some access restrictions on the :create, :update, and :destroy actions where clients shouldn’t be allowed to create, update, or destroy records that they don’t “own”.

policy action_type([:update, :destroy]) do
   forbid_unless expr(owner_id == ^actor(:name))
end

This seemingly works, however it returns a 404 instead of a 403 when a policy isn’t allowed for :update and :destroy. I’m not sure if that’s expected or not, but I thought :update and :destroy would yield the forbidden error rather than the “filtering” 404. Further, if I update the :access_type to force :strict mode then the policy never authorizes anything even when the expr should be returning true (this one definitely confuses me). For a little more context the :read action is unrestricted so anyone can see anyone else’s records – they’re just not allowed to update/delete them.

policy action_type([:update, :destroy]) do
   access_type :strict
   authorize_if expr(owner == ^actor(:name))
end

Trying to figure out if I’m missing something, if the above behavior is an actual bug, or maybe I’m playing way out in left field somewhere.

Marked As Solved

zachdaniel

zachdaniel

Creator of Ash

filtering updates

There are actually two “modes” for authorizing bulk updates and destroys. AshJsonApi uses Ash.bulk_update and Ash.bulk_destroy with a filter for a single record as a mechanism for potentially avoiding the need to update the underlying record. It is currently using the default behavior, which adds the authorization rules for the update as a filter. We could make this configurable, telling AshJsonApi to pass authorize_changeset_with: :error (this is not supported by all data layers, but postgres can do it). This would give you the behavior you are looking for. Please open a proposal issue or PR :person_bowing:. We can likely add a domain-wide and/or global configuration to start, which would be pretty straightforward.

access_type :strict

As to why access_type :strict doesn’t behave as expected, what access_type :strict means is that “everything in this policy must pass before ever attempting to speak to the data layer”. its effectively impossible to use a filter check in that context. You could instead write custom checks that do things like look at the changeset and compare changing values to the actor etc.

Last Post!

zachdaniel

zachdaniel

Creator of Ash

Yep, you should prefer to use SimpleCheck, and add def requires_original_data?(_, _), do: true to the check module.

Where Next?

Popular in Questions Top

JeremM34
Hello, how can I check the Phoenix version ? Thanks !
New
vegabook
I’m brand new to Phoenix and I have stripped one of the demo applications to the bone. I just want to get an svg up on the screen. Here i...
New
minhajuddin
I have seen a lot of code which picks the first element from a list using Enum.at(0) instead of List.first. Is there a reason why people ...
New
baxterw3b
Hi guys, i’m new in the Elixir world, and i have to say, that i love it! i’m having some problem to understand anonymous functions with ...
New
Qqwy
Original source of discussion: This topic on the Pragmatic Programmers’ Functional Web Development with Elixir, OTP, and Phoenix forum. ...
New
albydarned
Hello all! I am typing this post from my new MacBook Pro with the M1 chip. I’m loving it so far, and will probably use it as my daily dr...
New
jason.o
In the code below, if the create action is not set to accept “extra_key” as an input, it errors out with a message shown above. Is there ...
New

Other popular topics Top

Qqwy
Original source of discussion: This topic on the Pragmatic Programmers’ Functional Web Development with Elixir, OTP, and Phoenix forum. ...
New
vonH
In asking this question I am more interested about the expressiveness of the language itself and less concerned about the availability of...
New
dokuzbir
I want to highlight html closing tags when i click a html tag. That works in .html files but doesnt work for html.eex templates. How can...
New
Darmani72
If I have a post route which an argument: post /my_post_route/:my_param1, MyController.my_post_handler How would get the post params ...
New
AngeloChecked
What learn first? Rust or Elixir Hi Elixir community! I’m here because i want learn a new language. I’m a junior developer and mainly i ...
New
senggen
Erlang/OTP 25 [erts-13.2.2] [source] [64-bit] [smp:8:8] [ds:8:8:10] [async-threads:1] 15:22:35.803 [error] gen_event {lager_file_backend...
New

We're in Beta

About us Mission Statement