gordoneliel

gordoneliel

When tokens are enabled for a resource, there appears to be no way to customize the signed token with extra claims when using the AshAuthentication.Plug.

I tried manually defining routes for auth, but when I try to create the token manually with AshAuthentication.Jwt.token_for_user, I get duplicate tokens (Because store_all_tokens is true). If I set store_all_tokens? to false, I can manually create a token, but the token doesn’t get stored.

Question is, is it possible to add extra claims to the jwt when using the generated ash plug?

autentication do
    tokens do
        enabled? true
        token_resource AccountsService.Accounts.Token
        signing_secret AccountsService.Accounts.Secrets
        store_all_tokens? true
        require_token_presence_for_authentication? true
        token_lifetime {90, :days}
      end
end

Showing Posts 1 to 4

jimsynz

jimsynz

Ash Core Team

Hi @gordoneliel :wave:

So, looking at the code to refresh my memory, it seems that by default the primary key is the JTI, which is unique to every token so I don’t know how you could possibly be getting a conflict. Additionally, you can provide an alternative “purpose” for the token (defaults to "user") by passing the purpose option to token_for_user/3.

What I would probably do is customise your AuthController/AuthPlug success callback and have it ignore the auto-generated token and generate a new token with the claims you want.

gordoneliel

gordoneliel OP

I tried doing that, and going the full custom routes as well, but unfortunately the code for creating a token looks into the resource to check whether to store the token or not. If I leave it on, it works, but creates a duplicate token for one login request. If I turn off store_all_tokens? then nothing gets stored in the db.

  defp maybe_store_token(token, resource, user, purpose, opts) do
    if Info.authentication_tokens_store_all_tokens?(resource) do
      with {:ok, token_resource} <- Info.authentication_tokens_token_resource(resource) do
        TokenResource.Actions.store_token(
          token_resource,
          %{
            "token" => token,
            "purpose" => to_string(purpose)
          },
          Keyword.put(opts, :context, %{
            ash_authentication: %{
              user: user
            }
          })
        )
      end
    else
      :ok
    end
  end
gordoneliel

gordoneliel OP

Just to clarify, I’m not getting a conflict, what happens is that two tokens get created every time a user signs in

jimsynz

jimsynz

Ash Core Team

Ahhhh! I see. I thought you were running into a database constraint.

I think we could add a behaviour or callback to token generation that lets you modify the claims.

— All posts loaded —

Where Next? Top

Trending in Questions Top

katta
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
achenet
Hello, I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind. However, when I launch mix phx.server, I get an error...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
asweet-confluent
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
Cxx-mlr
I’m working on a small exercise involving update_in/3, and I came up with this solution: data = %{ name: "Periodic Table", category:...
New
ChrisAmelia
I’ve got trouble wrapping my head around the order in which functions are called in this snippet (from Phoenix’s authentication): toke...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New
KristerV
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews