rapidfsub

rapidfsub

This is a test code for ash_state_machine.
https://github.com/rapidfsub/sonet/blob/develop/test/sonet_lib/ash_state_machine/common_test.exs#L48

assert Ashex.can?({object, :progress}, nil) == false

This assertion passes, so I think there is no permission.

assert {:error, %Ash.Error.Forbidden{}} = Ashex.run_update(object, :progress, actor: nil)

But this assertion does not pass, because the Object.progress action fails with Ash.Error.Invalid.
I think action call without permission should return Ash.Error.Forbidden.
And Ash.Error.Invalid looks like a validation error.

Is this a bug?

Showing Posts 1 to 10

zachdaniel

zachdaniel

Creator of Ash

Ash.can? is “is valid and is allowed” by default. Try using Ash.can and see what kind of error is returned.

rapidfsub

rapidfsub OP

“valid” means validity of policies?
Not the validity determined by validations?

zachdaniel

zachdaniel

Creator of Ash

I’m referring to the validity of the changeset itself. The reason for this is that validations and changes run before authorization.

zachdaniel

zachdaniel

Creator of Ash

Any changes or validations that should run after authorization should use before_action?: true (in the case of validations) or Ash.Changeset.before_action in the case of changes.

rapidfsub

rapidfsub OP

I think I have bad understandig at policy and can function.
So I need to study more about them.

I have a small question.
Would you give me a scenario, when does the can function return {:ok, :maybe}?

zachdaniel

zachdaniel

Creator of Ash

{:ok, :maybe} would be returned in the case of filter policies on read actions, when the data to be read isn’t provided, and run_queries? is set to false. So to answer we’d have to run the queries, so we’d have to say :maybe.

rapidfsub

rapidfsub OP

Thank you for your explanation.

rapidfsub

rapidfsub OP

Ok, now I got it about my original question.

My Conclusions

Ash.can

  • return {:ok, true} when policy pass (even if validation fail)
  • return {:ok, false} when policy fail

Error returned by action

  • return Ash.Error.Forbidden when only policy fail
  • return Ash.Error.Invalid when only validation fail
  • return Ash.Error.Invalid when policy and validation fail
  • cannot determine policy passed/failed by error class

Why return Ash.Error.Invalid when policy and validation fail?

Is this correct? @zachdaniel

rapidfsub

rapidfsub OP

I got these conclusions with below test codes.

This is my ash_state_machine test code.
https://github.com/rapidfsub/sonet/blob/develop/test/sonet_lib/ash_state_machine/common_test.exs

And this is my authorization_validation_priority_test.exs.
https://github.com/rapidfsub/sonet/blob/develop/test/sonet_lib/ash/research/authorization_validation_priority_test.exs

zachdaniel

zachdaniel

Creator of Ash

A better way to phrase this would be that when running the action, policies aren’t run on invalid actions.

— All posts loaded —

Where Next? Top

Trending in Questions Top

katta
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
achenet
Hello, I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind. However, when I launch mix phx.server, I get an error...
New
bradley
I really like the adapter patterns that ecto, nebulex, waffle, etc. use and would love find something similar for a key management servic...
New
unaware8150
Hello folks! So at work, we are seeing some situations where we have to define some “fixed” strings that are used across the codebase in...
New
Cxx-mlr
I’m working on a small exercise involving update_in/3, and I came up with this solution: data = %{ name: "Periodic Table", category:...
New
ChrisAmelia
I’ve got trouble wrapping my head around the order in which functions are called in this snippet (from Phoenix’s authentication): toke...
New
dillonoconnor
Is there any way to avoid the Hologram compiler running when using iex? It seems like the front-end code could potentially be disregarded...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New
KristerV
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
mudasobwa
I fully migrated to my own harness from Anthropic/Gemini and I think it’s time to share it. Welcome DSH, the DeepSeek Harness, fully writ...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews