zhangzhen
The following routes are defined on the User resource:
json_api do
type "user"
routes do
base "/users"
get :read
get :current_user, route: "/me"
index :read
post :register_with_password
end
end
How do i connect this to MyAppWeb.ApiAuthController in router.ex? I want to setup routes for register, sign_in, sign_out json api.
Trending in Questions
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
Hello,
I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
I’m seeing that a list inside a Kino.DataTable will be interpreted as a charlist, even if the Kino.configure() is set to charlists: :as_l...
New
So my question is quite simple and i have found no conclusive answer on forum, google or AI.
Should we use :erlang.float for Integer to ...
New
Documentation
While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
Hi, I’ve just set up an application with ash_authentication. There is only magic link strategy for now, so there is no confirmation add o...
New
If a change or preparation module uses Ash.Changeset.get_argument/2 or Ash.Query.get_argument/2 (or any of the other get_argument functio...
New
Other Trending Topics
I am happy to introduce the very α version of the new programming language compiled to BEAM.
Welcome Cure.
It has literally three kille...
New
Hi there! We created Gust: A task orchestrator inspired by Airflow.
For those who have never heard about Aiflow, it’s a Python-based wor...
New
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New
Corex is an accessible, unstyled UI component library for Phoenix that integrates Zag.js state machines using Vanilla JavaScript and Live...
New
With AI doing more of the implementation work, I’ve been wondering how much coding I should deliberately keep doing myself.
My main conc...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixirconf-us
- #ai
- #blog-post
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #hex
- #security
- #metaprogramming










Showing Posts 1 to 8- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
zachdaniel
Right now there is not a good set up for using
ash_json_apito do sign in/registration. You will need to handwrite phoenix controllers. This is, however, something I am working on this week: Ash Framework Roadmap · GitHubzachdaniel
Support for this is now in
main, with a guide on setting it up. It will be a few days at least before this gets a proper release: ash_json_api/documentation/topics/authenticate-with-json-api.md at main · ash-project/ash_json_api · GitHubzhangzhen
Thank you for your quick response. what about sign_out?
zachdaniel
You should be able to work something out for
sign_outusing the new feature inmainof connecting generic actions to routes.TBH I forget exactly what the sign_out logic does by default, I think it just expires the token. @jimsynz may be able to provide more info here. Check the actions defined in your user/token resources, using
Ash.Resource.Info.actions(User)andAsh.Resource.Info.actions(Token)to see what actions are generated byAshAuthenticationfor calling.zhangzhen
Following the doc you listed, I setup the signin json api and tested it via SwaggerUI. Policies are defined in the User resource as follows:
Unexpected, I got Forbidden back. What is the reason that this json api returned Forbidden?
zachdaniel
AshJsonApiby calling it directly (in a test or in iex) for example. So you can reproduce there, and you’ll likely get more information. Set the following configs in yourdev.exsandtest.exsto get more policy related information:zhangzhen
after some trial and error, i found that if email and password don’t match the database, then Forbidden/403 is returned. Is this reasonable?
zachdaniel
Yes, this should be correct. It returns a 403 if there is no matching email in the database as well, so this can’t be used for an enumeration attack.