marinho10

marinho10

I’m trying make authorization/authentication graphql subscriptions with elixir and absinthe using cookies and I used the follow link:

I’m trying authenticate the user for subscribe the right topic but I don’t have access to the cookies in the subscription connection. Why?

After I saw the follow link:

And in my user_socket.ex I pass the user_id as query param, this works, but it’s not secure at all… I can pass the id that I want !!!

Can someone help me?

 @moduledoc false

 use Phoenix.Socket

 use Absinthe.Phoenix.Socket,
   schema: MyAppGraphQL.Schema

 ## Channels
 # channel "room:*", MyAppWeb.RoomChannel

 # Socket params are passed from the client and can
 # be used to verify and authenticate a user. After
 # verification, you can put default assigns into
 # the socket that will be set for all channels, ie
 #
 #     {:ok, assign(socket, :user_id, verified_user_id)}
 #
 # To deny connection, return `:error`.
 #
 # See `Phoenix.Token` documentation for examples in
 # performing token verification on connect.
 def connect(%{"user_id" => user_id}, socket) do
   case current_user(user_id) do
     nil ->
       :error

     current_user ->
       socket =
         Absinthe.Phoenix.Socket.put_options(socket,
           context: %{
             current_user: current_user
           }
         )

       {:ok, socket}
   end
 end

 def connect(_, _), do: :error

 defp current_user(user_id), do: MyApp.Accounts.lookup_user_with_company(user_id)

 # Socket id's are topics that allow you to identify all sockets for a given user:
 #
 #     def id(socket), do: "user_socket:#{socket.assigns.user_id}"
 #
 # Would allow you to broadcast a "disconnect" event and terminate
 # all active sockets and channels for a given user:
 #
 #     MyAppWeb.Endpoint.broadcast("user_socket:#{user.id}", "disconnect", %{})
 #
 # Returning `nil` makes this socket anonymous.
 def id(_socket), do: nil

end

Showing Posts 1 to 3

fuelen

fuelen

WebSockets do not have cookies. All they have is parameters. You have to use a token by which you can get user id and user after that.
There is an example here Phoenix.Token — Phoenix v1.8.8 how to use Phoenix.Token with sockets.

marinho10

marinho10 OP

To understand everything, I follow the following topic: Accessing cookies in Phoenix.Socket connect

— All posts loaded —

Where Next? Top

Trending in Questions Top

katta
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
achenet
Hello, I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind. However, when I launch mix phx.server, I get an error...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
asweet-confluent
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
mnkhod
So i have been using ash framework for a while and i love it. However currently the issue im having with ash framework is the error handl...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews