MartinVolerich

MartinVolerich

Authorizer Policies: Whats the difference....?

What’s the difference between a simple policy on a resource that is:

policy action_type(:create) do
  description "Only admins can create surveys"
  authorize_if actor_attribute_equals(:admin?, true)
  forbid_if always()
end

as compared to

policy action_type(:create) do
  description "Only admins can create surveys"
  forbid_unless actor_attribute_equals(:admin?, true)
end

I had assumed that the latter would be the same as the former but less lines - but that doesn’t seem to be the case.

What else do I need to read on this topic?

Thanks
Martin

Most Liked

zachdaniel

zachdaniel

Creator of Ash

Policies forbid by default. So when following a policy from the top down, if nothing creates the :authorized result, then the policy is forbidden.

What that means for your first policy is:

policy action_type(:create) do
  description "Only admins can create surveys"
  authorize_if actor_attribute_equals(:admin?, true)
  #  forbid_if always() <- this is not necessary
end

What that means for your second policy is:

policy action_type(:create) do
  description "Only admins can create surveys"
  forbid_unless actor_attribute_equals(:admin?, true)
  # Nothing will ever produce `:authorized` here, so this policy will never pass.
end

The policies guide explains how policies are evaluated, expanding on these concepts.

MartinVolerich

MartinVolerich

Makes sense - so a authorize_if always() after the forbid would work in the second case.

Thanks for the reply.

Where Next?

Trending in Questions Top

lanycrost
Hi everyone! I need implement if…else if…else condition from my elixir code, and anymore of this control flow structures not work proper...
New
senggen
Erlang/OTP 25 [erts-13.2.2] [source] [64-bit] [smp:8:8] [ds:8:8:10] [async-threads:1] 15:22:35.803 [error] gen_event {lager_file_backend...
New
hariharasudhan94
Lets say I have map like this fetching from my database %{"_id" =&gt; #BSON.ObjectId&lt;58eb1a7a9ad169198c3dXXXX&gt;, "email" =&gt; ...
New
tj0
I’ve been following the steps here for the upgrade from 1.6 to 1.7 and it has gone relatively smoothly all the way till the phoenix_view ...
New
cgraham
Hi! What is currently the best library/method for parsing text and tabular data out of PDF files in Elixir or Erlang?
New
stefanchrobot
Hi, I need a way to handle data migrations in my application. I found an article by @wojtekmach about manual migrations: Automatic and ma...
New
stjefim
Hello! Suppose you are building workflow (order / task / payment) processing system with the following requirements: Each workflow con...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
kip
Localize is the next generation localisation library for Elixir. Think of it as ex_cldr version 3.0. The first version will be released ...
New
webofbits
Squid Mesh is an open source workflow automation runtime for Elixir applications. It is aimed at Phoenix and OTP apps that want to defin...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
kip
In 2021 I started a new library called Tempo with the objective of modelling time as a set of intervals - not as instants. In 2022 I gave...
New

We're in Beta

About us Mission Statement