MartinVolerich
Authorizer Policies: Whats the difference....?
What’s the difference between a simple policy on a resource that is:
policy action_type(:create) do
description "Only admins can create surveys"
authorize_if actor_attribute_equals(:admin?, true)
forbid_if always()
end
as compared to
policy action_type(:create) do
description "Only admins can create surveys"
forbid_unless actor_attribute_equals(:admin?, true)
end
I had assumed that the latter would be the same as the former but less lines - but that doesn’t seem to be the case.
What else do I need to read on this topic?
Thanks
Martin
Most Liked
zachdaniel
Creator of Ash
Policies forbid by default. So when following a policy from the top down, if nothing creates the :authorized result, then the policy is forbidden.
What that means for your first policy is:
policy action_type(:create) do
description "Only admins can create surveys"
authorize_if actor_attribute_equals(:admin?, true)
# forbid_if always() <- this is not necessary
end
What that means for your second policy is:
policy action_type(:create) do
description "Only admins can create surveys"
forbid_unless actor_attribute_equals(:admin?, true)
# Nothing will ever produce `:authorized` here, so this policy will never pass.
end
The policies guide explains how policies are evaluated, expanding on these concepts.
1
MartinVolerich
Makes sense - so a authorize_if always() after the forbid would work in the second case.
Thanks for the reply.
1
Trending in Questions
Hi everyone!
I need implement if…else if…else condition from my elixir code, and anymore of this control flow structures not work proper...
New
Erlang/OTP 25 [erts-13.2.2] [source] [64-bit] [smp:8:8] [ds:8:8:10] [async-threads:1]
15:22:35.803 [error] gen_event {lager_file_backend...
New
Lets say I have map like this fetching from my database
%{"_id" => #BSON.ObjectId<58eb1a7a9ad169198c3dXXXX>, "email" => ...
New
I’ve been following the steps here for the upgrade from 1.6 to 1.7 and it has gone relatively smoothly all the way till the phoenix_view ...
New
Hi!
What is currently the best library/method for parsing text and tabular data out of PDF files in Elixir or Erlang?
New
Hi, I need a way to handle data migrations in my application. I found an article by @wojtekmach about manual migrations: Automatic and ma...
New
Hello!
Suppose you are building workflow (order / task / payment) processing system with the following requirements:
Each workflow con...
New
Other Trending Topics
Edit: 2026 May 15 - This post is archived.
Mob is alive!!
Main docs: mob v0.7.11 — Documentation
A bit of explanation for the slightly c...
New
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
Localize is the next generation localisation library for Elixir. Think of it as ex_cldr version 3.0. The first version will be released ...
New
Squid Mesh is an open source workflow automation runtime for Elixir applications.
It is aimed at Phoenix and OTP apps that want to defin...
New
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
In 2021 I started a new library called Tempo with the objective of modelling time as a set of intervals - not as instants. In 2022 I gave...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #deployment
- #library
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #channels
- #elixirconf
- #exunit
- #discussion
- #code-sync
- #javascript
- #podcasts
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixir-ls
- #phoenix_html
- #iex
- #blog-post
- #graphql
- #genstage
- #ai
- #websockets
- #elixirconf-us
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #metaprogramming
- #security
- #hex









