lcabrini

lcabrini

I have a user resource that looks more or less like that one in the Ash Authentication getting started doc, with one added field: role. Role can be one of admin, merchant, client. Only admins should be able to log in via the web frontend, merchants and clients should only be able to register and “sign in” (that is, receive a token) only via a JSON API.

At this time, I’m only interested in the password strategy.

On the web side, everything works well (registration is disabled, I seed an initial admin, who can log in and create more admins, if needed).

However, I cannot get authentication to work with the JSON API. I have followed the documentation for ash-authentication and ash-json-api as well as peeked at this: Ash authentication on mobile - #11 by lud which is the closest I have found to what I’m looking to do.

Right now I’m not sure if I have completely missunderstood everything or if I’m just missing out on some little part. I was expecting registration to be fairly straight-forward, but not even that seems to be working.

I have created a router as per the getting started guide for ash-json-api. Do I need a controller as well? The documentation says the router partly plays the role of a controller, the forum post above says to add a controller. I’m a bit lost here.

Could somebody explain the steps required to get authentication working together with JSON API? Or even better, if you are working on a project that does this and is open source, I unfortunately seem to be better at reading code than explanations, or so it would seem.

Showing Posts 1 to 5

zachdaniel

zachdaniel

Creator of Ash

This is definitely an area we intend to improve at some point. The tools are all there, it’s just a matter of providing the guidance of how to use them. I will let @jimsynz answer because he is much more familiar with AshAuthentication’s internals than I.

lcabrini

lcabrini OP

Yeah, I’ve noticed that Ash can really do a lot, but that the documentation, especially when it’s outside of the default use cases can be a bit lacking at times. I guess that’s normal for projects that move relatively fast. I’d be happy to help out in any way to rectify that situation.

jimsynz

jimsynz

Ash Core Team

Hi there.

Ash Authentication’s dev/test setup includes an example of using JSON:API for password registration. Can you give us more information about what’s not working?

lcabrini

lcabrini OP

Hi. Thanks for the pointer to the dev/test code. I’m looking through to see what I can figure out. To start off I’m trying to get registration to work. This is what I’m currently getting and I’m a little bit stumped, because I think if followed the documentation properly.

$ curl -X POST --data-raw '{"data": {"email": "foo@bar.bim", "password": "f00#b4Rb1mBAzzZ"}}' --header 'Accept: application/vnd.api+json' --header 'Content-Type: application/vnd.api+json' http://localhost:4000/api/accounts/users
{"errors":[{"code":"InvalidBody","id":"6f4fa33a-82ab-4840-a766-34fd349a0b19","status":"400","title":"Invalid Body","source":{"pointer":"data/email"},"detail":"Expected only defined properties, got key [\"data\", \"email\"]."},{"code":"InvalidBody","id":"b9be9233-73fa-4e1a-9188-5ae6d3735ed7","status":"400","title":"Invalid Body","source":{"pointer":"data/password"},"detail":"Expected only defined properties, got key [\"data\", \"password\"]."}],"jsonapi":{"version":"1.0"}}

Clearly I’m missing something or I’ve done something wrong. I just don’t really know what and I’m just running around in a circle at this point.

zachdaniel

zachdaniel

Creator of Ash

Have you followed the set up for the ash json api open api features? I’d suggest doing that and then you can look at your own api docs to see how it works :slight_smile:

— All posts loaded —

Where Next? Top

Trending in Questions Top

katta
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
achenet
Hello, I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind. However, when I launch mix phx.server, I get an error...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
asweet-confluent
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
mnkhod
So i have been using ash framework for a while and i love it. However currently the issue im having with ash framework is the error handl...
New
Cxx-mlr
I’m working on a small exercise involving update_in/3, and I came up with this solution: data = %{ name: "Periodic Table", category:...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews