adarsh1021

adarsh1021

My current authentication system looks like this:

  1. On entering username and password, the login endpoint is called (not a form action) that authenticates the user.
  2. A new session (row in an internal table) is created for this user, and this session id is put in the session cookie.
  3. On every request, I fetch the session from cookie, get the session id, do a lookup to identify the user.

On running sobelow, I get the CSRF error because is uses the :fetch_session plug. On adding the :protect_from_forgery, naturally it throws an error because I do not have a CSRF token set for my APIs.

The alternative is to use a bearer token mechanism for authentication of APIs. I also need the user to be logged in for an extended period of time. This means along with the bearer token I need to use a refresh token mechanism as well. I also figured out storing the refresh token on the client side is a bad idea. I came across the solution to use a HttpOnly cookie to store the refresh token.

But I am confused by the overall flow here:

  1. Obtain a CSRF token for the client.
  2. Send the CSRF token along with the login credentials.
  3. Once authenticated, generate refresh token and bearer token. Put refresh token in the HttpOnly cookie and send back bearer token.
  4. For every API call use the bearer token for authentication.
  5. Once the bearer token expires, what do I do? To get access to the refresh token I need access to the cookies, which again means I need a CSRF token?

What am I missing here? I feel like there has to be a simpler way.
Would really appreciate any help / guidance on this :smile:

References:

Showing Posts 1 to 2

cospin

cospin

Before the token expires, a request is made to an endpoint that is responsible for generating another access token. The server does have access to the refresh token, so once it receives the request, it verifies the refresh token stored in the cookies, and if everything is fine, it returns a new access token to the client, and now the client uses that.

This is a simple way to accomplish it, there are other more advanced and secure measures such as using a fingerprint. This guide is very comprehensive, although it is somewhat focused on GraphQL, it explains all the concepts very well: Your GraphQL guide to handling JWTs on frontend clients

adarsh1021

adarsh1021 OP

This is helpful, thank you!!

— All posts loaded —

Where Next? Top

Trending in Questions Top

RSP87
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
nseaSeb
Hello, I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
asweet-confluent
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
apz
I’m new to elixir and just tried to install the elixirLS extension for VScode(ium) and it is throwing some errors that I would like help ...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews