jordelver
Generate token for email and SMS
I have a form where a user submits their email, a record is inserted into the database, and the database id is added to the session. They are then redirected to a LiveView where the session is passed.
In case the user closes their browser or they want to find their page for any reason, I want to send an email and SMS containing a link. When they click the link they should end up back on their particular page.
So I need to generate a token for them.
Phoenix.Token seems like it would work, but it generates a long string, which would work fine for sending in an email, but is too long for an SMS.
Is it secure enough to just generate a random token, save to the database, and include that in a URL? What length is considered “good enough”?
No personal information is available on the user’s page and the page is short lived.
I’m paranoid about security after reading so much! Thanks.
Most Liked
jordelver
I was just looking at how phx.auth.gen generates tokens and they do this:
token = :crypto.strong_rand_bytes(32)
hashed_token = :crypto.hash(:sha256, token)
Base.url_encode64(token, padding: false)
dom
hauleth
Popular in Questions
Other popular topics
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #deployment
- #library
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #channels
- #elixirconf
- #exunit
- #discussion
- #code-sync
- #javascript
- #podcasts
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixir-ls
- #phoenix_html
- #iex
- #blog-post
- #graphql
- #genstage
- #ai
- #websockets
- #supervisor
- #elixirconf-us
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #metaprogramming
- #security
- #hex










