dogweather

dogweather

This may be a real beginner thing to be figuring out, but I’m working on both:

  • Good security practices
  • Phoenix module naming

Here’s my current idea.

# Customer-scoped APIs
IndexFlow.Domains.get!(customer_id, id)
IndexFlow.Sitemaps.list(customer_id)

# System APIs  
IndexFlow.Domains.Internal.get!(id)
IndexFlow.Sitemaps.Internal.bulk_update_status(ids, status)

I want this because the app is both end-user facing plus has batch jobs running on schedules. Those jobs need full access across all customers. But queries done on behalf of a customer need to be scoped to them. I want to make it obvious to me (and the default) when I’m more secure.

Now, as far as locating this code? I’ll probably create /domains/intrernal.ex, etc. I do dislike that this will be alongside my schema files, yet it’s a context. But my module files are getting way too big as it is…

Anyone else tackle this?

Showing Posts 1 to 3

kokolegorille

kokolegorille

I use a different endpoint for admin purpose… mostly because of client request to have a clear separation with public facing endpoint.

But my core logic stays the same.

camatcode

camatcode

I’m not saying this is a great solution for you, its just one I’ve used in an absurdly secure environment - in case it helps.

HTTP call → Service Layer → Broker Layer → Data Layer

  • Service layer checks that its a sane call (auth happened correctly, nothing fishy about the request) and passes it onto the Broker layer. It might format result for a particular purpose.
  • Broker layer checks that the caller is allowed to make that call, has proper access to see that data, etc, and executes queries/commands against the Data Layer.
  • Data Layer - think Repo calls.

Third-parties use the Service Layer, Processes use the Broker Layer.

sodapopcan

sodapopcan

I always pass the current Scope as the first argument to these functions (could also be the current User) and dispatch based on authorization rules.

— All posts loaded —

Where Next? Top

Trending in Discussions Top

AstonJ
As the title says, please share what you’ve been up to with Elixir. Whether that’s been learning it, looking into it, making stuff with i...
2977 91898 914
New
AstonJ
The obligatory hello world thread! Who are you and where are you from? :stuck_out_tongue:
4616 55835 594
New
byu
@chrismccord : I just saw the Extract AGENTS.md from Phoenix.new into phx.new generator commit to the phoenix project. My initial shotgu...
New
arcanemachine
I was working on an Ecto migration and I needed a timestamp. So, for the nth time, I looked up the different data types for timestamps, a...
New
alexslade
Fly’s CEO posted this recently - Turn And Face The Strange · The Fly Blog It says that Fly is going all-in on sprites, which is a worry ...
New
Herve37
We’re evaluating API mocking tools for OpenAPI-based projects and would love to hear what other teams are using. We’re particularly inte...
New
matt-savvy
Is there a word for the ~> symbol used in Version strings? Do you also just call it a Squiggle Arrow™ ?!
New

Other Trending Topics Top

JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
Damirados
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge & Solve. They are GUI (Emerge) and State management (S...
New
netoum
Corex is an accessible, unstyled UI component library for Phoenix that integrates Zag.js state machines using Vanilla JavaScript and Live...
New
ausimian
Emily is an Elixir library that runs Nx computations on Apple’s MLX. Install it as the default Nx backend and Nx, defn, Axon, Nx.Serving,...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews