dokuzbir

dokuzbir

This week i focus to web security. I read blogposts watch videos . As far as i know ecto queries protect us from SQL injection, changesets filters forms, phoenix sanitizes user inputs to prevent XSS. In additon to these never fetch a file from a url param, sanitize inputs in frontends too, never hardcode api keys… Elixir community has alot experienced developers what are some your advices or resources to help me learn more?

Showing Posts 1 to 10

aethereus

aethereus

See Securing Rails Application. I know it’s neither Elixir nor Phoenix, but the basic ideas about security are the same. You just need to implement these ideas with Elixir/Plug/Phoenix if they are not implemented by default.

blatyo

blatyo

Conduit Core Team

Make sure you don’t log sensitive things like passwords or PII. I added opt in logging for query parameters to Phoenix a while ago, where you have to be explicit about which things you allow to be logged.

config :phoenix, :filter_parameters, {:keep, ["id", "order"]}
AstonJ

AstonJ

Also don’t forget…

:023:

dokuzbir

dokuzbir OP

@aethereus rails guide is good thanks
@blatyo I never thought about logs, really important thing.
@AstonJ @griffinbyatt having a elixir library is really nice.

idi527

idi527

“Secure” distribution

If your app is distributed over multiple machines, make sure the nodes communicate over a secure channel like vpn (almost every cloud provider supports some sort of private networking) or tls [1, 2] (if you use several cloud providers for your app and it needs to keep a shared state).

[1] Erlang Distribution over TLS — OTP 29.0.2 (ssl 11.7.2)
[2] Erlang Consultancy and Development - Erlang Solutions

DDoS attack mitigation

or at least an attempt at

Check out [3] and [4]. Or, if you use haproxy (usually a good idea), maybe look into [5]. You can also use haproxy to terminate tls connections, since it would probably do a better job at it than erlang.

Note #1: if you do end up using haproxy for tls termination and/or load balancing, the general advice seems to be to pick a machine with a small number of high frequency cores [6].

Note #2: erlang, and by extension cowboy, are not particularly well suited for serving static assets, especially over tls on linux (freebsd seems to have some support for sendfile over tls [7]), so maybe pick nginx or h2o [8] for it.

[3] GitHub - michalmuskala/plug_attack: A plug building toolkit for blocking and throttling abusive requests · GitHub
[4] Ask HN: How is DDoS protection implemented? | Hacker News
[5] Application-Layer DDoS Attack Protection With HAProxy
[6] HAProxy version 1.8.30 - Starter Guide
[7] https://people.freebsd.org/~rrs/asiabsd_2015_tls.pdf
[8] https://h2o.examp1e.net/

“Secure” configs

Some cloud providers have tools like azure key vault [9]. But you can also host hashisorp vault [10] yourself. These are good for storing sensitive configuration information like database credentials and the like.

[9] https://azure.microsoft.com/en-us/services/key-vault/
[10] https://www.vaultproject.io/

blatyo

blatyo

Conduit Core Team

A good resource is OWASP. Here’s a checklist of good coding practices:

jakemorrison

jakemorrison

In addition to the application, there is a lot that you can do to add security when deploying it: Improving app security with the principle of least privilege

Phoenix’s ability to proxy connections efficiently allows some very interesting architectures for better security: Secure web applications with GraphQL and Elixir

coen.bakker

coen.bakker

Happily working my way through this thread and all the suggestions and resources posted in it.

It has been a few years since the last posts. Any new suggestions and resources for those of us (including me) that are trying to learn the ins and outs of applied web/Phoenix security in 2022?

pedromvieira

pedromvieira

We are migrating our SaaS application to LiveView and this documentation helped a lot.

https://hexdocs.pm/phoenix_live_view/security-model.html

In our case we use Guardian + Ueberauth.

AstonJ

AstonJ

Don’t forget to secure on a server level too, disable root login or use passwordless authentication, change SSH ports, block unused ports in your firewall, consider installing software like fail2ban/Denyhosts etc.

Usually your host will have tips/guides on how to do it for your OS, or they may even do a lot of it for you.

Where Next? Top

Trending in Questions Top

katta
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
achenet
Hello, I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind. However, when I launch mix phx.server, I get an error...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
Cxx-mlr
I’m working on a small exercise involving update_in/3, and I came up with this solution: data = %{ name: "Periodic Table", category:...
New
ChrisAmelia
I’ve got trouble wrapping my head around the order in which functions are called in this snippet (from Phoenix’s authentication): toke...
New
dillonoconnor
Is there any way to avoid the Hologram compiler running when using iex? It seems like the front-end code could potentially be disregarded...
New
thiagogsr
** (ArgumentError) expected :max_attempts to be a positive integer, got: {:@, [line: 10, column: 19], [{:max_attempts, [line: 10, column:...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New
KristerV
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews