kamaroly
How can I set the actor globally after the user successfully logs in, so that I don’t have to pass actor in every query.
Here 's what I did so far. It works if I manually set actor while querying, but it does not work with the actor set in the plugs.
I added set_actor in the Phoenix router plugs like the following
defmodule KamaroWeb.Router do
use KamaroWeb, :router
use AshAuthentication.Phoenix.Router
import AshAuthentication.Plug.Helpers # <-- ADDED THIS
pipeline :browser do
plug :accepts, ["html"]
plug :fetch_session
plug :fetch_live_flash
plug :put_root_layout, {KamaroWeb.Layouts, :root}
plug :protect_from_forgery
plug :put_secure_browser_headers
plug :load_from_session
plug :set_actor, :user # <-- ADDED THIS LINE
end
I inspected and indeed confirmed that the actor is being set in the connection privates.
However when I inspect the actor from the Policy, it is nil.
defmodule Kamaro.Checks.Can do
use Ash.Policy.SimpleCheck
def describe(_opts) do
"Check if a user/ actor has permission on a specific resource"
end
def match?(actor, context, opts) do
dbg(actor) # <-- ACTOR IS NIL HERE
{:ok, true}
end
end
But, when I query by passing the actor like the following, the actor is not nil.
Stock.get_categories!(actor: user)
Here is how the resource policy is configured
policies do
policy action_type(:read) do
authorize_if Kamaro.Checks.Can
end
end
Trending in Questions
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
Documentation
While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
Hello,
I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind.
However, when I launch mix phx.server, I get an error...
New
Hi everyone,
I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding.
I sta...
New
I’m working on a small exercise involving update_in/3, and I came up with this solution:
data = %{
name: "Periodic Table",
category:...
New
I’ve got trouble wrapping my head around the order in which functions are called in this snippet (from Phoenix’s authentication):
toke...
New
Is there any way to avoid the Hologram compiler running when using iex? It seems like the front-end code could potentially be disregarded...
New
Other Trending Topics
Edit: 2026 May 15 - This post is archived.
Mob is alive!!
Main docs: mob v0.7.11 — Documentation
A bit of explanation for the slightly c...
New
I am happy to introduce the very α version of the new programming language compiled to BEAM.
Welcome Cure.
It has literally three kille...
New
Hobbes is a low-level distributed database for the Elixir programming language.
Hobbes provides a simple, safe, and scalable storage lay...
New
A little off-topic, but I feel like people here have a good head on their shoulders.
I used to be quite good at making software. Was luc...
New
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ai
- #ecto-query
- #elixirconf-us
- #blog-post
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #elixirconf-eu
- #api
- #forms
- #metaprogramming
- #hex










Showing Posts 1 to 5- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
zachdaniel
It is (intentionally) not possible to do this. You have to pass the actor to each call.
kamaroly
Thank you for the clarification @zachdaniel.
spacebat
What is the intent behind that design decision? I can see points on both sides.
Benefits of explicit passing:
Benefits of a global actor:
zachdaniel
We had this feature in 2.0, and ultimately removed it due to the multitude of footguns that presented themselves. Two such examples:
Code is no longer portable across processes
Given that many things that exist in the elixir ecosystem take a callback which will (or may or may not at the discretion of whats being called) run in another process, design that depends on the process context for security can be very problematic. Even something simple like using some
Task.asyncto parallelize a few read actions risks introducing very non-obvious security bugs.Actions calling other actions
Given this example:
If you do this:
the call to
Comment’s:createaction does not receive an actor.But if you do
now the call to create a comment sees the process context actor and uses it. This is especially problematic because when you are writing logic in hooks, you are encapsulating logic, and the ability for some external source to make changes to how changes/hooks in your action run is very dangerous.
When we talked about removing it, we brought the above two things up, and got conflicting feedback that was especially illustrative of why this had to be removed.
Some people were upset to discover that
Ash.set_actorset the actor in hooks as well, and realized there were likely bugs in their code.But also, some people were relying on that behaviour, and saw it as a feature.
Leading up to Ash 3.0, the major design epic was missing major pieces in Ash core, specifically bulk actions and atomics. But the theme of changes made post 3.0 is less surprises/sharp edges and better developer experience, and the removal of the process dictionary features is more in line with those goals.
It may be more annoying, but without the process-dictionary features, your code does exactly what it looks like it does.
spacebat
Well put, thanks.