smon
Let’s me start out with a new project based on generators:
Using mix phx.gen.live gives me form_component.ex, index.ex and show.ex for my schema. The latter two use the form_component.ex as a modal:
<.modal :if={@live_action in [:new, :edit]} id="project-modal" show on_cancel={JS.patch(~p"/projects")}>
<.live_component
module={DemoWeb.User.FormComponent}
id={@user.id || :new}
title={@page_title}
action={@live_action}
project={@user}
patch={~p"/userss"}
/>
</.modal>
or
<.modal :if={@live_action == :edit} id="project-modal" show on_cancel={JS.patch(~p"/projects/#{@project}")}>
<.live_component
module={DemoWeb.ProjectLive.FormComponent}
id={@project.id}
title={@page_title}
action={@live_action}
project={@project}
patch={~p"/projects/#{@project}"}
/>
</.modal>
Now I am having a look at mix phx.gen.auth and was wondering how I could restrict only the modal usage (both :new and :edit) to registered users.
Ideas so far:
- Create a standalone live view
form.exand replaceform_component.ex. But then I can not use it inside a modal (?). This way I could set authorization in myrouter.ex. - Add a check in the relevant
apply_action/3inindex.exand use the same pattern inshow.ex? - Add checks to both existing live views:
.modal :if={@live_action in [:new, :edit] and @current_user}in the heex? - Pass the
:current_userto the live component and let the live component handle the check?
I would prefer to handle this in the router.ex, just because then all restriction related logic would be defined at one point.
Any other ideas?
Trending in Discussions
I am happy to introduce the very α version of the new programming language compiled to BEAM.
Welcome Cure.
It has literally three kille...
New
A little off-topic, but I feel like people here have a good head on their shoulders.
I used to be quite good at making software. Was luc...
New
Hi there! :wave:
@frigidcode and I (but mostly him) have been running an Elixir Book club, we’re almost done with Designing Elixir Syste...
New
I’ve been using Emacs as my main code editor for more than a two years. It’s a custom build version although I’ve tried doom emacs and sp...
New
I love Elixir. It’s one of 2 programming languages I’ve ever fallen in love with.
But I don’t use it anymore.
Serverless was the promis...
New
Lately I’ve been thinking about how to organize components as a LiveView application grows. One of the pain points I’ve found (for myself...
New
What IDE or editor are you using for Elixir development?
Personally, I use Zed, and I really like it, but sometimes I wish there were a ...
New
Other Trending Topics
Edit: 2026 May 15 - This post is archived.
Mob is alive!!
Main docs: mob v0.7.11 — Documentation
A bit of explanation for the slightly c...
New
Hobbes is a low-level distributed database for the Elixir programming language.
Hobbes provides a simple, safe, and scalable storage lay...
New
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
With AI doing more of the implementation work, I’ve been wondering how much coding I should deliberately keep doing myself.
My main conc...
New
Just published claude-code-elixir, a plugin marketplace for Claude Code with Elixir support. These are the plugins I’ve been using for my...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ai
- #ecto-query
- #elixirconf-us
- #blog-post
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #elixirconf-eu
- #api
- #forms
- #metaprogramming
- #hex










Showing Posts 1 to 6- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
LostKobrakai
The modals in the default boilerplate have separate routes. Add authorization to those.
smon
How would you do that from the router?
The generated authentication logic seems only to check “on_mount” for live views and the initial “dead view” requests. If a guest user is on the
:indexroute (i.e. successfully mounts the view) and then switches to the edit route which is supposed to be restricted, they still use the same live view process, there is nomountcall anymore and there is no second evaluation happening.LostKobrakai
You could switch the patch to be a proper redirect. More expensive on resoure loading, but giving you another mount.
smon
Ah, right - the patching in my links was what confused me.
Instead of switching all patches to redirect I would simply render those links only if current_user is set? I am still struggling to evaluate where I might run into security issues with the LiveView Javascript magic.
codeanpeace
Definitely ensure that the
handle_eventcallback for the form submission/save event checks for authorization – in your case, that the user is registered.Events Consideration | LiveView Security considerations
krasenyp
I’d hide all the actions which the current user can’t perform.