giusdp

giusdp

Hi everyone,

I’m finding myself kinda paralyzed over this issue of authenticating (signup/login) an user in my Liveview+Supabase project. Mostly due to where to put the access_token (and refresh) that supabase gives me.

Supabase offers its own auth system with an api on top for user registration/login, it uses JWTs. In my project I have an UserController that calls the login endpoint with the credentials provided. I’m unsure if this is a good approach cause here the client sends the credentials to the server, the server calls the supabase api and gets the access_token, then where to store this access_token?

I’m using ecto with supabase so it’s kinda seamless from using any other postgres db (which is awesome), but I’m stuck on how to use and store these access_tokens for future queries after I login.

Perhaps should I just ignore the auth system and do it myself with phx.gen.auth and create my own users tables on the supabase postgres?

Showing Posts 1 to 4

giusdp

giusdp OP

I’m thinking about just dropping the Auth api from supabase and use it as a pure Postgres DB with ecto. So I will just use phx.gen.auth for my auth system. At that point I’m not sure if it’s convenient to still use supabase instead of my own DB, but money-wise it seems it’s still better to use supabase. It has a free tier and a 25$ tier, while most hosting solutions cost way more to just reach the hardware in the 25$ tier.

conradfr

conradfr

I had recently the same question but with Firebase.

Where I’m at now is that I use Firebase only to log in the user (keeping it client side via a LiveView hook), verify the returned JWT at the backend level and then use Guardian and its own generated JWT to keep the user logged. That way I use Guardian plugs & helpers.

It’s a bit involved, especially as Phoenix doesn’t have built-in auth(s) support but it seems to work OK.

As for LiveView I stumbled upon “live_session” randomly and it’s useful. Read Live sessions in action · The Phoenix Files to know more.

To be honest if I only wanted to support email/password I would have probably used the (meh) Phoenix auth generator.

giusdp

giusdp OP

I think I was in the direction of your solution. After a day of confusion I thought about using the auth api on the client side and pass the access_token to the server, then use it somehow to authenticate the user in my app for the routes. I found out about guardian to do authentication as well. Then I backtracked and gave up on the auth api cause I was getting nowhere.

Knowing someone else went through the same problems and managed to make it work gives me confidence to try it again. So thanks for the reply! I think I will go the same route so I can take advantace of the social logins and so on.

Debian3

Debian3

Have you ever made progress on this? I feel like supabase auth have all the batteries included and I’m unsure how to integrate that with the gen.auth.

— All posts loaded —

Where Next? Top

Trending in Questions Top

katta
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
achenet
Hello, I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind. However, when I launch mix phx.server, I get an error...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
asweet-confluent
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
mnkhod
So i have been using ash framework for a while and i love it. However currently the issue im having with ash framework is the error handl...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews