dave0

dave0

I’ve used mix phx.gen.auth to create an authentication system. Now the user session/reset password is part of the non-LiveView app while most authenticated points are “live”. The only exception is the UserSettings portion of the auth. I’d like these to be “live” as well.

The first thing I tried was moving the “update password” feature to live. So I made a LiveComponent to open a modal and, using phx-trigger-action, I can validate inside the LiveView component and then submit it to the UserSettingsController to handle clearing the session and re-logging in the user. Then it’ll kick me back to the live session.

This all works fine, but I can’t help wonder if there may be a security issue here.

  1. Is it safe to send the new password this way?

  2. When the form validates, it automatically clears the password fields. I then have to repopulate the values using socket.assigns before submitting over HTTP. Is there an issue with having the passwords in the assigns or manually set using the value attribute?

Showing Posts 1 to 2

f0rest8

f0rest8

I think you might find this thread helpful.

I’m not totally following your question but your change_password_component.html.leex (or equivalent) might look something similar to this:

<%= f = form_for @password_changeset, Routes.person_settings_path(@socket, :update_password),
        id: "form-update-password",
        phx_change: "validate_password",
        phx_submit: "update_password",
        phx_trigger_action: @password_trigger_action,
        phx_target: @myself %>
  ...
  <%= hidden_input f, :action, name: "action", value: "update_password" %>
  <%= password_input f, :password, value: input_value(f, :password) %>
  ...
</form>

I’ve stripped out a lot, but the input_value/2 from Phoenix.HTML needs to be set on your password field.

And you use the update/2 callback for Phoenix.LiveComponent in your change_password_component.ex file (or equivalent):

  @impl true
  def update(assigns, socket) do
    if socket.assigns[:current_person] do
      {:ok, socket}
    else
      {:ok,
       socket
       |> assign(:current_person, assigns.current_person)
       |> assign(:password_changeset, Accounts.change_person_password(assigns.current_person))
       |> assign(:current_password, nil)
       |> assign(:password_trigger_action, false)
      }
    end
  end
  ...

You’d also have handle_event/3 callbacks for "validate_password" and "update_password", or whatever you’d like to call those actions.

I’m planning to add another Medium post on switching the settings page over to a Live View page as a continuation of my other two posts (which you can find in the aforementioned thread), and I will update @slouchpie’s thread accordingly.

Hope this helps :heart:

dave0

dave0 OP

Thanks, that was very helpful. In the other thread, you mentioned how bytepack_archive also moved some stuff into LiveView and I was just looking at that archive. Great to know they’re doing the same things I was questioning in this thread.

— All posts loaded —

Where Next? Top

Trending in Questions Top

Blokh
Hey guys, I’ve got a huge CSV ( around 10 GB ) that needs to be processed hourly Do you guys have any suggestions what is the best prac...
New
kszambelanczyk
Hello! Could someone please give me a help/sample code, how to delete a file from s3 using waffle/waffle_ecto from Phoenix app. I creat...
New
RemyXRenard
I’m seeing that a list inside a Kino.DataTable will be interpreted as a charlist, even if the Kino.configure() is set to charlists: :as_l...
New
matt-savvy
Anyone here using Honeybadger? My Honeybadger account is being overwhelmed with noise from some bots. Seeing a lot of Bandit.HTTPError...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
samoloth
Hi, I’ve just set up an application with ash_authentication. There is only magic link strategy for now, so there is no confirmation add o...
New
FlyingNoodle
If a change or preparation module uses Ash.Changeset.get_argument/2 or Ash.Query.get_argument/2 (or any of the other get_argument functio...
New

Other Trending Topics Top

mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
Damirados
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge &amp; Solve. They are GUI (Emerge) and State management (S...
New
netoum
Corex is an accessible, unstyled UI component library for Phoenix that integrates Zag.js state machines using Vanilla JavaScript and Live...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews