wernerlaude

wernerlaude

I use {:phauxth, “~> 1.2”}
authorize.ex

Works great for User, but checking a “belongs_to” controller with a user_id, this seems to not work out of the box.

in my controller

plug :id_check when action in [:show]

..

def show(%Plug.Conn{assigns: %{current_user: user}} = conn, %{"id" => id}) do
  angebot = Projects.get_angebot!(id)
  render(conn, "show.html", angebot: angebot)
end

kicks me out.
should check ..current_user.id==user_id
Tried a lot but no success..any idea?
Could find Info..
Thanks

Showing Posts 1 to 3

joaoevangelista

joaoevangelista

I used phauxth in a prototype, it does not provide such functionality, what id_check does is only to see if the given id on a path is the same of the current user.

You need to load the resource before it happens and usually in a controller that is not what happends, so what you could do is:

  • Use phauxth to check if there is authenticated user
  • Use some authorization lib to match the fields

I used Bodyguard and plays really nice, you just need to load the resource first and get the user, then you pass this context to your permit and get a result, you can do really fine grained authorization using simple pattern matching

joaoevangelista

joaoevangelista

A policy example

defmodule App.AngebotPolicy do
  @behaviour Bodyguard.Policy

  def authorize(:show, %{id: user_id}, %{user_id: user_id}), do: :ok
  def authorize(_action, _user, _resource), do: {:error, "Get off my lawn!"}
end
defmodule MyController do
  plug :user_check when action in [:index, :show]
  # ....
  def show(%Plug.Conn{assigns: %{current_user: user}} = conn, %{"id" => id}) do
  angebot = Projects.get_angebot!(id)
  with :ok <- Bodyguard.permit(AngebotPolicy, :show, user, angebot) do
    render(conn, "show.html", angebot: angebot)
  else
  # do something  to alert the user
     {:error, reason} ->
       conn
       |> put_flash(:error, reason)
       |> redirect(to: page_path(conn, :index)
  end
end

end
wernerlaude

wernerlaude OP

Thanks for support.. I will check that..looks good

— All posts loaded —

Where Next? Top

Trending in Questions Top

RSP87
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
nseaSeb
Hello, I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
RemyXRenard
I’m seeing that a list inside a Kino.DataTable will be interpreted as a charlist, even if the Kino.configure() is set to charlists: :as_l...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
samoloth
Hi, I’ve just set up an application with ash_authentication. There is only magic link strategy for now, so there is no confirmation add o...
New
FlyingNoodle
If a change or preparation module uses Ash.Changeset.get_argument/2 or Ash.Query.get_argument/2 (or any of the other get_argument functio...
New

Other Trending Topics Top

JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews