richjdsmith
I was hoping to discuss the merits between the two libraries. I’ve been comparing them for a greenfield project and as someone new to Elixir and Phoenix, I am struggling to see any major difference between them.
Things I see they share in common:
- Both appear to be primarily front-end (not API) based - more for web apps versus API serving apps.
- Both appear to be somewhat opinionated on context design.
- Both have installers and seem straightforward to implement.
- Both have both Authentication and Authorization built in.
Differences:
- Phauxth seems to be more actively developed? Perhaps it is because it is because Phauth is newer or because the lead dev for Coherence is just tied up, but Coherence has had a security flaw open since August on github, whereas Phauxth seems to be regularly worked on by its maintainer.
- Phauxth is significantly less popular than Coherence.
But I don’t know. As stated, I’m still a pretty darn Jr dev. I’m curious to get opinions from the community? I’m certainly not trying to pit them against each other - I appreciate any and all work done within this community as well as the OSS community in general! I’m just hoping to get someone to explain the differences so I or anyone else who sees this can choose the best option for their specific needs.
Thanks all! ![]()
Trending in Discussions
As the title says, please share what you’ve been up to with Elixir. Whether that’s been learning it, looking into it, making stuff with i...
New
The obligatory hello world thread!
Who are you and where are you from? :stuck_out_tongue:
New
I want to open this thread for you all to discuss and help those who really like Ash but are still hesitant to use it in a real project. ...
New
I was working on an Ecto migration and I needed a timestamp. So, for the nth time, I looked up the different data types for timestamps, a...
New
Fly’s CEO posted this recently - Turn And Face The Strange · The Fly Blog
It says that Fly is going all-in on sprites, which is a worry ...
New
We’re evaluating API mocking tools for OpenAPI-based projects and would love to hear what other teams are using.
We’re particularly inte...
New
Is there a word for the ~> symbol used in Version strings?
Do you also just call it a Squiggle Arrow™ ?!
New
Other Trending Topics
Hobbes is a low-level distributed database for the Elixir programming language.
Hobbes provides a simple, safe, and scalable storage lay...
New
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge & Solve.
They are GUI (Emerge) and State management (S...
New
Corex is an accessible, unstyled UI component library for Phoenix that integrates Zag.js state machines using Vanilla JavaScript and Live...
New
There are three potential reasons for members of this forum to have a look at https://vutuv.de
You are tired or annoyed of LinkedIn.
Yo...
New
Aludel - LLM Evaluation Workbench
Aludel is an embeddable Phoenix LiveView dashboard for evaluating and comparing LLM prompts across mult...
New
Latest Phoenix Threads
Latest on Elixir Forum
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #deployment
- #library
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #javascript
- #podcasts
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixir-ls
- #blog-post
- #ai
- #phoenix_html
- #elixirconf-us
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #hex
- #security
- #metaprogramming











Showing Posts 1 to 5- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
richjdsmith
(I deliberately kept Guardian/Uberauth out of the discussion because they really are in their own category - more of a “batteries not included” sorts of packages. Not an issue with that, just not something I am interested in at this point.)
LostKobrakai
Phauxth does not include authorization. It just gives examples on how to implement in it on top of phoenix and phauxth in userland.
OvermindDL1
As I recall coherence has only authentication, not authorization.
As for phxauth, I’ve not looked closely enough at it yet but I recall it doing only the absolute basics of authorization, not enough to really be useful except in the most basic of cases?
Phxauth is newer, hence more development and less usage thus far.
Personally neither are really a fit for what I need to do (API auth, non-local auth like oauth2 and so forth, in addition to needing detailed permission control for authorization).
Guardian is ‘mostly’ just JWT, useful in remote API’s, not in a local authentication system.
Uberauth is purely an authentication library, fantastic for front-end and back-end both, less useful than coherence for purely local logins, but absolutely fantastic for remote logins (like oauth2, ldap, whatever), doesn’t come with templates (which I actually prefer libraries not to come with).
Good to know, so yeah both phxauth and coherence are purely authentication (and coherence is local only, I think phxauth has ‘some’ remote auth support?).
richjdsmith
@riverrun or @smpallen99 are you able/willing to chime in?
riverrun
Hi, I’m the maintainer of Phauxth, and it’s nice to see a little bit of interest in it
I don’t really know enough about coherence to comment on it, so I’ll just make a few points about what I’m trying to achieve with Phauxth:
verify/3functions, which are called like normal functions (with params, context module and options as arguments).For more information, see this blog post or the Phauxth wiki.
If anyone has any questions, just let me know.