hasmanyguitars

hasmanyguitars

I have a logger metadata plug (MyAppWeb.Plug.LoggerMetadata) that requires the following 2 plugs to run first in order to add the user_id to the metadata:

  • plug(:fetch_session)
  • plug(MyAppWeb.Auth.Pipeline) (which uses Guardian to fetch the user_id)

So I initially set up the endpoint.ex file to look like this:

  ....
  plug(:fetch_session)
  plug MyAppWeb.Auth.Pipeline
  plug MyAppWeb.Plug.LoggerMetadata
  plug(Plug.Logger)

  plug(MyAppWeb.Router)
  ...

It feels weird to have fetch_session and Auth.Pipeline in endpoint.ex as opposed to the router, though.

So I ended up moving those plugs back to the router.ex file like so:

...
pipeline :logger do
  plug MyAppWeb.Plug.LoggerMetadata
  plug(Plug.Logger)
end

pipeline :support_authentication do
  plug(MyAppWeb.Auth.Pipeline)
end

pipeline :browser do
  plug(:accepts, ["html"])
  plug(:fetch_session)
  plug(:support_authentication)
  plug(:logger)
  ...
end
...

This also feels weird because now we have to explicitly call the logger with each new pipeline such as api, ajax, etc.

I’m wondering if there are any drawbacks/gotchas with my first method or maybe if I’m missing some third option.

Showing Posts 1 to 2

hauleth

hauleth

Do you want that user_id be available in both messages of Plug.Logger? If yes, then unfortunately this is probably the only solution, if it is enough to have that message only in second message, then you can put Plug.Logger back to the endpoint.

christhekeele

christhekeele

The Endpoint is all about what is requisite for an HTTP request to connect to your service.

The Router is about which controller to connect to given certain request values.

The point of a pipeline is to sort of blur the difference in your Router (in a useful way!) with nuanced controls based on request metadata: you don’t want to deny the request outright, you just want to pre-process it (and maybe choose to reject it with an appropriate status code) based on processing.

In this lens, auth belongs in the pipelines in your Router. Where an Endpoint should refuse responses outright, you probably want your Router to return meaningful auth failure HTTP status codes to callers.

Specifically, you want to route a request to a particular unauthenticated response: definitely a Router concern. I think your idea of making auth support a discrete pipeline makes sense in this context.

— All posts loaded —

Where Next? Top

Trending in Questions Top

stjefim
Hello! Suppose you are building workflow (order / task / payment) processing system with the following requirements: Each workflow con...
New
jonnycharles
I’m in search of an Elixir library that offers PDF generation capabilities similar to Ruby’s Prawn. While there have been discussions abo...
New
spammy
I’m looking to build a personal workflow to quickly deploy web applications written in elixir/phoenix, for local consumption (ie not on t...
New
dli
Before I dive in myself, did anyone successfully sprinkle Hologram into their existing LiveView app? Looking for hints regarding: Addi...
New
roeland
Kia ora, We have been using elixir-google-api to connect to Google Drive. However, with the updates to Tesla due to CVEs this is now bro...
New
bottlenecked
Hi all, I wanted to ask how the community is dealing with post-release steps. Today we have Ecto migrations, which make sure that the db...
New
rahultumpala
Hello, I have an Elixir backend that implements a custom protocol over TCP. I want to load test the backend and assess the performance o...
New

Other Trending Topics Top

JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
Damirados
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge & Solve. They are GUI (Emerge) and State management (S...
New
netoum
Corex is an accessible, unstyled UI component library for Phoenix that integrates Zag.js state machines using Vanilla JavaScript and Live...
New
ausimian
Emily is an Elixir library that runs Nx computations on Apple’s MLX. Install it as the default Nx backend and Nx, defn, Axon, Nx.Serving,...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews