danschultzer

danschultzer

Pow Core Team

None of the current solutions worked well for me, so I went ahead and built a user management system from scratch.

This project took far longer than I initially thought, and I would love to get some help to iron out everything. So please try it out and let me know what you think!

https://github.com/danschultzer/pow
https://hexdocs.pm/pow/

The latest release is a pre release version, but it is running in a production environment (we went away from a Coherence setup).

So what does Pow do (differently)?

Functional configuration

A huge issue with most libraries is the dependency on a global environment configuration. It becomes especially messy when dealing with umbrella apps. Pow handles configuration by passing it as an argument to all method calls (and with plug it’s passed in a private key). There’s also fallback to app-specific environment configuration by using :otp_app like Ecto/Phoenix.

Plug n’ play

Pow exposes only necessary files. It means that even views and templates for Phoenix aren’t generated unless required for customization.

Modular

Pow has been build with clear separation between Ecto, Plug, and Phoenix modules, so if/when deep customization is necessary, you can pull out any part and work with it.

Extendable

Out of the box, Pow does basic user and session management. But Pow has been made to be easy to extend. A reset password, email confirmation and remember me extension ships with it! Extensions are built as a separate system to keep the core of Pow lean and easy to understand.

Security

When working with user authentication, there can be many pitfalls. That’s why your user authentication library should do as much of the work as possible, so you don’t have to think about it. Pow is built with care for recommended best practice, and detailed in the readme.

Transparent

Pow attempts to give the developer full control and understanding of the API for Pow. For example, when you install pow, you’ll have to enable extension support yourself, so you understand the working parts. This it to remove as much “magic” as possible.

And a whole lot more

Showing Posts 241 to 232

spurgus

spurgus

Hi, first of all, thanks for creating this auth library.

Is it still maintained? I’ve seen there hasn’t been a release for more than a year ago and it’s no longer compatible with the latest Phoenix versions. There are PRs for that but seem abandoned.

Thanks!

Kurisu

Kurisu

Hello @danschultzer,

The guide on user roles and authorization through a Plug is great for keeping users from accessing restricted pages but sometimes we would want more radical methods. For example in an umbrella project, I don’t want front_app users to be authenticated when trying to login through the admin_app page.

So I added a custom authenticate method to the admin users context:


@doc """
  Ensure that only admin can be authenticated
  """
  def authenticate(params) do
    user = pow_authenticate(params)

    case user do
      %{role: "admin"} -> user
      %{role: "superadmin"} -> user
      _ -> nil
    end
  end

Maybe there is a better/recommended way to achieve this?

Kurisu

Kurisu

Fortunately erasing the .elixir_ls folder and let it be rebuilt made the warning gone. Thanks.

NobbZ

NobbZ

The LS uses a bundled/vendored version of dialyxir, just to translate errors that have been found by dialyzer into elixir syntax.

If you want to run dialyzer from the terminal on your own, you will need to add the dialyxir package as a :dev dependency to your project.

A “has no local return” is often hard to debug and can require knowledge of the full program context and its libraries. More than often, this errors origin was in a library that had some types of its own wrong, or a NIF-stub was not set up correctly.

Kurisu

Kurisu

Thank you all for your replies and for your time.

I think the issue has nothing to do with Pow. I just replaced the LoadProfilePlug with another Plug code that does not show any warning in its original context, and the warning remains in the LoadPlugProfile. That is to say no matter the code I put in it, the warning remains. The issue comes probably from the outside of the Plug, maybe because of how I call it? I will be checking that.

I feel really sorry for wasting you some time on this.
Thanks

Kurisu

Kurisu

I’m using the vscode extension and it’s marked ElixirLS v0.5.0.

I’m working in an umbrella project and running mix dyalizer at the root of the umbrealla or in its child app shows:

** (Mix) The task “dyalizer” could not be found

Should I add any dependency?

My initial warning message
Function call/2 has no local return.ElixirLS Dialyzer
is shown only in vscode editor. When compiling the project in terminal and running Phoenix server I don’t see any warning. I have to say also that I just installed the ElixirLs vscode plugin but didn’t add any configuration.

danschultzer

danschultzer OP

Pow Core Team

What version of ElixirLS are you using? I just tested with the plug and it doesn’t print any dialyzer warning for me (I also ran mix dialyzer just to be sure.). Using ElixirLS 0.2.25.

NobbZ

NobbZ

no_return means, this function will never return.

Never returning means, it will recurse infinitely.

Raising is always allowed, you do not need to annotate it, we are not doing Java here.

Dialyzer will never complain about a raise here or there, as long as it can proove you will return a value of the correct type at least sometimes.

It will complain though, if it does not find a way to properly return a value of the correct type, it will tell you something like “function foo does not have a local return”.

Just adding no_return as one of the possible return types, tells dialyzer “ignore everything else, this function does not return ever”.

So instead of just adding no_return you should think about if that is right, and why dialyzer might think it is that way and then fix the code.

Schultzer

Schultzer

I’m not an expert on dialyzer at all, but in the past when I had dialyzer warnings with any function that could raise then ‘no_return()’ has always worked.
But there might be a specific type that encapsule a function that would raise on error or return a value?

I’m intrested in hearing how you have solved these dialyzer warnings on function no_return?

NobbZ

NobbZ

no_return | … doesn’t make sense.

Either a function is no_return or it is not. But it can’t be both.

Where Next? Top

Trending in Announcing Top

type1fool
WebAuthnLiveComponent WebAuthnComponents See this post about renaming the package. Passwordless authentication for Phoenix LiveView app...
New
GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
woylie
I released Doggo, a collection of unstyled Phoenix components. https://github.com/woylie/doggo Features Unstyled Phoenix components....
New
ahamez
Hi everyone, I’ve been working on this protobuf library for 3 years. We use it in the company I work for, EasyMile, to communicate with ...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
kip
I’ll shortly be launching Text, a nascent text analysis library. Current functionality In this early version (not ready for prime time) ...
New
kip
Following on from my CLDR lbraries I started work on Unicode transforms. But like everything related to CLDR there is a lot of yak-shavin...
New

Other Trending Topics Top

budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New
KristerV
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
juhalehtonen
There has been a thread to discuss the Stack Overflow Developer Survey on this forum every year since 2018, so here’s yet another one for...
New
budgie
I love Elixir. It’s one of 2 programming languages I’ve ever fallen in love with. But I don’t use it anymore. Serverless was the promis...
New
Null-logic-0
What IDE or editor are you using for Elixir development? Personally, I use Zed, and I really like it, but sometimes I wish there were a ...
New
type1fool
I just stumbled on a newly redesigned elixir-lang.org. :tada: It looks like @Software_Mansion did the work, and I think it is generally a...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews