sezaru

sezaru

I’m upgrading my project from Ash 2 to Ash 3.

One thing that I saw is that the token policies should be like this:

  policies do
    bypass AshAuthentication.Checks.AshAuthenticationInteraction do
      authorize_if always()
    end

    policy always() do
      description """
      There are currently no usages of user tokens resource that should be publicly
      accessible, they should all be using authorize?: false.
      """

      forbid_if always()
    end
  end

If I leave like that, my sign_in_with_password action will fail when run from graphql:

[error] Core.Marketplace.Accounts.Token.read


Policy Breakdown
  Actor: %{active?: true, confirmed_at: ~U[2024-09-11 16:29:09.372093Z], roles: [:guest]}

  There are currently no usages of user tokens resource that should be publicly
accessible, they should all be using authorize?: false.
 | ⛔:
    condition: always true    
    forbid if: always true | ✓ | ⛔

If I replace the token policy with this:

  policies do
    bypass AshAuthentication.Checks.AshAuthenticationInteraction do
      authorize_if always()
    end

    # sign in needs token access
    policy always() do
      authorize_if always()
    end
  end

Now it works, but I’m not sure if this is correct.

Showing Posts 1 to 4

zachdaniel

zachdaniel

Creator of Ash

Can I see your :sign_in_with_password action? Are you manually defining it or using the default?

sezaru

sezaru OP

I’m using the default

zachdaniel

zachdaniel

Creator of Ash

@jimsynz this is a strange one. If the user has access to the sign_in_with_password action, shouldn’t the internals that call token actions set the context that its ash authentication performing the action?

jimsynz

jimsynz

Ash Core Team

I can’t see anywhere where it’s not set. Are you still seeing this? (I know you asked this a while ago).

— All posts loaded —

Where Next? Top

Trending in Questions Top

RSP87
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
nseaSeb
Hello, I know there is an approach for handling lists that allows for optimized traversal, but I can’t recall the specific method (somet...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
asweet-confluent
I recently noticed that Elixir’s Logger defaults its primary log level to :debug when no :logger, :level application configuration is pre...
New
ryanwinchester
apply_graft/2 doesn’t rewrite an add_many sub-workflow’s deps on an add step. Grafted jobs cancel with “upstream job was deleted” Version...
New

Other Trending Topics Top

JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
mhanberg
Hi everyone! The first release candidate for the Expert language server project is now available! We’ve published a press release detai...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New

Latest on Elixir Forum

Elixir Forum

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews