codez

codez

A project I am working on now has strong security requirements. Therefore I would like to have a layered approach that provides guard-rails at several levels. In the past I did development with the Python based Zope application server. This server has the notion of traversal.

Traversal is an alternative to pattern based routing. This cuts the URL into path components and then looks up an item from the database. It then uses that to traverse to the second path component and so on until the components all are processed.

The nice thing about this traversal concept is that it allows for authorization checks to be applied during the traversal phase. This can make sure that it would be impossible to access sub-paths if access is denied at a higher level.

I think I can replicate this concept in Phoenix. What I am wondering about is if this makes sense or if there are better options to do this kind of thing. As a concrete example of an URL:

/organizations/mega-corp/projects/secret-X/tools/profitinator/...

This could also be modelled (with traversal) as:

/organizations/mega-corp/secret-X/profitinator/...

I’m fine with either of those, just interested in the security aspect. With traversal (in both versions) it would be possible to limit access to sub-paths of mega-corp to employees. A similar thing can be done when traversing secret-X and so on.

For more background on the traversal mechanism in Python based frameworks:

https://morepath.readthedocs.io/en/latest/security.html

Showing Posts 1 to 1

LostKobrakai

LostKobrakai

This is not how Plug.Router nor Phoenix.Router work. They’re so fast in matching routes exactly because they harness plain old pattern matching below the hood. This is not to say you cannot get the same level of security from them. With scopes and pipelines you can prevent access in a similar manner. Only the router won’t be able to resume matching if being prevented from access for an previously matched route.

You can also build a custom router. In the end routers are just plugs, which receive a conn and some opts and dispatch to controllers, which also are just plugs (MyController.call(conn, action)). But keep in mind that this will likely mean you cannot use phoenix liveview. It’s deeply integrated with the router level.

— All posts loaded —

Where Next? Top

Trending in Questions Top

RSP87
I’m working on a project that simulates the bumbl example in the programming phoenix book. It acts almost like an email client. We have a...
New
kszambelanczyk
Hello! Could someone please give me a help/sample code, how to delete a file from s3 using waffle/waffle_ecto from Phoenix app. I creat...
New
RemyXRenard
I’m seeing that a list inside a Kino.DataTable will be interpreted as a charlist, even if the Kino.configure() is set to charlists: :as_l...
New
velrest
So my question is quite simple and i have found no conclusive answer on forum, google or AI. Should we use :erlang.float for Integer to ...
New
samoloth
Hi, I’ve just set up an application with ash_authentication. There is only magic link strategy for now, so there is no confirmation add o...
New
FlyingNoodle
If a change or preparation module uses Ash.Changeset.get_argument/2 or Ash.Query.get_argument/2 (or any of the other get_argument functio...
New
ryanwinchester
apply_graft/2 doesn’t rewrite an add_many sub-workflow’s deps on an add step. Grafted jobs cancel with “upstream job was deleted” Version...
New

Other Trending Topics Top

mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New
Damirados
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge & Solve. They are GUI (Emerge) and State management (S...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews