Rich_Morin
Using Pow without Ecto or an RDBMS
Pow seems like a very nice, “batteries included” way to handle user authentication in Phoenix apps. However, some of the batteries it includes (e.g., Ecto, relational databases) aren’t a good fit for my project’s current design and development setup.
I’d like to be able to use Pow, but store the encrypted passwords (etc) in some TOML files I’m already using for user profiles. Can someone point me to documentation and/or examples for this sort of setup?
Most Liked
danschultzer
@dimitarvp is right, there’s no tight coupling so you should be able to get Pow working without Ecto or a DB. There are several ways to do it, but I would just set up a custom context and user module.
This is also how I unit test Pow so I’m not relying on Ecto/DB. The user module is necessary because it’s used to generate a changeset for the form, and to fetch the user id field dynamically for the form. Depending how your app works, you could also use the the user module to load the password from the TOML file on compile.
config :my_app, :pow,
user: MyApp.Users.User,
users_context: MyApp.Users
defmodule MyApp.Users.User do
defstruct email: nil, password_hash: nil
use Pow.Ecto.Schema
def changeset(user, _params), do: user
def verify_password(user, password), do: # Verify password here
end
defmodule MyApp.Users do
use Pow.Ecto.Context
def authenticate(_params), do: # Use params to look up user and verify password with `MyApp.Users.User.verify_password/2`
def create(_params), do: {:error, :not_implemented}
def update(_user, _params), do: {:error, :not_implemented}
def delete(_user), do: {:error, :not_implemented}
def get_by(_clauses), do: {:error, :not_implemented}
end
I imagine that since you use TOML files there will be no user create/update/delete, but only authentication. In that case, you should ensure that there is only the session controller. You can take a look at the context callbacks for specs.
You are the first person I’ve heard from that wants to use Pow in this way. I built Pow so it’s easy to decouple any group of modules (Ecto, Phoenix, Plug), but I would love to hear how it works in practice and if there’s something that can be improved. Please don’t hesitate to open any issues or PR on github ![]()
danschultzer
Quick update: I just released 1.0.8 today where there is no longer an expectation that @changeset is an Ecto.Changeset struct. This should make it easier for you to use Pow without Ecto ![]()
dimitarvp
Haven’t looked into most of Pow’s guts but I’d guess it’s not tightly related to a RDBMS; only to Ecto.
So if you find – or invent – a way to access those files through an Ecto interface then I’d expect Pow to work just fine after.
Last Post!
danschultzer
Hey, super sorry for the late reply, been overwhelmed with work lately.
Great point! Definitely makes sense to move the behaviour out of Pow.Ecto.Context.
And for anybody curious, it’s the operations module that glues the plug and context module together: pow/lib/pow/operations.ex at main · pow-auth/pow · GitHub
Edit: Created Move context behaviour out by danschultzer · Pull Request #503 · pow-auth/pow · GitHub thanks for the feedback ![]()
Popular in Questions
Other popular topics
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #deployment
- #library
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #channels
- #elixirconf
- #exunit
- #discussion
- #code-sync
- #javascript
- #podcasts
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixir-ls
- #phoenix_html
- #iex
- #blog-post
- #graphql
- #genstage
- #ai
- #websockets
- #supervisor
- #elixirconf-us
- #advent-of-code
- #distillery
- #processes
- #forms
- #api
- #metaprogramming
- #security
- #hex









