marcin

marcin

Hi!

I am just looking for a simple :crossed_fingers: way to sign in users from GitHub and GitLab.
I am using Phoenix 1.6, so my go to auth base is phx.gen.auth.
How to add oauth to this?

I found a post from 2021, suggesting to use Ueberauth.
Trying it out: ueberauth version 0.10 and ueberauth_github 0.8 – i instantly discover that ueberauth_github requires ueberauth 0.7 (very old release) and will not work with a recent one. So something :fish:y is going on here – the same team maintains these two packages, but plugins lag behind big time.

The other battle tested options is to use POW. However, AFAIK pow replaces phx.gen.auth, so might be an overkill to use with recent phoenix.

When I check both project repositories, both have low commit frequency in last year. Are they finished and complete and this is why contributions are low?

Perhaps there is some other package that you currently use with phx.gen.auth?

I’ll be grateful for pointers!

Marcin

Showing Posts 1 to 10

josevalim

josevalim

Creator of Elixir

Also take a look at assent from the awesome @danschultzer: GitHub - pow-auth/assent: Multi-provider framework in Elixir · GitHub

If you integrate it with mix phx.gen.auth, consider writing an article or even a guide for the project if one does not yet exist (and check if Dan would accept it).

13
Post #1
marcin

marcin OP

Thank you for the tip! Do I understand correctly I can use pow-auth/assent directly with phx.gen.auth (and it’s schemas) without using pow at all (indeed assent does not list pow as dep)?

josevalim

josevalim

Creator of Elixir

That’s also what I understand but I am not 100% sure!

derek-zhou

derek-zhou

I use ueberauth 0.7. There is nothing wrong with using stable software.

al2o3cr

al2o3cr

I’m not sure if those are two things that should be used together - a lot of the machinery produced by phx.gen.auth is focused on hashed password maintenance, which is specifically the thing that an Oauth-based auth system doesn’t need.

LostKobrakai

LostKobrakai

It also brings a lot of machinery to properly handle user sessions, which is exactly what oauth systems usually don’t bring (or vastly overengineer). I’ve stripped pw handling out of phx.gen.auth successfully in the past and it’s great to have the option to add the removed code back in when needed.

Also the code for account confirmation can be useful depending on how things should work.

marcin

marcin OP

Nothing wrong with stable software! Although with some disruptions like Phoenix implementing auth, some software might become unsupported

marcin

marcin OP

I also want to support oldschoold password accounts, for people who shun big platforms.

Schultzer

Schultzer

Yes, Assent is independent of Pow, I use it to fecth resources from a bunch of diffrent APIs with the Oauth2, Oauth1 and some custom strategies.

Futhermore, PowAssent uses Pow and Assent to combine User/Session with differnt authorizing stragegies.

I hope this clarifies it for you.

danschultzer

danschultzer

Pow Core Team

As already said, Assent doesn’t require Pow/PowAssent. It’s a low-level multi-provider framework abstracting away OIDC, OAuth 2.0, and OAuth 1.0. The only dependencies are related to JWT parsing and HTTP client (I strive to keep a minimal dependency graph). PowAssent is build on top of it, and deals with all the complexity of user registration.

I know you said you are going to support password, but for anyone else wanting to do something like this and only want provider authentication I would recommend not using phx.gen.auth or Pow at all. You can just add the user info to the signed/encrypted session cookie (with an expiration timestamp!) or use a JWT when succesfully authenticating, and store whatever provider was used as a cookie. When the session info/JWT expires just redirect to the provider again to reauth. The less surface you add, the better for security.

Finally as for Pow, it’s a complete package. I’m planning a larger rewrite of how it works to improve observability and also have built-in LiveView support. I’m currently updating Pow to support Phoenix 1.7 with all the breakling changes 1.7 introduces.

Unfortunately only got so much time to maintain my open source projects :slight_smile:

Where Next? Top

Trending in Questions Top

katta
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
brecabral
Documentation While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
achenet
Hello, I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind. However, when I launch mix phx.server, I get an error...
New
kpanic
Hi everyone, I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding. I sta...
New
Cxx-mlr
I’m working on a small exercise involving update_in/3, and I came up with this solution: data = %{ name: "Periodic Table", category:...
New
ChrisAmelia
I’ve got trouble wrapping my head around the order in which functions are called in this snippet (from Phoenix’s authentication): toke...
New
dillonoconnor
Is there any way to avoid the Hologram compiler running when using iex? It seems like the front-end code could potentially be disregarded...
New

Other Trending Topics Top

GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New
KristerV
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
mcass19
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews