marcin
Hi!
I am just looking for a simple
way to sign in users from GitHub and GitLab.
I am using Phoenix 1.6, so my go to auth base is phx.gen.auth.
How to add oauth to this?
I found a post from 2021, suggesting to use Ueberauth.
Trying it out: ueberauth version 0.10 and ueberauth_github 0.8 – i instantly discover that ueberauth_github requires ueberauth 0.7 (very old release) and will not work with a recent one. So something
y is going on here – the same team maintains these two packages, but plugins lag behind big time.
The other battle tested options is to use POW. However, AFAIK pow replaces phx.gen.auth, so might be an overkill to use with recent phoenix.
When I check both project repositories, both have low commit frequency in last year. Are they finished and complete and this is why contributions are low?
Perhaps there is some other package that you currently use with phx.gen.auth?
I’ll be grateful for pointers!
Marcin
Trending in Questions
Other Trending Topics
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ai
- #ecto-query
- #elixirconf-us
- #blog-post
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #elixirconf-eu
- #api
- #forms
- #metaprogramming
- #hex











Showing Posts 1 to 10- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
josevalim
Also take a look at assent from the awesome @danschultzer: GitHub - pow-auth/assent: Multi-provider framework in Elixir · GitHub
If you integrate it with mix phx.gen.auth, consider writing an article or even a guide for the project if one does not yet exist (and check if Dan would accept it).
marcin
Thank you for the tip! Do I understand correctly I can use
pow-auth/assentdirectly with phx.gen.auth (and it’s schemas) without usingpowat all (indeed assent does not listpowas dep)?josevalim
That’s also what I understand but I am not 100% sure!
derek-zhou
I use ueberauth 0.7. There is nothing wrong with using stable software.
al2o3cr
I’m not sure if those are two things that should be used together - a lot of the machinery produced by
phx.gen.authis focused on hashed password maintenance, which is specifically the thing that an Oauth-based auth system doesn’t need.LostKobrakai
It also brings a lot of machinery to properly handle user sessions, which is exactly what oauth systems usually don’t bring (or vastly overengineer). I’ve stripped pw handling out of
phx.gen.authsuccessfully in the past and it’s great to have the option to add the removed code back in when needed.Also the code for account confirmation can be useful depending on how things should work.
marcin
Nothing wrong with stable software! Although with some disruptions like Phoenix implementing auth, some software might become unsupported
marcin
I also want to support oldschoold password accounts, for people who shun big platforms.
Schultzer
Yes, Assent is independent of Pow, I use it to fecth resources from a bunch of diffrent APIs with the Oauth2, Oauth1 and some custom strategies.
Futhermore, PowAssent uses Pow and Assent to combine User/Session with differnt authorizing stragegies.
I hope this clarifies it for you.
danschultzer
As already said, Assent doesn’t require Pow/PowAssent. It’s a low-level multi-provider framework abstracting away OIDC, OAuth 2.0, and OAuth 1.0. The only dependencies are related to JWT parsing and HTTP client (I strive to keep a minimal dependency graph). PowAssent is build on top of it, and deals with all the complexity of user registration.
I know you said you are going to support password, but for anyone else wanting to do something like this and only want provider authentication I would recommend not using phx.gen.auth or Pow at all. You can just add the user info to the signed/encrypted session cookie (with an expiration timestamp!) or use a JWT when succesfully authenticating, and store whatever provider was used as a cookie. When the session info/JWT expires just redirect to the provider again to reauth. The less surface you add, the better for security.
Finally as for Pow, it’s a complete package. I’m planning a larger rewrite of how it works to improve observability and also have built-in LiveView support. I’m currently updating Pow to support Phoenix 1.7 with all the breakling changes 1.7 introduces.
Unfortunately only got so much time to maintain my open source projects