Packages
ash_authentication_phoenix
2.4.3
3.0.0-rc.9
3.0.0-rc.8
3.0.0-rc.7
3.0.0-rc.6
3.0.0-rc.4
3.0.0-rc.3
3.0.0-rc.2
3.0.0-rc.1
3.0.0-rc.0
2.17.2
2.17.1
2.17.0
2.16.0
2.15.0
2.14.1
2.14.0
2.13.1
2.13.0
2.12.2
2.12.1
2.12.0
2.11.0
2.10.5
2.10.4
2.10.3
2.10.2
2.10.1
2.10.0
2.9.0
2.8.0
2.7.0
2.6.3
2.6.2
2.6.1
2.6.0
2.5.4
2.5.3
2.5.2
2.5.1
2.5.0
2.4.8
2.4.7
2.4.6
2.4.5
2.4.4
2.4.3
2.4.2
2.4.1
2.4.0
2.3.0
2.2.1
2.2.0
2.1.11
2.1.10
2.1.9
2.1.8
2.1.7
2.1.6
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0
2.0.2
2.0.1
2.0.0
2.0.0-rc.2
2.0.0-rc.1
2.0.0-rc.0
1.9.4
1.9.3
1.9.2
1.9.1
1.9.0
1.8.7
1.8.6
1.8.5
1.8.4
1.8.3
1.8.2
1.8.1
1.8.0
1.7.3
1.7.2
1.7.1
1.7.0
1.6.6
1.6.5
1.6.4
1.6.3
1.6.2
1.6.1
1.6.0
1.5.1
1.5.0
1.4.8
1.4.7
1.4.6
1.4.5
1.4.4
1.4.3
1.4.2
1.4.1
1.4.0
1.3.1
1.3.0
1.2.0
1.1.0
1.0.1
1.0.0
Phoenix integration for Ash Authentication
Security advisory:
This version has known vulnerabilities.
View advisories
Current section
Files
Jump to
Current section
Files
lib/ash_authentication_phoenix/strategy_router.ex
defmodule AshAuthentication.Phoenix.StrategyRouter do
@moduledoc false
@behaviour Plug
@impl true
def init(opts), do: opts
@impl true
def call(conn, opts) do
# ensure query params have been fetched
conn = Plug.Conn.fetch_query_params(conn)
opts
|> routes()
|> Enum.reduce_while(
{:not_found, conn},
fn {resource, strategy, path, phase}, {:not_found, conn} ->
strategy_path_split = Path.split(String.trim_leading(path, "/"))
if paths_match?(strategy_path_split, conn.path_info) do
{:halt, {:found, resource, strategy, path, phase}}
else
{:cont, {:not_found, conn}}
end
end
)
|> case do
{:found, resource, strategy, _path, phase} ->
subject_name = AshAuthentication.Info.authentication_subject_name!(resource)
conn
|> Plug.Conn.put_private(:strategy, strategy)
|> opts[:controller].call(
{subject_name, AshAuthentication.Strategy.name(strategy), phase}
)
{:not_found, conn} ->
not_found(conn, opts)
end
end
defp not_found(conn, opts) do
if plug = opts[:not_found_plug] do
plug.call(conn, opts)
else
conn
|> Plug.Conn.put_status(:not_found)
|> Phoenix.Controller.json(%{error: "Not Found"})
|> Plug.Conn.halt()
end
end
defp paths_match?([], []), do: true
defp paths_match?([":" <> _ | strategy_rest], [_ | actual_rest]) do
paths_match?(strategy_rest, actual_rest)
end
defp paths_match?([":*"], _), do: true
defp paths_match?([item | strategy_rest], [item | actual_rest]) do
paths_match?(strategy_rest, actual_rest)
end
defp paths_match?(_, _), do: false
defp routes(opts) do
opts[:resources]
|> Stream.flat_map(fn resource ->
resource
|> AshAuthentication.Info.authentication_add_ons()
|> Enum.concat(AshAuthentication.Info.authentication_strategies(resource))
|> Stream.flat_map(&strategy_routes(resource, &1))
end)
end
defp strategy_routes(resource, strategy) do
strategy
|> AshAuthentication.Strategy.routes()
|> Stream.map(fn {path, phase} ->
{resource, strategy, path, phase}
end)
end
end