Packages
ash_authentication_phoenix
3.0.0-rc.2
3.0.0-rc.9
3.0.0-rc.8
3.0.0-rc.7
3.0.0-rc.6
3.0.0-rc.4
3.0.0-rc.3
3.0.0-rc.2
3.0.0-rc.1
3.0.0-rc.0
2.17.2
2.17.1
2.17.0
2.16.0
2.15.0
2.14.1
2.14.0
2.13.1
2.13.0
2.12.2
2.12.1
2.12.0
2.11.0
2.10.5
2.10.4
2.10.3
2.10.2
2.10.1
2.10.0
2.9.0
2.8.0
2.7.0
2.6.3
2.6.2
2.6.1
2.6.0
2.5.4
2.5.3
2.5.2
2.5.1
2.5.0
2.4.8
2.4.7
2.4.6
2.4.5
2.4.4
2.4.3
2.4.2
2.4.1
2.4.0
2.3.0
2.2.1
2.2.0
2.1.11
2.1.10
2.1.9
2.1.8
2.1.7
2.1.6
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0
2.0.2
2.0.1
2.0.0
2.0.0-rc.2
2.0.0-rc.1
2.0.0-rc.0
1.9.4
1.9.3
1.9.2
1.9.1
1.9.0
1.8.7
1.8.6
1.8.5
1.8.4
1.8.3
1.8.2
1.8.1
1.8.0
1.7.3
1.7.2
1.7.1
1.7.0
1.6.6
1.6.5
1.6.4
1.6.3
1.6.2
1.6.1
1.6.0
1.5.1
1.5.0
1.4.8
1.4.7
1.4.6
1.4.5
1.4.4
1.4.3
1.4.2
1.4.1
1.4.0
1.3.1
1.3.0
1.2.0
1.1.0
1.0.1
1.0.0
Phoenix integration for Ash Authentication
Current section
Files
Jump to
Current section
Files
lib/ash_authentication_phoenix/recovery_code_verify_live.ex
# SPDX-FileCopyrightText: 2022 Alembic Pty Ltd
#
# SPDX-License-Identifier: MIT
defmodule AshAuthentication.Phoenix.RecoveryCodeVerifyLive do
use AshAuthentication.Phoenix.Overrides.Overridable,
root_class: "CSS class for the root `div` element.",
recovery_code_verify_id: "Element ID for the `VerifyForm` LiveComponent."
@moduledoc """
A generic, white-label recovery code verification page.
This live-view supports two authentication flows:
## Token-based Flow (Password -> Recovery Code)
Used after a user has authenticated with their primary credentials (e.g., password)
but needs to complete 2FA and cannot access their TOTP authenticator. The `token`
URL parameter contains a partial authentication token that will be exchanged for a
full session token after successful recovery code verification.
## Step-up Authentication Flow
Used when an already-authenticated user needs to verify their identity to access
protected resources. In this mode, no token is required - the verification uses
the `current_user` from the session.
## Usage
Add to your router using the `recovery_code_verify_route/3` macro:
scope "/", MyAppWeb do
pipe_through :browser
recovery_code_verify_route MyApp.Accounts.User, :recovery_code, auth_routes_prefix: "/auth"
end
#{AshAuthentication.Phoenix.Overrides.Overridable.generate_docs()}
"""
use AshAuthentication.Phoenix.Web, :live_view
alias AshAuthentication.Phoenix.Components
alias Phoenix.LiveView.{Rendered, Socket}
@doc false
@impl true
def mount(_params, session, socket) do
overrides =
session
|> Map.get("overrides", [AshAuthentication.Phoenix.Overrides.Default])
socket =
socket
|> assign(overrides: overrides)
|> assign_new(:otp_app, fn -> nil end)
|> assign(:current_tenant, session["tenant"])
|> assign(:context, session["context"] || %{})
|> assign(:auth_routes_prefix, session["auth_routes_prefix"])
|> assign(:gettext_fn, session["gettext_fn"])
|> assign(:strategy, session["strategy"])
|> assign(:resource, session["resource"])
{:ok, socket}
end
@doc false
@impl true
@spec handle_params(map, String.t(), Socket.t()) :: {:noreply, Socket.t()}
def handle_params(params, _uri, socket) do
token = params["token"]
mode =
cond do
token && token != "" -> :token
socket.assigns[:current_user] -> :step_up
true -> :error
end
socket =
socket
|> assign(:token, token)
|> assign(:mode, mode)
{:noreply, socket}
end
@doc false
@impl true
@spec render(Socket.assigns()) :: Rendered.t()
def render(assigns) do
~H"""
<div class={override_for(@overrides, :root_class)}>
<.live_component
module={Components.RecoveryCode.VerifyForm}
otp_app={@otp_app}
id={override_for(@overrides, :recovery_code_verify_id, "recovery_code_verify")}
token={@token}
mode={@mode}
current_user={@current_user}
strategy={@strategy}
auth_routes_prefix={@auth_routes_prefix}
overrides={@overrides}
resource={@resource}
current_tenant={@current_tenant}
context={@context}
gettext_fn={@gettext_fn}
/>
</div>
"""
end
end