Packages
auth_plug
0.1.1
1.5.2
1.5.1
1.5.0
1.4.21
1.4.20
1.4.19
1.4.18
1.4.17
1.4.16
1.4.15
1.4.14
1.4.13
1.4.12
1.4.11
1.4.10
1.4.9
1.4.8
1.4.7
1.4.6
1.4.5
1.4.4
1.4.3
1.4.2
1.4.1
1.4.0
1.3.7
1.3.6
1.3.5
1.3.4
1.3.3
1.3.2
1.3.1
1.3.0
1.2.3
1.2.2
1.2.1
1.2.0
1.1.1
1.1.0
1.0.0
0.16.0
0.15.0
0.14.0
0.13.0
0.12.0
0.11.0
0.10.0
0.9.0
0.8.0
0.7.0
0.5.0
0.4.0
0.3.1
0.3.0
0.2.1
0.2.0
0.1.4
0.1.3
0.1.2
0.1.1
0.1.0
Turnkey Auth Plug lets you protect any route in an Elixir/Phoenix App.
Current section
Files
Jump to
Current section
Files
lib/auth_plug.ex
defmodule AuthPlug do
import Plug.Conn
use Joken.Config
@signer Joken.Signer.create("HS256", "secret")
def init(opts), do: opts
def call(conn, _) do
jwt =
conn.req_headers
|> List.keyfind("authorization", 0)
|> get_token_from_header()
validate_token(conn, jwt)
end
defp get_token_from_header(nil), do: nil
defp get_token_from_header({"authorization", value}) do
value = String.replace(value, "Bearer", "") |> String.trim()
if is_nil(value) do
nil
else # fast check for JWT format validity before slower verify:
case Enum.count(String.split(value, ".")) == 3 do
false ->
nil
true -> # appears to be valid JWT proceed to verifying it
value
end
end
end
defp validate_token(conn, nil), do: unauthorized(conn)
defp validate_token(conn, jwt) do
case AuthPlug.Token.verify_and_validate(jwt, @signer) do
{:ok, values} ->
# convert map of string to atom: stackoverflow.com/questions/31990134
claims = for {k, v} <- values, into: %{}, do: {String.to_atom(k), v}
assign(conn, :claims, claims)
{:error, _} -> unauthorized(conn)
end
end
defp unauthorized(conn) do
conn
|> put_resp_header("www-authenticate", "Bearer realm=\"Person access\"")
|> send_resp(401, "unauthorized")
|> halt()
end
end