Packages
legendary_core
8.9.1
8.12.0
8.11.1
8.11.0
8.10.0
8.9.2
8.9.1
8.5.3
8.5.2
8.5.1
8.5.0
8.4.0
8.3.6
8.3.5
8.3.4
8.3.3
8.3.2
8.3.1
8.3.0
8.2.7
8.2.5
8.2.4
8.2.3
8.2.2
8.2.1
8.2.0
8.1.1
8.1.0
8.0.1
8.0.0
7.17.12
7.17.8
7.17.7
7.17.6
7.17.5
7.17.4
7.17.3
7.17.2
7.17.1
7.17.0
7.16.12
7.16.11
4.5.4
4.0.0
2.12.0
2.11.5
2.6.0
2.4.1
2.4.0
2.3.7
2.1.2
A PETAL-stack batteries-included boilerplate for making Phoenix apps without tedium.
Current section
Files
Jump to
Current section
Files
lib/auth_web/plugs/require_admin.ex
defmodule Legendary.AuthWeb.Plugs.RequireAdmin do
@moduledoc """
A plug that returns 403 unauthorized if the user is not an admin. Used
to block out logged-in-only routes.
"""
import Plug.Conn
alias Legendary.Auth.{Roles, User}
def init(opts) do
opts
end
def call(conn, _opts) do
with user = %User{} <- Pow.Plug.current_user(conn),
true <- Roles.has_role?(user, "admin") do
conn
else
_ ->
conn
|> send_resp(403, "Unauthorized")
|> halt()
end
end
end