Packages
openmaize
0.10.1
3.0.1
retired
3.0.0
2.9.0
2.8.0
2.7.0
2.6.0
2.5.1
2.5.0
2.4.0
2.3.2
2.3.1
2.3.0
2.2.0
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0
2.0.2
2.0.1
2.0.0
1.0.1
1.0.0
1.0.0-beta.5
1.0.0-beta.4
1.0.0-beta.3
1.0.0-beta.2
1.0.0-beta.1
1.0.0-beta.0
0.19.3
0.19.2
0.19.1
0.19.0
0.18.1
0.18.0
0.17.2
0.17.1
0.17.0
0.16.2
0.16.1
0.16.0
0.15.1
0.15.0
0.14.0
0.13.0
0.12.0
0.11.1
0.11.0
0.10.2
0.10.1
0.10.0
0.8.1
0.8.0
0.7.5
0.7.4
0.7.2
0.7.1
0.7.0
0.6.7
0.6.6
0.6.3
0.6.2
0.6.1
0.6.0
0.5.0
0.4.1
0.4.0
Authentication library for Elixir using Plug
Current section
Files
Jump to
Current section
Files
lib/openmaize/login.ex
defmodule Openmaize.Login do
@moduledoc """
Module to handle password authentication and the generation, and
distribution, of tokens.
If the login is successful, the token will either be stored in a cookie
or sent back in the body of the response.
"""
import Ecto.Query
import Openmaize.Token
import Openmaize.Report
alias Openmaize.Config
@doc """
Function to handle user login.
If there is no error, a token will be created and sent to the user so that
the user can make further requests without logging in again.
If the option `redirects` is not set, or set to true, the user will then
be redirected to the main page / user page. If there is an error, the
user will be redirected to the login page.
If `redirects` is set to false, then there will be no redirects.
"""
def call(%Plug.Conn{params: params} = conn, {redirects, storage, token_opts}) do
%{"name" => user, "password" => password} = Map.take(params["user"], ["name", "password"])
case {login_user(user, password), redirects} do
{false, false} -> send_error(conn, 401, "Invalid credentials")
{false, true} -> handle_error(conn, "Invalid credentials")
{user, _} -> add_token(conn, user, token_opts, storage)
end
end
defp login_user(user, password) do
from(user in Config.user_model,
where: user.name == ^user,
select: user)
|> Config.repo.one
|> check_user(password)
end
defp check_user(nil, _), do: Config.get_crypto_mod.dummy_checkpw
defp check_user(user, password) do
Config.get_crypto_mod.checkpw(password, user.password_hash) and user
end
end