Packages
openmaize
0.16.1
3.0.1
retired
3.0.0
2.9.0
2.8.0
2.7.0
2.6.0
2.5.1
2.5.0
2.4.0
2.3.2
2.3.1
2.3.0
2.2.0
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0
2.0.2
2.0.1
2.0.0
1.0.1
1.0.0
1.0.0-beta.5
1.0.0-beta.4
1.0.0-beta.3
1.0.0-beta.2
1.0.0-beta.1
1.0.0-beta.0
0.19.3
0.19.2
0.19.1
0.19.0
0.18.1
0.18.0
0.17.2
0.17.1
0.17.0
0.16.2
0.16.1
0.16.0
0.15.1
0.15.0
0.14.0
0.13.0
0.12.0
0.11.1
0.11.0
0.10.2
0.10.1
0.10.0
0.8.1
0.8.0
0.7.5
0.7.4
0.7.2
0.7.1
0.7.0
0.6.7
0.6.6
0.6.3
0.6.2
0.6.1
0.6.0
0.5.0
0.4.1
0.4.0
Authentication library for Elixir using Plug
Current section
Files
Jump to
Current section
Files
lib/openmaize/token.ex
defmodule Openmaize.Token do
@moduledoc """
Module to generate Json Web Tokens and send them to the user, either
by storing the token in a cookie or by sending the token in the body of
the response.
## Json Web Tokens
Json Web Tokens (JWTs) are an alternative to using cookies to identify,
and provide information about, users after they have logged in.
One main advantage of using JWTs is that there is no need to keep a
session store as the token can be used to contain user information.
It is important, though, not to keep sensitive information in the
token as the information is not encrypted -- it is just encoded.
The JWTs need to be stored somewhere, either in cookies or sessionStorage
(or localStorage), so that they can be used in subsequent requests.
If you want to store the token in sessionStorage, you will need to add
the token to sessionStorage with the front-end framework you are using
and add the token to the request headers for each request.
If you decide to store the token in sessionStorage, and not in a cookie,
you will not need to use the `protect_from_forgery` (csrf protection) plug.
However, storing tokens in sessionStorage opens up the risk of cross-site
scripting attacks.
"""
import Plug.Conn
import Openmaize.{Report, Token.Create}
@doc """
Generate token based on the user information.
The token is then either stored in a cookie or sent in the body of the
response.
"""
def add_token(conn, %{role: role} = user, {true, _storage, token_opts, uniq}) do
{:ok, token} = generate_token(user, uniq, token_opts)
conn
|> put_resp_cookie("access_token", token, [http_only: true])
|> put_message(role, %{"info" => "You have been logged in"}, true)
end
def add_token(conn, user, {false, storage, token_opts, uniq}) do
generate_token(user, uniq, token_opts)
|> add_to_conn(conn, storage)
|> send_resp()
|> halt()
end
defp add_to_conn({:ok, token}, conn, :cookie) do
conn
|> put_resp_cookie("access_token", token, [http_only: true])
|> resp(200, "")
end
defp add_to_conn({:ok, token}, conn, nil) do
resp(conn, 200, ~s({"access_token": "#{token}"}))
end
end