Packages
openmaize
0.6.0
3.0.1
retired
3.0.0
2.9.0
2.8.0
2.7.0
2.6.0
2.5.1
2.5.0
2.4.0
2.3.2
2.3.1
2.3.0
2.2.0
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0
2.0.2
2.0.1
2.0.0
1.0.1
1.0.0
1.0.0-beta.5
1.0.0-beta.4
1.0.0-beta.3
1.0.0-beta.2
1.0.0-beta.1
1.0.0-beta.0
0.19.3
0.19.2
0.19.1
0.19.0
0.18.1
0.18.0
0.17.2
0.17.1
0.17.0
0.16.2
0.16.1
0.16.0
0.15.1
0.15.0
0.14.0
0.13.0
0.12.0
0.11.1
0.11.0
0.10.2
0.10.1
0.10.0
0.8.1
0.8.0
0.7.5
0.7.4
0.7.2
0.7.1
0.7.0
0.6.7
0.6.6
0.6.3
0.6.2
0.6.1
0.6.0
0.5.0
0.4.1
0.4.0
Authentication library for Elixir using Plug
Current section
Files
Jump to
Current section
Files
lib/openmaize/plugs/authorize.ex
defmodule Openmaize.Authorize do
@moduledoc """
Plug to verify that users are authorized to access the requested pages
/ resources.
Authorization is based on user roles, and so you will need a `role` entry
in your user model.
This plug can be used as a first stage in authorizing users, and so you
can call further plugs afterwards to make more fine-grained checks. To
help these further checks, if authorization is successful, two variables,
`path` and `match` are stored in the conn.private.openmaize_vars map.
`path` is the full path of the connection and `match` refers to a matching
path in the Config.protected map. If no `match` is found, it means that
the page is unprotected, and extra Openmaize checks are skipped.
There is one option:
* redirects
* if true, which is the default, redirect if authorized or if there is an error
## Examples
Call Authorize without any options:
Plug Openmaize.Authorize
Call Authorize without redirects:
Plug Openmaize.Authorize, redirects: false
"""
import Plug.Conn
import Openmaize.Report
alias Openmaize.Config
@protected_roles Config.protected
@protected Map.keys(Config.protected)
@behaviour Plug
def init(opts), do: opts
@doc """
Verify that the user is authorized to access the requested page / resource.
"""
def call(%{private: private, assigns: assigns} = conn, opts) do
if Map.get(private, :openmaize_skip) == true do
conn
else
opts = {Keyword.get(opts, :redirects, true)}
run(conn, opts, Map.get(assigns, :current_user))
end
end
defp run(conn, opts, data) do
get_match(conn) |> permitted?(data) |> authorized?(conn, opts)
end
defp permitted?({{0, _}, path}, nil) do
{:error, "You have to be logged in to view #{path}"}
end
defp permitted?(_, nil), do: {:ok, :nomatch}
defp permitted?({{0, match_len}, path}, %{role: role}) do
match = :binary.part(path, {0, match_len})
if role in Map.get(@protected_roles, match) do
{:ok, path, match}
else
{:error, role, "You do not have permission to view #{path}"}
end
end
defp permitted?(_, _), do: {:ok, :nomatch}
defp get_match(conn) do
path = full_path(conn)
{:binary.match(path, @protected), path}
end
def authorized?(:ok, conn, _), do: conn
def authorized?({:ok, :nomatch}, conn, _), do: put_private(conn, :openmaize_skip, true)
def authorized?({:ok, path, match}, conn, _) do
put_private(conn, :openmaize_vars, %{path: path, match: match})
end
def authorized?({:error, message}, conn, {false, _}), do: send_error(conn, 401, message)
def authorized?({:error, message}, conn, _), do: handle_error(conn, message)
def authorized?({:error, _, message}, conn, {false, _}), do: send_error(conn, 403, message)
def authorized?({:error, role, message}, conn, _), do: handle_error(conn, role, message)
end