Packages
openmaize
0.6.6
3.0.1
retired
3.0.0
2.9.0
2.8.0
2.7.0
2.6.0
2.5.1
2.5.0
2.4.0
2.3.2
2.3.1
2.3.0
2.2.0
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0
2.0.2
2.0.1
2.0.0
1.0.1
1.0.0
1.0.0-beta.5
1.0.0-beta.4
1.0.0-beta.3
1.0.0-beta.2
1.0.0-beta.1
1.0.0-beta.0
0.19.3
0.19.2
0.19.1
0.19.0
0.18.1
0.18.0
0.17.2
0.17.1
0.17.0
0.16.2
0.16.1
0.16.0
0.15.1
0.15.0
0.14.0
0.13.0
0.12.0
0.11.1
0.11.0
0.10.2
0.10.1
0.10.0
0.8.1
0.8.0
0.7.5
0.7.4
0.7.2
0.7.1
0.7.0
0.6.7
0.6.6
0.6.3
0.6.2
0.6.1
0.6.0
0.5.0
0.4.1
0.4.0
Authentication library for Elixir using Plug
Current section
Files
Jump to
Current section
Files
lib/openmaize/token.ex
defmodule Openmaize.Token do
@moduledoc """
Module to generate Json Web Tokens and send them to the user, either
by storing the token in a cookie or sending the token in the body of
the response.
## Json Web Tokens
Json Web Tokens (JWTs) are an alternative to using cookies to identify,
and provide information about, users after they have logged in.
One main advantage of using JWTs is that there is no need to keep a
session store as the token can be used to contain user information.
It is important, though, not to keep sensitive information in the
token as the information is not encrypted -- it is just encoded.
The JWTs need to be stored somewhere, either in cookies or sessionStorage
(or localStorage), so that they can be used in subsequent requests.
If you want to store the token in sessionStorage, you will need to add
the token to sessionStorage with the front-end framework you are using
and add the token to the request headers for each request.
If you do not store the token in a cookie, then you will not need to use
the `protect_from_forgery` (csrf protection) plug. However, if you are
storing the token in sessionStorage, there is then a risk of cross-site
scripting attack.
"""
import Plug.Conn
import Openmaize.Report
alias Openmaize.Config
alias Openmaize.TokenConfig
@token_info Config.token_info
@doc """
Encode JWT.
"""
def encode(payload) do
Joken.Token.encode(TokenConfig, payload)
end
@doc """
Decode JWT.
"""
def decode(token) do
Joken.Token.decode(TokenConfig, token)
end
@doc """
Generate token based on the user information and the `token_info`
setting in the config.
The token is then either stored in a cookie or sent in the body of the
response.
"""
def add_token(conn, user, storage) when storage == :cookie do
role = Map.get(user, :role)
{:ok, token} = generate_token(user)
put_resp_cookie(conn, "access_token", token, [http_only: true])
|> handle_info(role, "You have been logged in")
end
def add_token(conn, user, _storage) do
{:ok, token} = generate_token(user)
token_string = ~s({"access_token": #{token}})
send_resp(conn, 200, token_string) |> terminate
end
defp generate_token(user) do
Map.take(user, @token_info)
|> Map.merge(%{exp: token_expiry_secs})
|> encode
end
defp token_expiry_secs do
current_time + Config.token_validity
end
defp current_time do
{mega, secs, _} = :os.timestamp
mega * 1000000 + secs
end
end