Packages

phoenix_kit

1.7.121
1.7.208 1.7.207 1.7.206 1.7.205 1.7.204 1.7.203 1.7.202 1.7.201 1.7.200 1.7.199 1.7.198 1.7.197 1.7.196 1.7.194 1.7.193 1.7.192 1.7.191 1.7.190 1.7.189 1.7.187 1.7.186 1.7.185 1.7.184 1.7.183 1.7.182 1.7.181 1.7.180 1.7.179 1.7.178 1.7.177 1.7.176 1.7.175 1.7.174 1.7.173 1.7.172 1.7.171 1.7.170 1.7.169 1.7.168 1.7.167 1.7.166 1.7.165 1.7.164 1.7.162 1.7.161 1.7.160 1.7.159 1.7.157 1.7.156 1.7.155 1.7.154 1.7.153 1.7.152 1.7.151 1.7.150 1.7.149 1.7.146 1.7.145 1.7.144 1.7.143 1.7.138 1.7.133 1.7.132 1.7.131 1.7.130 1.7.128 1.7.126 1.7.125 1.7.121 1.7.120 1.7.119 1.7.118 1.7.117 1.7.116 1.7.115 1.7.114 1.7.113 1.7.112 1.7.111 1.7.110 1.7.109 1.7.108 1.7.107 1.7.106 1.7.105 1.7.104 1.7.103 1.7.102 1.7.101 1.7.100 1.7.99 1.7.98 1.7.97 1.7.96 1.7.95 1.7.94 1.7.93 1.7.92 1.7.91 1.7.90 1.7.89 1.7.88 1.7.87 1.7.86 1.7.85 1.7.84 1.7.83 1.7.82 1.7.81 1.7.80 1.7.79 1.7.78 1.7.77 1.7.76 1.7.75 1.7.74 1.7.71 1.7.70 1.7.69 1.7.66 1.7.65 1.7.64 1.7.63 1.7.62 1.7.61 1.7.59 1.7.58 1.7.57 1.7.56 1.7.55 1.7.54 1.7.53 1.7.52 1.7.51 1.7.49 1.7.44 1.7.43 1.7.42 1.7.41 1.7.39 1.7.38 1.7.37 1.7.36 1.7.34 1.7.33 1.7.31 1.7.30 1.7.29 1.7.28 1.7.27 1.7.26 1.7.25 1.7.24 1.7.23 1.7.22 1.7.21 1.7.20 1.7.19 1.7.18 1.7.17 1.7.16 1.7.15 1.7.14 1.7.13 1.7.12 1.7.11 1.7.10 1.7.9 1.7.8 1.7.7 1.7.6 1.7.5 1.7.4 1.7.3 1.7.2 1.7.1 1.7.0 1.6.20 1.6.19 1.6.18 1.6.17 1.6.16 1.6.15 1.6.14 1.6.13 1.6.12 1.6.11 1.6.10 1.6.9 1.6.8 1.6.7 1.6.6 1.6.5 1.6.4 1.6.3 1.5.2 1.5.1 1.5.0 1.4.9 1.4.8 1.4.7 1.4.6 1.4.5 1.4.4 1.4.3 1.4.2 1.4.1 1.4.0 1.3.2 1.3.1 1.3.0 1.2.10 1.2.9 1.2.8 1.2.7 1.2.5 1.2.4 1.2.2 1.2.1 1.2.0 1.1.0 1.0.0

A foundation for building Elixir Phoenix apps — SaaS, social networks, ERP systems, marketplaces, and more

Current section

Files

Jump to
phoenix_kit lib phoenix_kit users role.ex
Raw

lib/phoenix_kit/users/role.ex

defmodule PhoenixKit.Users.Role do
@moduledoc """
Role schema for PhoenixKit authorization system.
This schema defines user roles that can be assigned to users for authorization purposes.
## Fields
- `name`: Role name (unique, required for identification)
- `description`: Human-readable description of the role
- `is_system_role`: Whether this is a system-defined role that shouldn't be deleted
## System Roles
PhoenixKit includes three built-in system roles:
- **Owner**: System owner with full access (assigned to first user automatically)
- **Admin**: Administrator with elevated privileges
- **User**: Standard user with basic access (default for new users)
## Security Features
- System roles cannot be deleted
- Role names are unique
- Automatic assignment of User role to new registrations
- Automatic assignment of Owner role to first user
"""
use Ecto.Schema
import Ecto.Changeset
@type t :: %__MODULE__{
uuid: UUIDv7.t() | nil,
name: String.t(),
description: String.t() | nil,
is_system_role: boolean(),
inserted_at: DateTime.t(),
updated_at: DateTime.t()
}
@roles %{
owner: "Owner",
admin: "Admin",
user: "User"
}
@primary_key {:uuid, UUIDv7, autogenerate: true}
schema "phoenix_kit_user_roles" do
field :name, :string
field :description, :string
field :is_system_role, :boolean, default: false
has_many :role_assignments, PhoenixKit.Users.RoleAssignment,
foreign_key: :role_uuid,
references: :uuid
many_to_many :users, PhoenixKit.Users.Auth.User,
join_through: PhoenixKit.Users.RoleAssignment,
join_keys: [role_uuid: :uuid, user_uuid: :uuid]
timestamps(type: :utc_datetime)
end
@doc """
A role changeset for creating and updating roles.
## Parameters
- `role`: The role struct to modify
- `attrs`: Attributes to update
## Examples
iex> changeset(%Role{}, %{name: "Manager", description: "Department manager"})
%Ecto.Changeset{valid?: true}
iex> changeset(%Role{}, %{name: ""})
%Ecto.Changeset{valid?: false}
"""
def changeset(role, attrs) do
role
|> cast(attrs, [:name, :description, :is_system_role])
|> validate_required([:name])
|> validate_length(:name, min: 1, max: 50)
|> validate_length(:description, max: 500)
|> unique_constraint(:name)
|> validate_system_role_protection()
end
@doc """
Returns the map of system role names.
## Examples
iex> system_roles()
%{owner: "Owner", admin: "Admin", user: "User"}
"""
def system_roles do
@roles
end
@doc """
Checks if a role name is a system role.
## Examples
iex> system_role?(system_roles().owner)
true
iex> system_role?("Owner")
true
iex> system_role?("Manager")
false
"""
def system_role?(role_name) when is_binary(role_name) do
role_name in Map.values(system_roles())
end
# Protect system roles from being modified
defp validate_system_role_protection(changeset) do
if changeset.data.is_system_role &&
get_change(changeset, :is_system_role) == false do
add_error(changeset, :is_system_role, "system roles cannot be modified")
else
changeset
end
end
end