Packages
phoenix_live_view
0.17.11
1.2.7
1.2.6
1.2.5
1.2.4
1.2.3
1.2.2
1.2.1
1.2.0
1.2.0-rc.3
1.2.0-rc.2
1.2.0-rc.1
1.2.0-rc.0
1.1.32
1.1.31
1.1.30
1.1.29
1.1.28
1.1.27
1.1.26
1.1.25
1.1.24
1.1.23
1.1.22
1.1.21
1.1.20
1.1.19
1.1.18
1.1.17
1.1.16
1.1.15
1.1.14
1.1.13
1.1.12
1.1.11
1.1.10
1.1.9
1.1.8
1.1.7
1.1.6
retired
1.1.5
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0
1.1.0-rc.4
1.1.0-rc.3
1.1.0-rc.2
1.1.0-rc.1
1.1.0-rc.0
1.0.18
1.0.17
1.0.16
1.0.15
1.0.14
1.0.13
1.0.12
1.0.11
1.0.10
1.0.9
1.0.8
retired
1.0.7
1.0.6
retired
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
1.0.0-rc.9
1.0.0-rc.8
1.0.0-rc.7
1.0.0-rc.6
1.0.0-rc.5
1.0.0-rc.4
1.0.0-rc.3
1.0.0-rc.2
1.0.0-rc.1
1.0.0-rc.0
0.20.17
0.20.16
0.20.15
0.20.14
0.20.13
0.20.12
0.20.11
0.20.10
0.20.9
0.20.8
0.20.7
0.20.6
0.20.5
0.20.4
0.20.3
0.20.2
0.20.1
0.20.0
0.19.5
0.19.4
0.19.3
0.19.2
0.19.1
0.19.0
0.18.18
0.18.17
0.18.16
0.18.15
0.18.14
0.18.13
0.18.12
0.18.11
0.18.10
0.18.9
0.18.8
0.18.7
0.18.6
0.18.5
0.18.4
0.18.3
0.18.2
0.18.1
0.18.0
0.17.14
0.17.13
0.17.12
0.17.11
0.17.10
0.17.9
0.17.8
0.17.7
0.17.6
0.17.5
0.17.4
0.17.3
0.17.2
0.17.1
0.17.0
0.16.4
0.16.3
0.16.2
0.16.1
0.16.0
0.15.7
0.15.6
0.15.5
0.15.4
0.15.3
0.15.2
0.15.1
0.15.0
0.14.8
0.14.7
0.14.6
0.14.5
0.14.4
0.14.3
0.14.2
0.14.1
0.14.0
0.13.3
0.13.2
0.13.1
0.13.0
0.12.1
0.12.0
0.11.1
0.11.0
0.10.0
0.9.0
0.8.1
0.8.0
0.7.1
0.7.0
0.6.0
0.6.0-dev
0.5.2
0.5.1
0.5.0
0.4.1
0.4.0
0.3.1
0.3.0
0.2.1
0.2.0
0.1.1
0.1.0
Rich, real-time user experiences with server-rendered HTML
Current section
Files
Jump to
Current section
Files
lib/phoenix_live_view/session.ex
defmodule Phoenix.LiveView.Session do
@moduledoc false
alias Phoenix.LiveView.{Session, Route, Static}
defstruct id: nil,
view: nil,
root_view: nil,
parent_pid: nil,
root_pid: nil,
session: %{},
redirected?: false,
router: nil,
flash: nil,
live_session_name: nil,
live_session_vsn: nil,
assign_new: []
def main?(%Session{} = session), do: !is_nil(session.router) and !session.parent_pid
def authorize_root_redirect(%Session{} = session, %Route{} = route) do
%Session{live_session_name: session_name, live_session_vsn: session_vsn} = session
cond do
route.live_session.name == session_name and route.live_session.vsn == session_vsn ->
{:ok, replace_root(session, route.view, self())}
true ->
{:error, :unauthorized}
end
end
defp replace_root(%Session{} = session, new_root_view, root_pid) when is_pid(root_pid) do
%Session{
session
| view: new_root_view,
root_view: new_root_view,
root_pid: root_pid,
assign_new: [],
redirected?: true
}
end
@doc """
Verifies the session token.
Returns the decoded map of session data or an error.
## Examples
iex> verify_session(AppWeb.Endpoint, "topic", encoded_token, static_token)
{:ok, %Session{} = decoded_session}
iex> verify_session(AppWeb.Endpoint, "topic", "bad token", "bac static")
{:error, :invalid}
iex> verify_session(AppWeb.Endpoint, "topic", "expired", "expired static")
{:error, :expired}
"""
def verify_session(endpoint, topic, session_token, static_token) do
with {:ok, %{id: id} = session} <- Static.verify_token(endpoint, session_token),
:ok <- verify_topic(topic, id),
{:ok, static} <- verify_static_token(endpoint, id, static_token) do
merged_session = Map.merge(session, static)
{live_session_name, vsn} = merged_session[:live_session] || {nil, nil}
session = %Session{
id: id,
view: merged_session.view,
root_view: merged_session.root_view,
parent_pid: merged_session.parent_pid,
root_pid: merged_session.root_pid,
session: merged_session.session,
assign_new: merged_session.assign_new,
live_session_name: live_session_name,
live_session_vsn: vsn,
# optional keys
router: merged_session[:router],
flash: merged_session[:flash]
}
{:ok, session}
end
end
defp verify_topic("lv:" <> session_id, session_id), do: :ok
defp verify_topic(_topic, _session_id), do: {:error, :invalid}
defp verify_static_token(_endpoint, _id, nil), do: {:ok, %{assign_new: []}}
defp verify_static_token(endpoint, id, token) do
case Static.verify_token(endpoint, token) do
{:ok, %{id: ^id}} = ok -> ok
{:ok, _} -> {:error, :invalid}
{:error, _} = error -> error
end
end
end