Packages
shopifex
2.1.16
2.4.0
2.3.0
2.2.2
2.2.1
2.2.0
2.1.20
2.1.19
2.1.18
2.1.17
2.1.16
2.1.15
2.1.14
2.1.13
2.1.12
2.1.11
2.1.10
2.1.9
2.1.8
2.1.7
2.1.6
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0
2.0.1
2.0.0
1.1.1
1.1.0
1.0.1
1.0.0
0.6.2
0.6.1
0.6.0
0.5.7
0.5.6
0.5.5
0.5.4
0.5.3
0.5.2
0.5.1
0.5.0
0.4.1
0.4.0
0.3.6
0.3.5
0.3.4
0.3.3
0.3.2
0.3.1
0.3.0
0.2.1
0.2.0
0.1.5
0.1.4
0.1.3
0.1.2
0.1.1
0.1.0
Phoenix boilerplate for Shopify Embedded App SDK
Current section
Files
Jump to
Current section
Files
lib/shopifex/guardian.ex
defmodule Shopifex.Guardian do
# AppBridge frequently sends future `nbf`, and it causes `{:error, :token_not_yet_valid}`.
# Accept few seconds clock skew to avoid this error.
#
# see: https://github.com/Shopify/shopify_python_api/blob/master/shopify/session_token.py#L58-L60
@allowed_drift Application.compile_env(:shopifex, :allowed_drift, 10_000)
use Guardian,
otp_app: :shopifex,
issuer: {Application, :get_env, [:shopifex, :app_name]},
secret_key: {Application, :get_env, [:shopifex, :secret]},
allowed_algos: ["HS512", "HS256"],
allowed_drift: @allowed_drift
def subject_for_token(shop, _claims), do: {:ok, Shopifex.Shops.get_url(shop)}
@doc """
Since app bridge tokens are only short lived, we generate
a new longer lived token for the rest of the session
lifetime. These tokens contain the shop url in the
"sub" claim.
"""
def resource_from_claims(%{"dest" => "https://" <> shop_url}) do
shop = Shopifex.Shops.get_shop_by_url(shop_url)
{:ok, shop}
end
def resource_from_claims(%{"sub" => shop_url}) do
shop = Shopifex.Shops.get_shop_by_url(shop_url)
{:ok, shop}
end
def resource_from_claims(_claims) do
{:error, :reason_for_error}
end
end