Basic HTTP Authentication in Elixir/Phoenix
nts.strzibny.name
nts.strzibny.name
Many eyes on security relevant code is one of the most important reasons for using open source frameworks for web development - so it is very unfortunate if exactly this part is missing, it will always look incomplete.
Of course this leaves room for professional services, I understand that, but I believe the damage done is greater than the opportunities generated. The current situation for "Phoenix auth libraries" is horrible - as a developer you will
* waste a lot of time researching and testing all the available solutions
* or just take one "random solution from the internet" that "looks good enough"
* or you will just implement another solution yourself.
Instead you want to build on the solution that is provided and maintained by the core framework community.This is such a sad story. Elixir / Phoenix looks so nice, but without a strong security foundation it looks incomplete. Authorization and Authentication is not even mentioned in the docs - that is absurd!
I simply can not understand why the project leaders are ignoring this important area.
https://latacora.micro.blog/2018/06/12/a-childs-garden.html
https://latacora.micro.blog/2018/04/03/cryptographic-right-a...
https://lobotuerto.com/blog/building-a-json-api-in-elixir-wi...
I think the main reason it's not in the docs it's because in the end it's just an implementation detail. Have a look at how simple it is to protect some routes that needs the user to be logged in.
Base64 "looks" pretty secure if you're not paying attention.
https://lobotuerto.com/blog/building-a-json-api-in-elixir-wi...
Really depend how much of a language junkie you are.
I came from old school javascript and php and did mostly functional javascript (closure, high order function, etc...). I did other languages too but php & javascript was my primary. It's moderate not a very complex language but the paradigm can be a little bit high. The creator kept the language nice and small imo.
You can get away with half of it if you're just doing phoenix and ignore OTP (process, concurrecy stuff). You can learn OTP later.
> Is it a purely functional language?
Very close to pure.
There is no for loop. If you want to loop you have to do recursion.
You don't have to loop much because there are comprehensions and generators.
You don't use closure or anything that fancy unless you want to. I think the most is higher order function and those functional stuff like map, reduce, etc... It's not bad because you can google those things to get what you want. I think learning how to pipe |> a lot of stuff and pattern matching is what you really need mostly.
Reason I said very close is because it's pragmatic like Python where not everything is an object. You can invoke len() function without it being a method to an object. The example most Erlang tutorial will give being pragmatic is the time function how the time function isn't Referential transparency. Also so other fancy missing functional stuff from Haskell that some people asked for in elixir forum but I don't understand.
I'd suggest not to pay too much attention to the "functional" label of the language and not let it intimidate/distract you, and approach it as just learning another language. The usual functional programming concepts like monads, currying, partial application, etc aren't very apparent as they usually are in languages like Haskell, i.e. you can use the language productively without knowing any of these concept.
Including some custom stuff to handle firebase auth tokens on one project.