Add AshAuthentication with the password strategy #8

Open
opened 2026-09-26 13:58:30 +00:00 by belvedere · 0 comments
Collaborator

Objective: Real sign-up/sign-in backed by an Ash resource.

Files:

  • Modify: mix.exs ({:ash_authentication, "~> 4.15"},
    {:ash_authentication_phoenix, "~> 2.17"})
  • Modify: config/config.exs (token_signing_secret from env; never commit a literal)
  • Create: lib/first_thousand_words/accounts/user.ex
  • Create: lib/first_thousand_words/accounts.ex (domain Accounts)

Steps:

  1. Add a FirstThousandWords.Accounts domain and a User resource:
    use Ash.Resource, data_layer: AshPostgres.DataLayer, extensions: [AshAuthentication].
  2. Attributes: email (identity, allow_nil? false), hashed_password,
    confirmed_at, hashed_password default AshAuthentication.BcryptProvider.
  3. authentication do strategies do password :password do identity_field :email end end.
  4. Generate and run the migration. Resolve the signing secret via
    config/runtime.exs reading an env var.

Verify:

mix ash.codegen add_accounts && mix ash.migrate
mix test --only auth   # or run the coverage added in the next issue
**Objective:** Real sign-up/sign-in backed by an Ash resource. **Files:** - Modify: `mix.exs` (`{:ash_authentication, "~> 4.15"}`, `{:ash_authentication_phoenix, "~> 2.17"}`) - Modify: `config/config.exs` (`token_signing_secret` from env; never commit a literal) - Create: `lib/first_thousand_words/accounts/user.ex` - Create: `lib/first_thousand_words/accounts.ex` (domain `Accounts`) **Steps:** 1. Add a `FirstThousandWords.Accounts` domain and a `User` resource: `use Ash.Resource, data_layer: AshPostgres.DataLayer, extensions: [AshAuthentication]`. 2. Attributes: `email` (identity, `allow_nil? false`), `hashed_password`, `confirmed_at`, `hashed_password` default `AshAuthentication.BcryptProvider`. 3. `authentication do strategies do password :password do identity_field :email end end`. 4. Generate and run the migration. Resolve the signing secret via `config/runtime.exs` reading an env var. **Verify:** ```bash mix ash.codegen add_accounts && mix ash.migrate mix test --only auth # or run the coverage added in the next issue ```
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
nickkeers/first-thousand-words#8
No description provided.