security
Enforce Elixir/Phoenix security — auth, OAuth, sessions, CSRF, XSS, SQL
它会碰到什么
逐条看命中(1 条严重或高危)
- 严重
references/advanced-patterns.md:265cred-paths- [ ] .env in .gitignore
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Elixir/Phoenix Security Reference
> Ash projects: AshAuthentication has its own strategy/token patterns — use the ash-framework skill. CSRF, XSS, and secret management patterns below still apply.
Quick reference for security patterns in Elixir/Phoenix.
Iron Laws — Never Violate These
- VALIDATE AT BOUNDARIES — Never trust client input. All data through changesets
- NEVER INTERPOLATE USER INPUT — Use Ecto's
^operator, never string interpolation - NO String.to_atom WITH USER INPUT — Atom exhaustion DoS. Use
to_existing_atom/1 - AUTHORIZE EVERYWHERE — Check in contexts AND re-validate in LiveView events
- ESCAPE BY DEFAULT — Never use
raw/1with untrusted content - SECRETS NEVER IN CODE — All secrets in
runtime.exsfrom env vars - LIVEVIEW EVENT PARAMS ARE UNTRUSTED — Users can alter forms, hooks, and every
phx-value-*in DevTools. Validate and authorize against server-side state before acting
Quick Patterns
Timing-Safe Authentication
def authenticate(email, password) do
user = Repo.get_by(User, email: email)
cond do
user && Argon2.verify_pass(password, user.hashed_password) ->
{:ok, user}
user ->
{:error, :invalid_credentials}
true ->
Argon2.no_user_verify() # Timing attack prevention
{:error, :invalid_credentials}
end
end
LiveView Authorization (CRITICAL)
# `id` is client input even when it came from phx-value-id.
# RE-AUTHORIZE IN EVERY EVENT HANDLER
def handle_event("delete", %{"id" => id}, socket) do
post = Blog.get_post!(id)
# Don't trust that mount authorized this action!
with :ok <- Bodyguard.permit(Blog, :delete_post, socket.assigns.current_user, post) do
Blog.delete_post(post)
{:noreply, stream_delete(socket, :posts, post)}
else
_ -> {:noreply, put_flash(socket, :error, "Unauthorized")}
end
end
Rendered LiveView events can expose IDs in HTML and websocket payloads. That is
not automatically a vulnerability: treat IDs as public identifiers, never as
proof of access. Use opaque references only when the identifier itself must not
be disclosed, and still perform server-side authorization.
SQL Injection Prevention
# ✅ SAFE: Parameterized queries
from(u in User, where: u.name == ^user_input)
# ❌ VULNERABLE: String interpolation
from(u in User, where: fragment("name = '#{user_input}'"))
Quick Decisions
What to validate?
- All user input → Ecto changesets
- File uploads → Extension + magic bytes + size
- Paths →
Path.safe_relative/2for traversal - Atoms →
String.to_existing_atom/1only
What to escape?
- HTML output → Auto-escaped by default (
<%= %>) - User HTML → HtmlSanitizeEx with scrubber
- Never →
raw/1with untrusted content
Anti-patterns
| Wrong | Right |
|-------|-------|
| "SELECT * FROM users WHERE name = '#{name}'" | from(u in User, where: u.name == ^name) |
| String.to_atom(user_input) | String.to_existing_atom(user_input) |
| <%= raw @user_comment %> | <%= @user_comment %> |
| Hardcoded secrets in config | runtime.exs from env vars |
| Auth only in mount | Re-auth in every handle_event |
| Trusting phx-value-* or hidden IDs | Load server-side state and authorize it |
References
For detailed patterns, see:
references/authentication.md- phx.gen.auth, MFA, sessionsreferences/authorization.md- Bodyguard, scopes, LiveView authreferences/input-validation.md- Changesets, file uploads, pathsreferences/security-headers.md- CSP, CSRF, rate limiting, headersreferences/oauth-linking.md- OAuth account linking, token managementreferences/rate-limiting.md- Composite key strategies, Hammer patternsreferences/advanced-patterns.md- SSRF prevention, secrets management, supply chain
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
同名技能的其他版本
有 6 个不同仓库或目录里都有叫 security 的技能。它们内容并不相同,别混用:
- oliver-kriska/claude-elixir-phoenix — Enforce Elixir/Phoenix security — auth, OAuth, sessions, CSRF, XSS, SQL injection, input v
- oliver-kriska/claude-elixir-phoenix — Enforce Elixir/Phoenix security — auth, OAuth, sessions, CSRF, XSS, SQL
- oliver-kriska/claude-elixir-phoenix — Enforce Elixir/Phoenix security — auth, OAuth, sessions, CSRF, XSS; Use
- oliver-kriska/claude-elixir-phoenix — Enforce Elixir/Phoenix security — auth, OAuth, sessions, CSRF, XSS, SQL
- oliver-kriska/claude-elixir-phoenix — Enforce Elixir/Phoenix security — auth, OAuth, sessions, CSRF, XSS, SQL