ash_hq/lib/ash_hq_web/router.ex
Zach Daniel 025b56d1a4 improvement: get a build set up
improvement: fix lint/security issues
improvement: add CSP
improvement: remove currently unnecessary/old code
2022-08-06 19:22:58 -04:00

116 lines
3.7 KiB
Elixir

defmodule AshHqWeb.Router do
use AshHqWeb, :router
import AshHqWeb.UserAuth
pipeline :browser do
plug :accepts, ["html"]
plug :fetch_session
plug :fetch_live_flash
plug :put_root_layout, {AshHqWeb.LayoutView, :root}
plug :protect_from_forgery
plug AshHqWeb.SessionPlug
end
pipeline :dead_view_authentication do
plug :fetch_current_user
end
pipeline :api do
plug :accepts, ["json"]
end
scope "/", AshHqWeb do
pipe_through :api
post "/import/:library", ImportController, :import
end
scope "/", AshHqWeb do
pipe_through :browser
live_session :main,
on_mount: {AshHqWeb.LiveUserAuth, :live_user},
root_layout: {AshHqWeb.LayoutView, "root.html"} do
live "/", AppViewLive, :home
live "/docs/", AppViewLive, :docs_dsl
live "/docs/guides/:library/:version/*guide", AppViewLive, :docs_dsl
live "/docs/dsl/:library", AppViewLive, :docs_dsl
live "/docs/dsl/:library/:version", AppViewLive, :docs_dsl
live "/docs/dsl/:library/:version/:extension", AppViewLive, :docs_dsl
live "/docs/dsl/:library/:version/:extension/*dsl_path", AppViewLive, :docs_dsl
live "/docs/module/:library/:version/:module", AppViewLive, :docs_dsl
end
end
## Authentication routes
scope "/", AshHqWeb do
pipe_through [
:browser,
:dead_view_authentication,
:redirect_if_user_is_authenticated,
:put_session_layout
]
get "/users/register", UserRegistrationController, :new
post "/users/register", UserRegistrationController, :create
get "/users/log_in", UserSessionController, :new
post "/users/log_in", UserSessionController, :create
get "/users/reset_password", UserResetPasswordController, :new
post "/users/reset_password", UserResetPasswordController, :create
get "/users/reset_password/:token", UserResetPasswordController, :edit
put "/users/reset_password/:token", UserResetPasswordController, :update
end
scope "/", AshHqWeb do
pipe_through [:browser, :dead_view_authentication, :require_authenticated_user]
get "/users/settings", UserSettingsController, :edit
put "/users/settings", UserSettingsController, :update
get "/users/settings/confirm_email/:token", UserSettingsController, :confirm_email
end
scope "/", AshHqWeb do
pipe_through [:browser, :dead_view_authentication]
# get "/users/log_out", UserSessionController, :delete
delete "/users/log_out", UserSessionController, :delete
get "/users/confirm", UserConfirmationController, :new
post "/users/confirm", UserConfirmationController, :create
get "/users/confirm/:token", UserConfirmationController, :confirm
end
# Other scopes may use custom stacks.
# scope "/api", AshHqWeb do
# pipe_through :api
# end
# Enables LiveDashboard only for development
#
# If you want to use the LiveDashboard in production, you should put
# it behind authentication and allow only admins to access it.
# If your application does not have an admins-only section yet,
# you can use Plug.BasicAuth to set up some basic authentication
# as long as you are also using SSL (which you should anyway).
if Mix.env() in [:dev, :test] do
import Phoenix.LiveDashboard.Router
scope "/" do
pipe_through [:browser, :dead_view_authentication]
live_dashboard "/dashboard", metrics: AshHqWeb.Telemetry
end
end
# Enables the Swoosh mailbox preview in development.
#
# Note that preview only shows emails that were sent by the same
# node running the Phoenix server.
if Mix.env() == :dev do
scope "/dev" do
pipe_through [:browser, :dead_view_authentication]
forward "/mailbox", Plug.Swoosh.MailboxPreview
end
end
end