aprs.me/docs/contexts/accounts.md

2.5 KiB

Accounts Context

Overview

Module: Aprsme.Accounts (lib/aprsme/accounts.ex)

Handles user registration, authentication, email confirmation, password reset, and session management.

Schemas

User (lib/aprsme/accounts/user.ex)

Field Type Notes
id binary_id Primary key
email citext Case-insensitive, unique
callsign string Optional amateur radio callsign
hashed_password string Bcrypt-hashed
confirmed_at utc_datetime Email confirmation timestamp
password virtual Transient, used for changesets only

UserToken (lib/aprsme/accounts/user_token.ex)

Field Type Notes
id binary_id Primary key
token binary Bcrypt-hashed token
context string "session", "confirm", "reset_password", "change_email"
sent_to string Email or identifier
user_id binary_id FK → users.id

Public API

Registration

  • register_user/1 — Create user from registration params
  • change_user_registration/2 — Changeset for registration form

Authentication

  • get_user_by_email_and_password/2 — Verify credentials
  • generate_user_session_token/1 — Create session token
  • get_user_by_session_token/1 — Lookup user from token
  • delete_user_session_token/1 — Logout

Email Confirmation

  • deliver_user_confirmation_instructions/2 — Send confirmation email
  • confirm_user/1 — Mark user as confirmed

Password Reset

  • deliver_user_reset_password_instructions/2 — Send reset email
  • get_user_by_reset_password_token/1 — Validate reset token
  • reset_user_password/2 — Update password

Account Settings

  • change_user_email/2, update_user_email/2 — Email change flow
  • change_user_callsign/2, update_user_callsign/3 — Callsign management
  • change_user_password/2, update_user_password/3 — Password change

Email Delivery

Uses Aprsme.Accounts.UserNotifier which delegates to Aprsme.Mailer (Swoosh with custom Resend adapter).

Web Integration

  • AprsmeWeb.UserAuth module provides plug-based and LiveView on_mount hooks
  • Session stored in signed+encrypted cookie (_aprs_key)
  • "Remember me" cookie (60-day expiry, signed)
  • Token-based session with fixation prevention (renew on login/logout)

Notes

  • No FK relationship between userspackets
  • Authentication is optional; most pages are publicly accessible without login
  • Authenticated pages: /users/settings, /dashboard (LiveDashboard), /errors (ErrorTracker)