Elixir Expert
pass-agent/loomkin
Expert in Elixir, Phoenix Framework, and OTP. An agent skill from pass-agent/loomkin.
A skill your agent uses when protecting LiveViews with authentication — onmount hooks, livesession, mountcurrentscope, auth redirect testing.
$ npx skills add j-morgan6/elixir-phoenix-guide --skill phoenix-liveview-auth -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install j-morgan6/elixir-phoenix-guide phoenix-liveview-auth --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/j-morgan6/elixir-phoenix-guide.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/phoenix-liveview-auth .claude/skills/phoenix-liveview-auth && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "phoenix-liveview-auth" agent skill from https://github.com/j-morgan6/elixir-phoenix-guide/tree/main/skills/phoenix-liveview-auth into .claude/skills/phoenix-liveview-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phoenix-liveview-auth", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/j-morgan6/elixir-phoenix-guide/tree/main/skills/phoenix-liveview-authType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add j-morgan6/elixir-phoenix-guide --skill phoenix-liveview-auth -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install j-morgan6/elixir-phoenix-guide phoenix-liveview-auth --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/j-morgan6/elixir-phoenix-guide.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/phoenix-liveview-auth .agents/skills/phoenix-liveview-auth && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "phoenix-liveview-auth" agent skill from https://github.com/j-morgan6/elixir-phoenix-guide/tree/main/skills/phoenix-liveview-auth into .agents/skills/phoenix-liveview-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phoenix-liveview-auth", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add j-morgan6/elixir-phoenix-guide --skill phoenix-liveview-auth -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install j-morgan6/elixir-phoenix-guide phoenix-liveview-auth --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/j-morgan6/elixir-phoenix-guide.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/phoenix-liveview-auth .cursor/skills/phoenix-liveview-auth && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "phoenix-liveview-auth" agent skill from https://github.com/j-morgan6/elixir-phoenix-guide/tree/main/skills/phoenix-liveview-auth into .cursor/skills/phoenix-liveview-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phoenix-liveview-auth", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/j-morgan6/elixir-phoenix-guide.git --path skills/phoenix-liveview-auth--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add j-morgan6/elixir-phoenix-guide --skill phoenix-liveview-auth -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install j-morgan6/elixir-phoenix-guide phoenix-liveview-auth --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/j-morgan6/elixir-phoenix-guide.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/phoenix-liveview-auth .gemini/skills/phoenix-liveview-auth && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "phoenix-liveview-auth" agent skill from https://github.com/j-morgan6/elixir-phoenix-guide/tree/main/skills/phoenix-liveview-auth into .gemini/skills/phoenix-liveview-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phoenix-liveview-auth", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install j-morgan6/elixir-phoenix-guide phoenix-liveview-authInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add j-morgan6/elixir-phoenix-guide --skill phoenix-liveview-auth -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/j-morgan6/elixir-phoenix-guide.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/phoenix-liveview-auth .github/skills/phoenix-liveview-auth && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "phoenix-liveview-auth" agent skill from https://github.com/j-morgan6/elixir-phoenix-guide/tree/main/skills/phoenix-liveview-auth into .github/skills/phoenix-liveview-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phoenix-liveview-auth", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add j-morgan6/elixir-phoenix-guide --skill phoenix-liveview-auth -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install j-morgan6/elixir-phoenix-guide phoenix-liveview-auth --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/j-morgan6/elixir-phoenix-guide.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/phoenix-liveview-auth .opencode/skills/phoenix-liveview-auth && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "phoenix-liveview-auth" agent skill from https://github.com/j-morgan6/elixir-phoenix-guide/tree/main/skills/phoenix-liveview-auth into .opencode/skills/phoenix-liveview-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phoenix-liveview-auth", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
phoenix-liveview-authA skill your agent uses when protecting LiveViews with authentication — onmount hooks, livesession, mountcurrentscope, auth redirect testing.
Phoenix Liveview Auth is an agent skill from j-morgan6/elixir-phoenix-guide. Use when protecting LiveViews with authentication — onmount hooks, livesession, mountcurrentscope, auth redirect testing.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in AI & LLM Engineering, covering LLM observability and Authentication. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit cdfddac. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are elixir).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Phoenix Liveview Auth loads about 2.5k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 409 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from j-morgan6/elixir-phoenix-guide at commit cdfddac, republished under its MIT licence (© j-morgan6). 409 words, ~2,465 tokens.
.claude/skills/phoenix-liveview-auth/SKILL.md (or your agent's skills folder).on_mount callbacks for LiveView auth — never check auth in mount/3 directly; on_mount runs before mount and centralizes auth logicmount_current_scope/2 to extract scope from session — never access session tokens manually or parse session data in LiveViews:cont and :halt returns from on_mount — :halt must redirect with a flash message, never silently drop the connectionUserAuth contains both conn plugs and on_mount hooks. Import Phoenix.Controller normally (the plugs need redirect/2), and fully qualify the LiveView calls inside on_mount hooks: Phoenix.LiveView.redirect(socket, to: ...) and Phoenix.LiveView.put_flash(socket, :error, ...). Excluding the Controller imports breaks the plug half of the module.mount_current_scope always assigns :current_scope, so @current_scope is safe; the hazard is calling .user on a nil scope. Write @current_scope && @current_scope.user. Bracket access assigns[:current_scope] is only needed when the assign may be entirely absent (e.g. layouts shared with non-auth live_sessions).{:error, {:redirect, %{to: path}}} — don't test auth by checking rendered content; verify the redirect tuple from live/2on_mount hooks once, reference via live_session in router — never duplicate auth logic across LiveView modulesThe standard pattern for LiveView authentication. Define once, use everywhere via live_session.
defmodule MyAppWeb.UserAuth do
use MyAppWeb, :verified_routes
import Plug.Conn
import Phoenix.Controller
# Called by live_session :require_authenticated_user
def on_mount(:require_authenticated_user, _params, session, socket) do
socket = mount_current_scope(socket, session)
if socket.assigns.current_scope && socket.assigns.current_scope.user do
{:cont, socket}
else
socket =
socket
|> Phoenix.LiveView.put_flash(:error, "You must log in to access this page.")
|> Phoenix.LiveView.redirect(to: ~p"/users/log-in")
{:halt, socket}
end
end
# Called by live_session :redirect_if_authenticated
def on_mount(:redirect_if_authenticated, _params, session, socket) do
socket = mount_current_scope(socket, session)
if socket.assigns.current_scope && socket.assigns.current_scope.user do
{:halt, Phoenix.LiveView.redirect(socket, to: ~p"/")}
else
{:cont, socket}
end
end
# Conn plug — needs the plain Phoenix.Controller redirect/2
def require_authenticated_user(conn, _opts) do
if conn.assigns[:current_scope] && conn.assigns.current_scope.user do
conn
else
conn
|> put_flash(:error, "You must log in to access this page.")
|> redirect(to: ~p"/users/log-in")
|> halt()
end
end
# Called by live_session :mount_current_scope (public pages)
def on_mount(:mount_current_scope, _params, session, socket) do
{:cont, mount_current_scope(socket, session)}
end
defp mount_current_scope(socket, session) do
Phoenix.Component.assign_new(socket, :current_scope, fn ->
if user = find_user_from_session(session) do
%Scope{user: user}
end
end)
end
defp find_user_from_session(%{"user_token" => token}) do
Accounts.get_user_by_session_token(token)
end
defp find_user_from_session(_session), do: nil
endUse live_session to apply on_mount hooks to groups of LiveViews. Each session shares auth requirements.
defmodule MyAppWeb.Router do
use MyAppWeb, :router
# Public pages — scope is mounted but not required
live_session :mount_current_scope,
on_mount: [{MyAppWeb.UserAuth, :mount_current_scope}] do
scope "/", MyAppWeb do
pipe_through :browser
live "/", HomeLive.Index
end
end
# Authenticated pages — redirects to login if not authenticated
live_session :require_authenticated_user,
on_mount: [{MyAppWeb.UserAuth, :require_authenticated_user}] do
scope "/", MyAppWeb do
pipe_through [:browser, :require_authenticated_user]
live "/dashboard", DashboardLive.Index
live "/settings", SettingsLive.Index
end
end
# Guest-only pages — redirects to home if already authenticated
live_session :redirect_if_authenticated,
on_mount: [{MyAppWeb.UserAuth, :redirect_if_authenticated}] do
scope "/", MyAppWeb do
pipe_through [:browser, :redirect_if_authenticated]
live "/users/register", UserRegistrationLive
live "/users/log-in", UserLoginLive
end
end
endPhoenix.Controller and Phoenix.LiveView both export redirect/2 and put_flash/3. UserAuth needs both — conn plugs for the router pipeline, and on_mount hooks for LiveView — so excluding one side's imports breaks the other half of the module. The 1.8 generator resolves this by importing Phoenix.Controller normally and fully qualifying the LiveView calls:
# Bad — excluding Phoenix.Controller breaks the plug functions,
# which need plain redirect/2 and put_flash/3
import Phoenix.LiveView
import Phoenix.Controller, except: [redirect: 2, put_flash: 3]
# Good — import Phoenix.Controller normally for the plugs;
# fully qualify inside on_mount hooks instead
import Phoenix.Controller
def on_mount(:require_authenticated_user, _params, session, socket) do
# ...
Phoenix.LiveView.redirect(socket, to: ~p"/")
Phoenix.LiveView.put_flash(socket, :error, "...")
end
def require_authenticated_user(conn, _opts) do
# plain redirect/2 and put_flash/3 here come from Phoenix.Controller
conn |> put_flash(:error, "...") |> redirect(to: ~p"/users/log-in")
endPhoenix 1.8+ uses Scope structs instead of raw current_user. The scope wraps the user and can carry additional context.
# Phoenix 1.8+ pattern — Scope struct
defmodule MyApp.Scope do
defstruct [:user]
end
# In LiveView — access user through scope
def mount(_params, _session, socket) do
user = socket.assigns.current_scope.user
{:ok, assign(socket, :posts, Posts.list_posts(user))}
end
# In templates — @current_scope is always assigned once on_mount has
# run, so dot access is safe; guard .user since the scope may wrap no user
<%= if @current_scope && @current_scope.user do %>
<p>Welcome, <%= @current_scope.user.email %></p>
<% end %>mount_current_scope/2 always assigns :current_scope (via assign_new), so @current_scope is safe to dot-access once an on_mount hook has run. The real hazard is calling .user when nobody is logged in — the scope itself is non-nil, but scope.user is nil.
# Bad — crashes when current_scope.user is nil (guest visitor)
<%= @current_scope.user.email %>
# Good — guard .user, not the current_scope lookup
<%= if @current_scope && @current_scope.user do %>
<%= @current_scope.user.email %>
<% end %>Bracket access assigns[:current_scope] is only needed when the assign may be entirely absent — for example, a layout shared with a live_session that never runs the mount_current_scope on_mount hook:
<%= if assigns[:current_scope] && @current_scope.user do %>
<%= @current_scope.user.email %>
<% end %>describe "require_authenticated_user" do
test "redirects if not logged in", %{conn: conn} do
assert {:error, {:redirect, %{to: "/users/log-in"}}} =
live(conn, ~p"/dashboard")
end
test "renders page when authenticated", %{conn: conn} do
user = user_fixture()
conn = log_in_user(conn, user)
{:ok, _lv, html} = live(conn, ~p"/dashboard")
assert html =~ "Dashboard"
end
end
describe "redirect_if_authenticated" do
test "redirects if already logged in", %{conn: conn} do
user = user_fixture()
conn = log_in_user(conn, user)
assert {:error, {:redirect, %{to: "/"}}} =
live(conn, ~p"/users/log-in")
end
enddescribe "on_mount: :require_authenticated_user" do
test "authenticates user from session", %{conn: conn} do
user = user_fixture()
token = Accounts.generate_user_session_token(user)
assert {:cont, updated_socket} =
UserAuth.on_mount(
:require_authenticated_user,
%{},
%{"user_token" => token},
%LiveView.Socket{
endpoint: MyAppWeb.Endpoint,
assigns: %{__changed__: %{}}
}
)
assert updated_socket.assigns.current_scope.user.id == user.id
end
test "redirects when no session token" do
assert {:halt, updated_socket} =
UserAuth.on_mount(
:require_authenticated_user,
%{},
%{},
%LiveView.Socket{
endpoint: MyAppWeb.Endpoint,
assigns: %{__changed__: %{}, flash: %{}}
}
)
assert updated_socket.redirected == {:redirect, %{to: "/users/log-in"}}
end
endSee testing-essentials skill for comprehensive testing patterns.
See phoenix-authorization-patterns skill for authorization after authentication.
© j-morgan6, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/phoenix-liveview-auth of j-morgan6/elixir-phoenix-guide.
Open the folder on GitHubat commit cdfddac
Phoenix Liveview Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Phoenix Liveview Auth this skillj-morgan6/elixir-phoenix-guide | 167 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Elixir Expertpass-agent/loomkin | 181 | 1 repos | ~796 | Automated safety check: Pass | MIT | |
| Hex Docs Searchbradleygolden/claude-marketplace-elixir | 176 | — | ~4.1k | Automated safety check: Notes | MIT | |
| Oci Data Scienceoracle/accelerated-data-science | 125 | — | ~2.1k | Automated safety check: Pass | UPL-1.0 | |
| HTTP Toolkit InterceptFactory-AI/factory-plugins | 111 | — | ~2.5k | Automated safety check: Pass | None | |
| Phoenix Contextsoliver-kriska/claude-elixir-phoenix | 565 | — | ~841 | Automated safety check: Pass | MIT |
pass-agent/loomkin
Expert in Elixir, Phoenix Framework, and OTP. An agent skill from pass-agent/loomkin.
bradleygolden/claude-marketplace-elixir
Research Hex packages (Sobelow, Phoenix, Ecto, Credo, Ash, etc).
oracle/accelerated-data-science
OCI Data Science service patterns including Jobs, Pipelines, Model Catalog, authentication, and the ADS SDK beyond AQUA.
Factory-AI/factory-plugins
Intercept and debug HTTP traffic from any CLI, service, or script using HTTP Toolkit.
oliver-kriska/claude-elixir-phoenix
Phoenix context design — creating/splitting contexts, Scope (1.8+), Ecto.Multi, PubSub, routers, plugs, controllers.
oliver-kriska/claude-elixir-phoenix
Build and harden Phoenix auth and security — OAuth login, password hashing, sessions, RBAC, rate limiting, CSRF, XSS, SQL injection, secrets.
j-morgan6/elixir-phoenix-guide
A skill your agent uses when refactoring for duplication, complexity, or dead code — includes the plugin's on-demand analysis scripts.
j-morgan6/elixir-phoenix-guide
A skill your agent uses when preparing releases or deployment config — runtime.exs vs compile-time config, release migrations, PHXHOST/PHXSERVER, assets, health checks.
j-morgan6/elixir-phoenix-guide
A skill your agent uses when a resource needs multiple changesets (registration vs update), conditional validation, field transforms, or uniqueness validation — changeset composition.
j-morgan6/elixir-phoenix-guide
A skill your agent uses when defining schemas, writing queries, or creating migrations — schema design, Repo usage, indexes, query composition.
j-morgan6/elixir-phoenix-guide
A skill your agent uses when a form or operation manages parent and child records together — castassoc/castembed, onreplace, Ecto.Multi across tables, FK cascade design.
j-morgan6/elixir-phoenix-guide
A skill your agent uses when writing or refactoring core Elixir — pattern matching, case/cond/with, pipes, {:ok, }/{:error, } contracts.
Categories
A skill your agent uses when protecting LiveViews with authentication — onmount hooks, livesession, mountcurrentscope, auth redirect testing. Phoenix Liveview Auth is an agent skill from j-morgan6/elixir-phoenix-guide. Use when protecting LiveViews with authentication — onmount hooks, livesession, mountcurrentscope, auth redirect testing.
Phoenix Liveview Auth fits situations like: protecting LiveViews with authentication — onmount hooks; mountcurrentscope; auth redirect testing.
Run `npx skills add j-morgan6/elixir-phoenix-guide --skill phoenix-liveview-auth -a claude-code`. Or copy the skill folder (skills/phoenix-liveview-auth in j-morgan6/elixir-phoenix-guide) into .claude/skills/phoenix-liveview-auth in your project. Claude Code loads it when a task matches its description.
Run `npx skills add j-morgan6/elixir-phoenix-guide --skill phoenix-liveview-auth -a codex`. Or copy the skill folder (skills/phoenix-liveview-auth in j-morgan6/elixir-phoenix-guide) into .agents/skills/phoenix-liveview-auth in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add j-morgan6/elixir-phoenix-guide --skill phoenix-liveview-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phoenix-liveview-auth, .gemini/skills/phoenix-liveview-auth, .github/skills/phoenix-liveview-auth and .opencode/skills/phoenix-liveview-auth in your project.
SKILL.md names no scripts, command-line tools or credentials: Phoenix Liveview Auth is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Phoenix Liveview Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Phoenix Liveview Auth: Elixir Expert (pass-agent/loomkin, 181 stars), Hex Docs Search (bradleygolden/claude-marketplace-elixir, 176 stars), Oci Data Science (oracle/accelerated-data-science, 125 stars) and HTTP Toolkit Intercept (Factory-AI/factory-plugins, 111 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
j-morgan6 (a GitHub user) maintains it in j-morgan6/elixir-phoenix-guide, which has 167 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on July 6, 2026.
Source: j-morgan6/elixir-phoenix-guide on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.