Agent skill

Phoenix Liveview Auth

by j-morgan6 in j-morgan6/elixir-phoenix-guide

A skill your agent uses when protecting LiveViews with authentication — onmount hooks, livesession, mountcurrentscope, auth redirect testing.

MITAuto-check passedAI & LLM Engineering

Install Phoenix Liveview Auth

skills CLI
$ npx skills add j-morgan6/elixir-phoenix-guide --skill phoenix-liveview-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install j-morgan6/elixir-phoenix-guide phoenix-liveview-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/j-morgan6/elixir-phoenix-guide.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/phoenix-liveview-auth .claude/skills/phoenix-liveview-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
phoenix-liveview-auth
GitHub stars
167
Token cost
~2.5k tokens
SKILL.md length
409 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when protecting LiveViews with authentication — onmount hooks, livesession, mountcurrentscope, auth redirect testing.

  • Works in 7 steps: Always use on_mount callbacks for… → Use mount_current_scope/2 to extract… → Handle both :cont and :halt returns from… → …
  • Protecting LiveViews with authentication — onmount hooks
  • SKILL.md covers RULES — Follow these with no…, on_mount Authentication Pattern, Router Integration and Import Conflict Resolution, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Phoenix Liveview Auth is an agent skill from j-morgan6/elixir-phoenix-guide. Use when protecting LiveViews with authentication — onmount hooks, livesession, mountcurrentscope, auth redirect testing.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering LLM observability and Authentication. The licence is MIT.

When your agent uses it

  • Protecting LiveViews with authentication — onmount hooks
  • Mountcurrentscope
  • Auth redirect testing

Example prompts

  • “/phoenix-liveview-auth”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Always use on_mount callbacks for LiveView auth — never check auth in mount/3 directly; on_mount runs before mount and centralizes auth…
  2. Use mount_current_scope/2 to extract scope from session — never access session tokens manually or parse session data in LiveViews
  3. Handle both :cont and :halt returns from on_mount — :halt must redirect with a flash message, never silently drop the connection
  4. Resolve Controller/LiveView name clashes the way the 1.8 generator does — UserAuth contains both conn plugs and on_mount hooks. Import…
  5. Guard the nil scope, not the assign lookup — mount_current_scope always assigns :current_scope, so @current_scope is safe; the hazard is…
  6. Test auth redirects by asserting {:error, {:redirect, %{to: path}}} — don't test auth by checking rendered content; verify the redirect…
  7. Define on_mount hooks once, reference via live_session in router — never duplicate auth logic across LiveView modules

What it can do on your machine

Read from SKILL.md and the folder at commit cdfddac. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are elixir).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Phoenix Liveview Auth loads about 2.5k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 409 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from j-morgan6/elixir-phoenix-guide at commit cdfddac, republished under its MIT licence (© j-morgan6). 409 words, ~2,465 tokens.

Download SKILL.mdSave it as .claude/skills/phoenix-liveview-auth/SKILL.md (or your agent's skills folder).
name
phoenix-liveview-auth
description
Use when protecting LiveViews with authentication — on_mount hooks, live_session, mount_current_scope, auth redirect testing.
file_patterns
**/*_live.ex, **/*_live/*.ex, **/user_auth.ex
auto_suggest
true

Phoenix LiveView Authentication

RULES — Follow these with no exceptions

  1. Always use on_mount callbacks for LiveView auth — never check auth in mount/3 directly; on_mount runs before mount and centralizes auth logic
  2. Use mount_current_scope/2 to extract scope from session — never access session tokens manually or parse session data in LiveViews
  3. Handle both :cont and :halt returns from on_mount — :halt must redirect with a flash message, never silently drop the connection
  4. Resolve Controller/LiveView name clashes the way the 1.8 generator does — UserAuth contains both conn plugs and on_mount hooks. Import Phoenix.Controller normally (the plugs need redirect/2), and fully qualify the LiveView calls inside on_mount hooks: Phoenix.LiveView.redirect(socket, to: ...) and Phoenix.LiveView.put_flash(socket, :error, ...). Excluding the Controller imports breaks the plug half of the module.
  5. Guard the nil scope, not the assign lookup — mount_current_scope always assigns :current_scope, so @current_scope is safe; the hazard is calling .user on a nil scope. Write @current_scope && @current_scope.user. Bracket access assigns[:current_scope] is only needed when the assign may be entirely absent (e.g. layouts shared with non-auth live_sessions).
  6. Test auth redirects by asserting {:error, {:redirect, %{to: path}}} — don't test auth by checking rendered content; verify the redirect tuple from live/2
  7. Define on_mount hooks once, reference via live_session in router — never duplicate auth logic across LiveView modules

on_mount Authentication Pattern

The standard pattern for LiveView authentication. Define once, use everywhere via live_session.

elixir
defmodule MyAppWeb.UserAuth do
  use MyAppWeb, :verified_routes
  import Plug.Conn
  import Phoenix.Controller

  # Called by live_session :require_authenticated_user
  def on_mount(:require_authenticated_user, _params, session, socket) do
    socket = mount_current_scope(socket, session)

    if socket.assigns.current_scope && socket.assigns.current_scope.user do
      {:cont, socket}
    else
      socket =
        socket
        |> Phoenix.LiveView.put_flash(:error, "You must log in to access this page.")
        |> Phoenix.LiveView.redirect(to: ~p"/users/log-in")

      {:halt, socket}
    end
  end

  # Called by live_session :redirect_if_authenticated
  def on_mount(:redirect_if_authenticated, _params, session, socket) do
    socket = mount_current_scope(socket, session)

    if socket.assigns.current_scope && socket.assigns.current_scope.user do
      {:halt, Phoenix.LiveView.redirect(socket, to: ~p"/")}
    else
      {:cont, socket}
    end
  end

  # Conn plug — needs the plain Phoenix.Controller redirect/2
  def require_authenticated_user(conn, _opts) do
    if conn.assigns[:current_scope] && conn.assigns.current_scope.user do
      conn
    else
      conn
      |> put_flash(:error, "You must log in to access this page.")
      |> redirect(to: ~p"/users/log-in")
      |> halt()
    end
  end

  # Called by live_session :mount_current_scope (public pages)
  def on_mount(:mount_current_scope, _params, session, socket) do
    {:cont, mount_current_scope(socket, session)}
  end

  defp mount_current_scope(socket, session) do
    Phoenix.Component.assign_new(socket, :current_scope, fn ->
      if user = find_user_from_session(session) do
        %Scope{user: user}
      end
    end)
  end

  defp find_user_from_session(%{"user_token" => token}) do
    Accounts.get_user_by_session_token(token)
  end

  defp find_user_from_session(_session), do: nil
end

Router Integration

Use live_session to apply on_mount hooks to groups of LiveViews. Each session shares auth requirements.

elixir
defmodule MyAppWeb.Router do
  use MyAppWeb, :router

  # Public pages — scope is mounted but not required
  live_session :mount_current_scope,
    on_mount: [{MyAppWeb.UserAuth, :mount_current_scope}] do
    scope "/", MyAppWeb do
      pipe_through :browser

      live "/", HomeLive.Index
    end
  end

  # Authenticated pages — redirects to login if not authenticated
  live_session :require_authenticated_user,
    on_mount: [{MyAppWeb.UserAuth, :require_authenticated_user}] do
    scope "/", MyAppWeb do
      pipe_through [:browser, :require_authenticated_user]

      live "/dashboard", DashboardLive.Index
      live "/settings", SettingsLive.Index
    end
  end

  # Guest-only pages — redirects to home if already authenticated
  live_session :redirect_if_authenticated,
    on_mount: [{MyAppWeb.UserAuth, :redirect_if_authenticated}] do
    scope "/", MyAppWeb do
      pipe_through [:browser, :redirect_if_authenticated]

      live "/users/register", UserRegistrationLive
      live "/users/log-in", UserLoginLive
    end
  end
end

Show full SKILL.md (167 more words)Show less

Import Conflict Resolution

Phoenix.Controller and Phoenix.LiveView both export redirect/2 and put_flash/3. UserAuth needs both — conn plugs for the router pipeline, and on_mount hooks for LiveView — so excluding one side's imports breaks the other half of the module. The 1.8 generator resolves this by importing Phoenix.Controller normally and fully qualifying the LiveView calls:

elixir
# Bad — excluding Phoenix.Controller breaks the plug functions,
# which need plain redirect/2 and put_flash/3
import Phoenix.LiveView
import Phoenix.Controller, except: [redirect: 2, put_flash: 3]

# Good — import Phoenix.Controller normally for the plugs;
# fully qualify inside on_mount hooks instead
import Phoenix.Controller

def on_mount(:require_authenticated_user, _params, session, socket) do
  # ...
  Phoenix.LiveView.redirect(socket, to: ~p"/")
  Phoenix.LiveView.put_flash(socket, :error, "...")
end

def require_authenticated_user(conn, _opts) do
  # plain redirect/2 and put_flash/3 here come from Phoenix.Controller
  conn |> put_flash(:error, "...") |> redirect(to: ~p"/users/log-in")
end

current_scope vs current_user

Phoenix 1.8+ uses Scope structs instead of raw current_user. The scope wraps the user and can carry additional context.

elixir
# Phoenix 1.8+ pattern — Scope struct
defmodule MyApp.Scope do
  defstruct [:user]
end

# In LiveView — access user through scope
def mount(_params, _session, socket) do
  user = socket.assigns.current_scope.user
  {:ok, assign(socket, :posts, Posts.list_posts(user))}
end

# In templates — @current_scope is always assigned once on_mount has
# run, so dot access is safe; guard .user since the scope may wrap no user
<%= if @current_scope && @current_scope.user do %>
  <p>Welcome, <%= @current_scope.user.email %></p>
<% end %>

Guarding a Nil Scope

mount_current_scope/2 always assigns :current_scope (via assign_new), so @current_scope is safe to dot-access once an on_mount hook has run. The real hazard is calling .user when nobody is logged in — the scope itself is non-nil, but scope.user is nil.

elixir
# Bad — crashes when current_scope.user is nil (guest visitor)
<%= @current_scope.user.email %>

# Good — guard .user, not the current_scope lookup
<%= if @current_scope && @current_scope.user do %>
  <%= @current_scope.user.email %>
<% end %>

Bracket access assigns[:current_scope] is only needed when the assign may be entirely absent — for example, a layout shared with a live_session that never runs the mount_current_scope on_mount hook:

elixir
<%= if assigns[:current_scope] && @current_scope.user do %>
  <%= @current_scope.user.email %>
<% end %>

Testing LiveView Auth

Testing Protected Routes
elixir
describe "require_authenticated_user" do
  test "redirects if not logged in", %{conn: conn} do
    assert {:error, {:redirect, %{to: "/users/log-in"}}} =
             live(conn, ~p"/dashboard")
  end

  test "renders page when authenticated", %{conn: conn} do
    user = user_fixture()
    conn = log_in_user(conn, user)

    {:ok, _lv, html} = live(conn, ~p"/dashboard")
    assert html =~ "Dashboard"
  end
end

describe "redirect_if_authenticated" do
  test "redirects if already logged in", %{conn: conn} do
    user = user_fixture()
    conn = log_in_user(conn, user)

    assert {:error, {:redirect, %{to: "/"}}} =
             live(conn, ~p"/users/log-in")
  end
end
Testing on_mount Directly
elixir
describe "on_mount: :require_authenticated_user" do
  test "authenticates user from session", %{conn: conn} do
    user = user_fixture()
    token = Accounts.generate_user_session_token(user)

    assert {:cont, updated_socket} =
             UserAuth.on_mount(
               :require_authenticated_user,
               %{},
               %{"user_token" => token},
               %LiveView.Socket{
                 endpoint: MyAppWeb.Endpoint,
                 assigns: %{__changed__: %{}}
               }
             )

    assert updated_socket.assigns.current_scope.user.id == user.id
  end

  test "redirects when no session token" do
    assert {:halt, updated_socket} =
             UserAuth.on_mount(
               :require_authenticated_user,
               %{},
               %{},
               %LiveView.Socket{
                 endpoint: MyAppWeb.Endpoint,
                 assigns: %{__changed__: %{}, flash: %{}}
               }
             )

    assert updated_socket.redirected == {:redirect, %{to: "/users/log-in"}}
  end
end

See testing-essentials skill for comprehensive testing patterns. See phoenix-authorization-patterns skill for authorization after authentication.

© j-morgan6, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/phoenix-liveview-auth of j-morgan6/elixir-phoenix-guide.

Open the folder on GitHubat commit cdfddac

Compare with similar skills

Phoenix Liveview Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Phoenix Liveview Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Phoenix Liveview Auth this skillj-morgan6/elixir-phoenix-guide167—~2.5kAutomated safety check: PassMIT
Elixir Expertpass-agent/loomkin1811 repos~796Automated safety check: PassMIT
Hex Docs Searchbradleygolden/claude-marketplace-elixir176—~4.1kAutomated safety check: NotesMIT
Oci Data Scienceoracle/accelerated-data-science125—~2.1kAutomated safety check: PassUPL-1.0
HTTP Toolkit InterceptFactory-AI/factory-plugins111—~2.5kAutomated safety check: PassNone
Phoenix Contextsoliver-kriska/claude-elixir-phoenix565—~841Automated safety check: PassMIT

Similar skills

  • Elixir Expert

    pass-agent/loomkin

    Expert in Elixir, Phoenix Framework, and OTP. An agent skill from pass-agent/loomkin.

    181 GitHub starsUsed in 1 repo~796 tokens
    AI & LLM EngineeringAuto-check passed
  • Hex Docs Search

    bradleygolden/claude-marketplace-elixir

    Research Hex packages (Sobelow, Phoenix, Ecto, Credo, Ash, etc).

    176 GitHub stars~4.1k tokensUpdated 9 mo ago
    AI & LLM EngineeringAuto-check: notes
  • Oci Data Science

    oracle/accelerated-data-science

    Official

    OCI Data Science service patterns including Jobs, Pipelines, Model Catalog, authentication, and the ADS SDK beyond AQUA.

    125 GitHub stars~2.1k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • HTTP Toolkit Intercept

    Factory-AI/factory-plugins

    Intercept and debug HTTP traffic from any CLI, service, or script using HTTP Toolkit.

    111 GitHub stars~2.5k tokensUpdated 3 days ago
    AI & LLM EngineeringAuto-check passed
  • Phoenix Contexts

    oliver-kriska/claude-elixir-phoenix

    Phoenix context design — creating/splitting contexts, Scope (1.8+), Ecto.Multi, PubSub, routers, plugs, controllers.

    565 GitHub stars~841 tokensUpdated 4 days ago
    AI & LLM EngineeringAuto-check passed
  • Security

    oliver-kriska/claude-elixir-phoenix

    Build and harden Phoenix auth and security — OAuth login, password hashing, sessions, RBAC, rate limiting, CSRF, XSS, SQL injection, secrets.

    565 GitHub stars~1k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

More from j-morgan6/elixir-phoenix-guide

All 19 skills in this repo
  • Code Quality

    j-morgan6/elixir-phoenix-guide

    A skill your agent uses when refactoring for duplication, complexity, or dead code — includes the plugin's on-demand analysis scripts.

    167 GitHub stars~1.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Deployment Gotchas

    j-morgan6/elixir-phoenix-guide

    A skill your agent uses when preparing releases or deployment config — runtime.exs vs compile-time config, release migrations, PHXHOST/PHXSERVER, assets, health checks.

    167 GitHub stars~2.6k tokensUpdated 3 mo ago
    Auto-check passed
  • Ecto Changeset Patterns

    j-morgan6/elixir-phoenix-guide

    A skill your agent uses when a resource needs multiple changesets (registration vs update), conditional validation, field transforms, or uniqueness validation — changeset composition.

    167 GitHub stars~2.1k tokensUpdated 3 mo ago
    Auto-check passed
  • Ecto Essentials

    j-morgan6/elixir-phoenix-guide

    A skill your agent uses when defining schemas, writing queries, or creating migrations — schema design, Repo usage, indexes, query composition.

    167 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Ecto Nested Associations

    j-morgan6/elixir-phoenix-guide

    A skill your agent uses when a form or operation manages parent and child records together — castassoc/castembed, onreplace, Ecto.Multi across tables, FK cascade design.

    167 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Elixir Essentials

    j-morgan6/elixir-phoenix-guide

    A skill your agent uses when writing or refactoring core Elixir — pattern matching, case/cond/with, pipes, {:ok, }/{:error, } contracts.

    167 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Phoenix Liveview Auth

What does Phoenix Liveview Auth do?

A skill your agent uses when protecting LiveViews with authentication — onmount hooks, livesession, mountcurrentscope, auth redirect testing. Phoenix Liveview Auth is an agent skill from j-morgan6/elixir-phoenix-guide. Use when protecting LiveViews with authentication — onmount hooks, livesession, mountcurrentscope, auth redirect testing.

When should I use Phoenix Liveview Auth?

Phoenix Liveview Auth fits situations like: protecting LiveViews with authentication — onmount hooks; mountcurrentscope; auth redirect testing.

How do I install Phoenix Liveview Auth in Claude Code?

Run `npx skills add j-morgan6/elixir-phoenix-guide --skill phoenix-liveview-auth -a claude-code`. Or copy the skill folder (skills/phoenix-liveview-auth in j-morgan6/elixir-phoenix-guide) into .claude/skills/phoenix-liveview-auth in your project. Claude Code loads it when a task matches its description.

How do I install Phoenix Liveview Auth in Codex?

Run `npx skills add j-morgan6/elixir-phoenix-guide --skill phoenix-liveview-auth -a codex`. Or copy the skill folder (skills/phoenix-liveview-auth in j-morgan6/elixir-phoenix-guide) into .agents/skills/phoenix-liveview-auth in your project. Codex loads it when a task matches its description.

Can I use Phoenix Liveview Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add j-morgan6/elixir-phoenix-guide --skill phoenix-liveview-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phoenix-liveview-auth, .gemini/skills/phoenix-liveview-auth, .github/skills/phoenix-liveview-auth and .opencode/skills/phoenix-liveview-auth in your project.

What does Phoenix Liveview Auth need to run?

SKILL.md names no scripts, command-line tools or credentials: Phoenix Liveview Auth is instructions for the agent only.

Does Phoenix Liveview Auth access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Phoenix Liveview Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Phoenix Liveview Auth use?

Phoenix Liveview Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Phoenix Liveview Auth use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Phoenix Liveview Auth?

Skills that share tags, products or a category with Phoenix Liveview Auth: Elixir Expert (pass-agent/loomkin, 181 stars), Hex Docs Search (bradleygolden/claude-marketplace-elixir, 176 stars), Oci Data Science (oracle/accelerated-data-science, 125 stars) and HTTP Toolkit Intercept (Factory-AI/factory-plugins, 111 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Phoenix Liveview Auth?

j-morgan6 (a GitHub user) maintains it in j-morgan6/elixir-phoenix-guide, which has 167 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on July 6, 2026.

Source: j-morgan6/elixir-phoenix-guide on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.