Auth module for Lift using MongoDB
Scala HTML Shell
Latest commit 5d66122 Dec 31, 2016 @eltimn Updated link in readme
Failed to load latest commit information.
project Added Scala 2.12 support. Dec 31, 2016
.gitignore Bumped version to 0.5-SNAPSHOT Feb 25, 2013
.travis.yml Updated link in readme Jan 1, 2017
LICENSE.txt Added license Nov 2, 2011
build.sbt Added a version.sbt file Dec 31, 2016
docker-compose.yml Added script Dec 31, 2016

MongoAuth Lift Module

Build Status

Authentication and Authorization module for Lift-MongoDB-Record.


Releases uses the Lift "edition" in the name. For example, if you use any of 2.5-SNAPSHOT, 2.5-RC4, or 2.5 the Lift edition is 2.5.

Note: some of the versions published had a '-' in the edition instead of a '.'. I.e extras_2-5 instead of extras_2.3.

For Lift 3.0 (Scala 2.11, 2.12):

libraryDependencies += "net.liftmodules" %% "mongoauth_3.0" % "1.2"

For Lift 2.5.x (Scala 2.9 and 2.10):

libraryDependencies += "net.liftmodules" %% "mongoauth_2.5" % "0.5"

For Lift <= 2.6-M3 (Scala 2.9 and Scala 2.10):

libraryDependencies += "net.liftmodules" %% "mongoauth_2.6" % "0.5"

For Lift => 2.6-M4 (Scala 2.10, 2.11):

libraryDependencies += "net.liftmodules" %% "mongoauth_2.6" % "0.7"


You must set the MongoAuth.authUserMeta object that you will be using (see below). Most likely in boot:

// init mongoauth

See MongoAuth for other settings that can be overriden.

You will also probably want to add the logout and login-token menus.

) :_*))

Creating a User Data Model

This module provides several traits for constructing user model classes, which include roles and permissions.

There are several ways you can utilize this module:


model.SimpleUser is a fully implemented user model, but is not extensible in any way. This is only useful for testing and demos. This shows what is necessary to create a user from ProtoAuthUser.


ProtoAuthUser and ProtoAuthUserMeta are a pair of traits that can be used to build a user model class and meta object. ProtoAuthUser has some standard fields. You can add fields to it, but you can't modify the ones provided. This is a good place to start. If you find you need to modify the provided fields, you can copy and paste them into your user class and use MongoAuthUser.


MongoAuthUser is a trait for defining a MongoRecord of AuthUser (provides authorization functionality). This can be used to build a user class from scratch. It only requires id and email fields.


ProtoAuthUserMeta is a combination of AuthUserMeta and UserLifeCycle traits. These provide authorization functionality and login/logout functionality for MongoMetaRecord objects. No matter which version you use for the MongoRecord user class, you can use this trait to define your MongoMetaRecord, if it provides sufficient functionality.

"Remember Me" functionality is provided by ExtSession.

LoginToken provides a way for users that forgot their password to log in and change it. Users are sent a link with a token (an ObjectId) on the url. When they click on it they can be handled appropriately. The implementation is left up to you.

Roles and Permissions

Permissions are defined using a simple case class. They have three parts; domain, actions, entities. This was heavily influenced by Apache Shiro's WildcardPermission. Please see the JavaDoc for WildcardPermission for detailed information.

See PermissionSpec for examples.

PermissionListField provides a way to store permissions for a user. It stores them as a list of strings.


user.permissions(List(Permission("printer", "print"), Permission("user", "edit", "123")))

assert(User.hasPermission(Permission("printer", "manage")) == false)

Role is a MongoRecord that provides a way to group a set of permissions. A user's full set of permissions is calculated using the permissions from any roles assigned to them and the individual permissions assigned to them. There are also LocParams as well as the User-Meta-Singleton that can be used to check for roles.


val superuser ="superuser").permissions(List(Permission.all)).save


assert(User.hasRole("superuser")) == true)
assert(User.lacksRole("superuser")) == false)
assert(User.lacksRole("admin")) == true)

SiteMap LocParams

The Locs trait and companion object provide some useful LocParams that use can use when defing your SiteMap.

This code was inspired by the lift-shiro module.


Meun.i("Settings") / "settings" >> RequireLoggedIn
Meun.i("Password") / "password" >> RequireAuthentication
Meun.i("Admin") / "admin" >> HasRole("admin")
Meun.i("EditEntitiy") / "admin" / "entity" >> HasPermission(Permission("entity", "edit"))

"Authenticated" means the user logged in by supplying their password. "Logged In" means the user was logged in by either an ExtSession or LoginToken, or they are Authenticated.


A default localization is provided and can be found here. If you require another language or would prefer different text, copy the default and subtitute your values. See the Localization page on the Liftweb wiki for more information.

Example Implementation

The lift-mongo giter8 template provides a fully functioning implementation of a basic user system.


Apache v2.0. See LICENSE.txt