Skip to main content

ChatLogin

ChatLogin 是面向 Python-backed 网站的可复用登录能力包:后端统一处理身份、认证、会话、CSRF、回跳和角色边界;前端可以使用默认模板、覆盖模板/CSS,或保留网站原有 HTML/JS 走 headless JSON API。

文档入口:https://arch.gh.wzhecnu.cn/ChatLogin/

场景 文档
FastAPI 快速接入 完整可运行应用
默认 UI、模板覆盖与 headless 能力地图
CLI 版本和命令树 CLI 树

安装

pip install "ChatLogin[web]"

只需要包内模板渲染、但不使用 FastAPI 时可安装:

pip install "ChatLogin[ui]"

要直接体验包内产品演示(demo extra 已自包含 web 依赖与 Uvicorn):

pip install "ChatLogin[demo]"
chatlogin serve
# 打开 http://127.0.0.1:8765/

反向代理时仍建议只绑定 loopback,并明确写出浏览器实际访问的可信源:

chatlogin serve --host 127.0.0.1 --port 8765 --origin https://login.example.com

serve 只运行隔离产品演示:公开合成身份、5 分钟有界内存会话与一次性 ChatVoice schema fixture。它不读取 ChatEnv 账号或生产数据库,不提供默认生产凭据,也不是可供多业务共享的登录微服务。详见演示站与快速开始。

核心包不要求网站采用包内页面。已有静态 HTML/原生 JS 的网站可以只挂载 JSON 路由,继续保留原登录入口和用户数据库;标准库 HTTP 宿主也可以只使用 LoginUI 渲染登录页。

选择认证后端(0.1.5)

账户来源 可选后端 会话与宿主边界
固定账号 / 多个显式账号 PasswordBackend(accounts) 一个 / 多个哈希条目;搭配 SessionManager 与所选 store
其他宿主用户库 CallbackBackend(authenticate) + 宿主 SessionStore 宿主定义密码验证、schema 和会话映射
异步上游校验 AsyncCallbackBackend(authenticate) 回调在事件循环中 await;非法输入不调用回调,非法结果失败关闭
已有 ChatVoice 账户/会话 schema chatlogin.backends.ChatVoiceAuth 现成兼容后端;固定 chatvoice 命名空间,不建表或迁移

ChatVoiceAuth 随核心包提供,按需导入;不依赖 ChatVoice 包或 web extra,不是任意 SQLite 账户系统的通用 ORM。默认 UI、宿主覆盖和 headless 三种模式与后端选择相互独立。账户创建、业务 owner 权限与宿主 HTTP 契约仍由网站负责。见 接入与安全。

设计边界

  • guest / user / admin 是服务端可信身份,角色不能由请求体指定。
  • 固定账号、多账号和宿主回调均可;已有 PBKDF2 密码材料可验证,不强制迁移。
  • 会话 token 只以 SHA-256 摘要持久化,支持 TTL、轮换、撤销、CSRF、实例隔离和公开 SessionManager.purge_expired() 清理。
  • 公开 PrivateSQLite 供依赖包复用;POSIX 上以可信 0700 数据目录和真实路径 mode=rw 连接保护主库及 SQLite sidecar,拒绝不安全的已有路径且不 chmod 历史文件。同 UID 进程属于本地文件系统信任边界;非 POSIX 不把 mode bits 误称为 ACL。
  • FastAPI adapter 默认同站 Origin/Host 校验、请求体大小限制、限流和安全 next。
  • ChatLogin[web] 声明 starlette>=0.40,<2.0;兼容性测试覆盖 Starlette 0.x、1.3.1 和 1.6.0,CI 门禁继续固定 0.x 与 1.3.x 线路。
  • 默认模板提供色系、布局与浅色/深色/跟随系统选项;宿主可覆盖局部或整页,也可保留原 HTML/JS 走 headless。
  • Admin 不自动绕过资源 owner;业务数据授权仍由宿主决定。
  • 不提供默认生产密码、独立登录微服务、SSO/OAuth、MFA 或账户管理后台。

开发与验证

python -m pip install -e ".[dev,docs]"
chatlogin --version
chatlogin --tree
chatlogin --tree-brief
python -m pytest -q
python -m build
python -m twine check dist/*
mkdocs build --strict

可运行的 FastAPI 合成账号示例:examples/demo_fastapi.py;包内交互演示:chatlogin serve。

Metadata

Release files for ChatLogin 0.1.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ChatLogin 0.1.5
File Size Uploaded
chatlogin-0.1.5.tar.gz 107.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ChatLogin 0.1.5
File Interpreter ABI Platform
chatlogin-0.1.5-py3-none-any.whl Python 3 none any Details

Total release size: 158.9 kB

Release files / chatlogin-0.1.5.tar.gz

Download URL chatlogin-0.1.5.tar.gz
Size 107.1 kB
Tags Source
SHA-256 checksum
How to use checksums
d8725f6dce47e2511c7ddc5a7c092cf0816dd5c8ee19fba109ef21364455819b
BLAKE2b-256 checksum
How to use checksums
a908d9b9170a581943384fa5d7f57dcdafc77e2252b5e1f6a0e9d1687dbfb25c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.

Transparency log

Release files / chatlogin-0.1.5-py3-none-any.whl

Download URL chatlogin-0.1.5-py3-none-any.whl
Size 51.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
77d6b0ab1bde5234a23237ef318049c7c2c2d026a07189af08e1008ac4cd1d46
BLAKE2b-256 checksum
How to use checksums
2af6bc10a340fb4687c999b562918bd2eeea37de49e14ff9ae629fa04d5b90bd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.0

2 release files

0.1.6

2 release files

This release

0.1.5 This release

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page