Skip to main content

Python library for the BrowserID Protocol

Project description

This is a python client library for the BrowserID protocol that underlies Mozilla Persona:

https://login.persona.org/

For the vast majority of deployments, you will simply want to call the module- level “verify” functon to verify a given assertion:

>>> data = browserid.verify(BROWSERIDASSERTION, "http://mysite.com")
>>> print data["email"]
"test@example.com"

The precise implementation of this function will change depending on the current recommendedations of the BrowserID team. Currently it POSTs the assertion to the remote verifier services on persona.org.

Note that you must specify your site’s root URL as the second argument to that function. This is the “expected audience” and is a key security feature of BrowserID.

If you are not able to determine the precise hostname by which your site is being accessed (e.g. due to virtual hosting) then you may specify one or more wildcard patterns like so:

>>> data = browserid.verify(BROWSERIDASSERTION, ["http://*.mysite.com"])
>>> print data["email"]
"test@example.com"

For finer control over the verification process, you can create an instance of a “Verifier” class and avoid having to specify the audience patterns over and over again:

>>> verifier = browserid.RemoteVerifier(["*.mysite.com"])
>>> data = verifier.verify(BROWSERIDASSERTION)
>>> print data["email"]
"test@example.com"

For improved performance, or if you just want to live on the bleeding edge, you can explicitly perform verification locally by using the LocalVerifier class like so:

>>> verifier = browserid.LocalVerifier(["*.mysite.com"])
>>> data = verifier.verify(BROWSERIDASSERTION)
>>> print data["email"]
"test@example.com"

Note that the details of the BrowserID Protocol are still in flux, so local verification might break due to incompatible changes. As things stabilise this will become the default implementation.

0.7.0 - 2012-07-26

  • Added a pure-python implementation of the JWT crypto routines, for use when M2Crypto is not available.

  • Added “from_pem_data” and “to_pem_data” methods to Key objects. Currently these are only available when M2Crypto is installed.

  • Added support for delegation of authority; thanks @kylef.

  • Use https://verifier.login.persona.org/verify for remote verification

0.6.2 - 2012-07-17

  • Add persona.org and related sites to the list of default trusted secondaries.

0.6.1 - 2012-06-07

  • Disable certificate chaining for now. This feature is not used by any servers in the wild, and the spec for it is going to change soon.

0.6.0 - 2012-31-05

  • Remove ability to use a custom JWT parser class, it’s not used and adds needless complexity.

  • Add a way to skip the ssl verification when getting certificates with the CertificateManager.

0.5.0 - 2012-04-18

  • add support of requests rather than custom code for ssl checking when retrieving certificates.

  • removed patch utility for secure_urlopen (we are now using requests)

  • add more verbose errors when dealing with RSA/DSA Keys.

0.4.0 - 2012-03-13

  • Renamed from PyVEP to PyBrowserID, in keeping with Mozilla branding.

  • Audience checking now accepts glob-style patterns as well as fixed audience strings.

  • Verifier objects now accept a list of audience patterns as their first argument. This is designed to encourage doing the right thing rather than, say, passing in the hostname from the request.

  • Allowed LocalVerifier to use of a custom JWT parser.

  • Removed browserid.verify_[remote|local|dummy] since they just cause confusion. You should either accept the defaults provided by the browserid.verify function, or use a full-blown Verifier object.

  • Split certificate loading and caching into a separate class, in browserid.certificates:CertificatesManager.

  • Removed the DummyVerifier class in favour of supporting functions in browserid.tests.support.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

PyBrowserID-0.7.0.tar.gz (34.1 kB view details)

Uploaded Source

File details

Details for the file PyBrowserID-0.7.0.tar.gz.

File metadata

  • Download URL: PyBrowserID-0.7.0.tar.gz
  • Upload date:
  • Size: 34.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No

File hashes

Hashes for PyBrowserID-0.7.0.tar.gz
Algorithm Hash digest
SHA256 7eb939fe459708f2e523cbf92426a982f49be020ea8a1c8b67808d84a46a70ce
MD5 a19eadc80c6038924c286d38b2e4f03e
BLAKE2b-256 1da461a9ab700bafcc72fa103c9ab1d4b6f1aa23fa47bcf04200a7b9e3002002

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page