Skip to main content

aiohttp_signer

This is an aiohttp client middleware, see also Client Middleware Cookbook, to add the digest and http message signatures.

Warning: Not all parts of RFC 9421 HTTP Message Signatures are implemented yet.

History

This package was created as part of rewriting bovine. My goal with it being to separate the parts that are HTTP from the parts that are Fediverse and the parts that are cryptography.

Usage

The following illustrates the simplest usage of this package

import aiohttp
from aiohttp_signer import DigestMiddleware, Rfc9421Signer

async def make_post_request(
    target_url: str,
    data: dict,
    key_id: str,
    signer: Callable[[bytes], bytes]
):
    async with aiohttp.ClientSession() as session:
        await session.post(
            target_url,
            json=data,
            middlewares=[
                DigestMiddleware(),
                Rfc9421Signer(key_id=key_id, signer=signer),
            ],
        )

This will cause the message to contain the content-digest, signature-input, and signature headers. Where the used signature parameters are @method, @target-uri, and content-digest.

A sample implementation of signer would be

from cryptography.hazmat.primitives.serialization import load_pem_private_key
from cryptography.hazmat.primitives.asymmetric import ed25519

private_key_pem = b"""
-----BEGIN PRIVATE KEY-----
MC4CAQAwBQYDK2VwBCIEIJ+DYvh6SEqVTm50DFtMDoQikTmiCqirVv9mWG9qfSnF
-----END PRIVATE KEY-----
"""

def signer(x: bytes):
    private_key = load_pem_private_key(private_key_pem, password=None)
    assert isinstance(private_key, ed25519.Ed25519PrivateKey)
    return private_key.sign(x)

Release files for aiohttp-signer 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aiohttp-signer 0.1.1
File Size Uploaded
aiohttp_signer-0.1.1.tar.gz 118.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aiohttp-signer 0.1.1
File Interpreter ABI Platform
aiohttp_signer-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 132.3 kB

Release files / aiohttp_signer-0.1.1.tar.gz

Download URL aiohttp_signer-0.1.1.tar.gz
Size 118.2 kB
Tags Source
SHA-256 checksum
How to use checksums
d7bddd4a460b5afc7a8fd59fd1cb86e4829ffcec3be9ccdaf638c46cbbdbae8b
BLAKE2b-256 checksum
How to use checksums
32a7795df98e0522728edf4ad7eef69ec4fa3a259f45e86935bdc89ffd2eb901
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.10.11 {"installer":{"name":"uv","version":"0.10.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Alpine Linux","version":"3.23.3","id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / aiohttp_signer-0.1.1-py3-none-any.whl

Download URL aiohttp_signer-0.1.1-py3-none-any.whl
Size 14.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
aa1438002574df7fa3ce6c5152dbc159b11c8f30f97764d96e4564819377ec6b
BLAKE2b-256 checksum
How to use checksums
09b4f3e6ea2650e70217a76e326b60a13781421e5ef675c542a85650ac823cec
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.10.11 {"installer":{"name":"uv","version":"0.10.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Alpine Linux","version":"3.23.3","id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page