Skip to main content

Anzar is a lightweight authentication and authorization framework that runs as a separate microservice

Project description

Anzar SDK Documentation

Server Middleware

The server SDK provides two middleware functions for protecting your routes using JWT tokens issued by your Anzar Auth container.

📝 Note: JWT vs. Session

Depending on what Authentication strategy you choose, use these middleware functions accordingly

Jwt

require_auth

Verifies the JWT token and attaches the authenticated user's ID to the request object. Use this to protect any route that requires a logged-in user.

import os

from flask import g
from flask import Flask, jsonify
from anzar.server.flask import require_auth, JwtAuth

app = Flask(__name__)

jwt_auth = JwtAuth(
    audience = os.getenv("AUDIENCE"),
    issuerBaseURL = os.getenv("ISSUER"),
)

@app.route("/protected")
@require_jwt(jwt_auth)
def me():
    return jsonify(g.user_id)

require_role

Verifies the JWT token and checks that the token includes a specific role. Use this to restrict routes to users with a particular permission level.

import os

from flask import g
from flask import Flask, jsonify
from anzar.server.flask import require_role, JwtAuth

app = Flask(__name__)

jwt_auth = JwtAuth(
    audience = os.getenv("AUDIENCE"),
    issuerBaseURL = os.getenv("ISSUER"),
)

@app.route("/admin")
@require_role(jwt_auth, roles="admin", permissions=["users:delete"])
def admin():
    return jsonify(f"admin panel, {g.user_id}")

Session

require_auth

Verifies the session and attaches the authenticated user's ID to the request object. Use this to protect routes when using session-based authentication instead of JWT tokens.

import os

from flask import g
from flask import Flask, jsonify
from anzar.server.flask import require_auth, SessionAuth

app = Flask(__name__)

session_auth = SessionAuth()

@app.route("/protected")
@require_session(session_auth)
def me():
    return jsonify(g.user_id)

require_role

Verifies the session and checks that the session includes a specific role. Use this to restrict routes to users with a particular permission level when using session-based authentication instead of JWT tokens.

import os

from flask import g
from flask import Flask, jsonify
from anzar.server import require_role, SessionAuth

app = Flask(__name__)

session_auth = SessionAuth()

@app.route("/admin")
@require_session_role(session_auth, roles="admin", permissions=["users:delete"])
def admin():
    return jsonify(f"admin panel, {g.user_id}")

Client

Install The Python SDK

In a python project run the following command to install the anzar package.

uv

$ uv add anzar

pip

# in a virtual env run
$ pip install anzar

Create Anzar Auth Instance

in your main entry file (main.py for example), import anzar.yml and parse it as a YAML file

def load_config(path: str) -> AnzarConfig:
    import yaml

    try:
        with open(path, "r") as f:
            data = yaml.safe_load(f)
        return AnzarConfig(**data)
    except Exception as e:
        import sys

        sys.exit("check your configuration file: anzar.yml")

import Anzar Auth and create your auth instance

# Initialize once at application startup
# The SDK will communicate with your Anzar container at the configured api_url
from anzar import Anzar

config = load_config("anzar.yml")
anzar = Anzar(config, options=None)

Note "Configuring Token Persistence" To keep users logged in across restarts, choose a token storage adapter.

```python
from anzar.adapters import RedisStorage
from anzar.types import SdkOptions 

anzar = Anzar(config, SdkOptions(storage=RedisStorage()))
```

Basic Usage

Anzar provides authentication support for email and password.

📝 Note: Other methods of authentication will be implemented later

Sign Up

To sign up a user you need to call the method register with the user's information.

from anzar.types import AuthResponse, ErrorCode

(data, error) = await anzar.Auth.register({
  "username": "username",
  "email": "user@example.com",
  "password": "password"
})

if data:
    print(data)

if error:
    if error.code == ErrorCode.InvalidCredentials:
        show_error("Invalid email or password.")
    elif error.code == ErrorCode.AccountNotVerified:
        show_error("Please verify your email before logging in.")

📝 Note: By default, the users are automatically signed in after they successfully sign up. Disabling this behavior will be implemented later

Sign In

To sign in a user you need to call the method login.

from anzar.types import ApiException, AuthResponse, ErrorCode

(response, error) = await anzar.Auth.login(
    LoginRequest(email="user@example.com", password="password")
)
if error:
    print("code:", error.code)
    print("message:", error.message)
print(response)

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

anzar-0.5.5.tar.gz (10.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

anzar-0.5.5-py3-none-any.whl (17.3 kB view details)

Uploaded Python 3

File details

Details for the file anzar-0.5.5.tar.gz.

File metadata

  • Download URL: anzar-0.5.5.tar.gz
  • Upload date:
  • Size: 10.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.11.16 {"installer":{"name":"uv","version":"0.11.16","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for anzar-0.5.5.tar.gz
Algorithm Hash digest
SHA256 8a4bcc7bf4202f5c7d91531b324bbe6979ebf7b45bf5150706f32a5edebdb708
MD5 3edb9e1d788928a571bf25c82a22e58a
BLAKE2b-256 6e1defd873742610ef51067e282a6892780faa2214d74367f79337fbbfc2a320

See more details on using hashes here.

File details

Details for the file anzar-0.5.5-py3-none-any.whl.

File metadata

  • Download URL: anzar-0.5.5-py3-none-any.whl
  • Upload date:
  • Size: 17.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.11.16 {"installer":{"name":"uv","version":"0.11.16","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for anzar-0.5.5-py3-none-any.whl
Algorithm Hash digest
SHA256 ef33f518bc7a3486dabab9812c78ee0489e20e71315c670b401396929770f607
MD5 71d2522b131f3483b1a80cf9dfc69b64
BLAKE2b-256 d4031ca70c18085a95a2d428464ba89709345e8ea0ff892e00e54effe7f47edf

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page