Usecase agnostic implementation of AWS4 Sig v4
This implementation aims to be usecase agnostic. As such it accepts the
component pieces of a request rather than a full opinionated request object
like httpx.Request.
https://docs.aws.amazon.com/AmazonS3/latest/API/sig-v4-authenticating-requests.html
Usage
Validation
from aws4 import generate_challenge, validate_challenge
payload = "<extract content from request>"
challenge = generate_challenge(
method=request.method,
url=request.url,
headers=request.headers,
content=payload.decode("utf-8"),
)
secret_access_key = <load secret key using the challenge.access_key_id>
validate_challenge(challenge, secret_key.secret_access_key)
Signing
An example of an httpx AWS4 request signing. In this example the Authorization header is injected into request.headers
from datetime import datetime, timezone
import aws4
service = "s3"
region = "us-east-1"
access_key_id = "my-access-key-id"
secret_access_key = "my-secret-access-key"
def http_aws4_auth(request: httpx.Request):
dt = datetime.now(tz=timezone.utc)
request.headers["x-amz-date"] = aws4.to_amz_date(dt)
request.headers["host"] = request.url.netloc.decode("utf-8")
body = request.content.decode("utf-8")
if body:
request.headers["Content-Length"] = str(len(body))
aws4.sign_request(
service,
request.method,
request.url,
region,
request.headers,
body,
access_key_id,
secret_access_key,
dt,
)
with httpx.Client() as client:
r = client.request(
url="http://localhost",
auth=auth,
)
Builtin httpx client
Currently there is only a builtin client for httpx, if you think there is a client implementation that would be useful to include, please raise an issue on github.
from datetime import datetime, timezone
import aws4
from aws4.key_pair import KeyPair
from aws4.client import HttpxAWS4Auth
auth = HttpxAWS4Auth(
KeyPair(
access_key_id="my-access-key-id",
secret_access_key="my-secret-access-key",
)
"s3",
"us-east-1",
)
with httpx.Client() as client:
r = client.request(
url="http://localhost",
auth=auth,
)
Extra credit
Thanks to @ozzzzz and @ivanmisic for work on the initial httpx/fastapi implementations this was extracted from.
Metadata
Release files for auth-aws4 0.1.13
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| auth_aws4-0.1.13.tar.gz | 77.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| auth_aws4-0.1.13-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 86.5 kB
Release files / auth_aws4-0.1.13.tar.gz
| Download URL | auth_aws4-0.1.13.tar.gz |
|---|---|
| Size | 77.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ee64769a6c89e3cba95dc4cdad81d0c332e91b6966005cfe65d227e9616f5bff
|
|
BLAKE2b-256 checksum How to use checksums |
415ea40fe6a1db269fcd477aab0388feb559491d06b35967d51846799ef63ed9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.25
|
Release files / auth_aws4-0.1.13-py3-none-any.whl
| Download URL | auth_aws4-0.1.13-py3-none-any.whl |
|---|---|
| Size | 9.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
98202e2a9463c04194ed401b4d11b7837a2a869477b28f6a9e5ffd4614855779
|
|
BLAKE2b-256 checksum How to use checksums |
2f1d7ded70f0ff63f8aa8183d27be2b49ae776cec57c9d1d20b4e6f325a26e5b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.25
|