Skip to main content

django-allauth plus allauth_async, a native-asyncio twin of its auth flows for ASGI apps. Ships the allauth package; do not install alongside django-allauth.

Project description

django-allauth-async

This is a fork of django-allauth (MIT licensed, by Raymond Penners and contributors) that adds allauth_async: a native-asyncio twin of allauth’s authentication flows for ASGI applications.

Why fork?

django-allauth is sync throughout — sync ORM in its flows, sync signal dispatch, blocking requests calls for OAuth/OIDC, and sync headless views. An async-first ASGI application (such as GlitchTip) can only call it through sync_to_async, paying a thread hop per auth request and running into known ASGI issues (upstream issues #3566, #3634). Upstream has no async roadmap; this fork exists to build one — with the intent of proposing the design upstream once it has stabilized in production.

How it relates to upstream

The allauth package in this repository is unmodified upstream code at the version this fork is based on (see the release tag). All fork code is additive, inside allauth_async/: each of its modules mirrors one upstream module and re-implements the blocking parts with real asyncio — async ORM, auth.alogin/aauthenticate, Signal.asend, async sessions, and aiohttp for outbound HTTP. A drift manifest (allauth_async/_upstream_manifest.json) records the reviewed hash of every mirrored upstream file; CI fails after an upstream merge until the affected async twins are re-reviewed (scripts/check_drift.py / scripts/ack_drift.py). Non-additive changes to upstream files are avoided; if one is ever unavoidable it carries [patch-upstream] in the commit subject so git log --grep='\[patch-upstream\]' lists the entire conflict surface.

Versioning

<upstream version>.<fork iteration> — e.g. 65.16.1.2 is the second fork release based on upstream 65.16.1. Upstream updates are merged (never rebased) from the upstream tag.

Installation
pip install django-allauth-async

Do not install alongside django-allauth — this distribution ships the allauth package itself, and the two would overwrite each other. allauth_async refuses to import if both are present.

Upstream’s documentation at https://docs.allauth.org applies to everything under allauth. The async layer is enabled by swapping specific entry points to their allauth_async counterparts (middleware, authentication backend, and the headless/provider URL includes); see the allauth_async module docstrings until dedicated docs land here.

Everything below this line is the original django-allauth README.


Welcome to django-allauth!

django-allauth logo

ci pypi Coverage Status btc liberapay pystyle jsstyle editor i18n PyPI - Downloads View Django Demo View React SPA Demo

Integrated set of Django applications addressing authentication, registration, account management as well as 3rd party (social) account authentication.

Home page

https://allauth.org/

Source code

https://codeberg.org/allauth/django-allauth

Issue Tracker

https://codeberg.org/allauth/django-allauth/issues

Documentation

https://docs.allauth.org/en/latest/

Stack Overflow

https://stackoverflow.com/questions/tagged/django-allauth

Demo

https://django.demo.allauth.org and https://react.demo.allauth.org

Translations

https://hosted.weblate.org/projects/allauth/django-allauth/

Rationale

Most existing Django apps that address the problem of social authentication unfortunately focus only on one dimension - the social. Most developers end up integrating another app in order to support authentication flows that are locally generated.

This approach creates a development gap between local and social authentication flows. It has remained an issue in spite of numerous common scenarios that both require. For example, an email address passed along by an OpenID provider may not be verified. Therefore, prior to hooking up an OpenID account to a local account the email address must be verified. This essentially is one of many use cases that mandate email verification to be present in both worlds.

Integrating both is a humongous and tedious process. It is not as simple as adding one social authentication app, and one local account registration app to your INSTALLED_APPS list.

This inadequacy is the reason for this project’s existence – to offer a fully integrated authentication app that allows for both local and social authentication, with flows that just work, beautifully!

Features

🔑 Comprehensive account functionality

Supports multiple authentication schemes (e.g. login by user name, or by email), as well as multiple strategies for account verification (ranging from none to mandatory email verification).

👥 Social Login

Login using external identity providers, supporting any Open ID Connect compatible provider, many OAuth 1.0/2.0 providers, as well as custom protocols such as, for example, Telegram authentication.

💼 Enterprise ready

Supports SAML 2.0, which is often used in a B2B context.

🕵️ Battle-tested

The package has been out in the open since 2010. It is in use by many commercial companies whose business depends on it and has hence been subjected to various penetration testing attempts.

⏳Rate limiting

When you expose an authentication-enabled web service to the internet, it is important to be prepared for potential brute force attempts. Therefore, rate limiting is enabled out of the box.

🔒 Private

Many sites leak information. For example, on many sites you can check whether someone you know has an account by input their email address into the password forgotten form, or trying to signup with it. We offer account enumeration prevention, making it impossible to tell whether or not somebody already has an account.

🧩 Customizable

As a developer, you have the flexibility to customize the core functionality according to your specific requirements. By employing the adapter pattern, you can effortlessly introduce interventions at the desired points to deviate from the standard behavior. This level of customization empowers you to tailor the software to meet your unique needs and preferences.

⚙️ Configuration

The required consumer keys and secrets for interacting with Facebook, X (Twitter) and the likes can be configured using regular settings, or, can be configured in the database via the Django admin. Here, optional support for the Django sites framework is available, which is helpful for larger multi-domain projects, but also allows for easy switching between a development (localhost) and production setup without messing with your settings and database.

Commercial Support

Commercial support is available. If you find certain functionality missing, or require assistance on your project(s), please contact us: info@intenct.nl.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

django_allauth_async-65.16.1.1.tar.gz (2.4 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

django_allauth_async-65.16.1.1-py3-none-any.whl (2.3 MB view details)

Uploaded Python 3

File details

Details for the file django_allauth_async-65.16.1.1.tar.gz.

File metadata

File hashes

Hashes for django_allauth_async-65.16.1.1.tar.gz
Algorithm Hash digest
SHA256 3a91abc0fc58ae5a7a02afc6286668a4648fddd96e08bd6de6a8b0b847b056f7
MD5 502b025271fac1242bfd8be81982f6bb
BLAKE2b-256 1e4d8b4af124fbf6c5f7697d36bb9349e4f59e327f39fd0c21a28e3cb84bde48

See more details on using hashes here.

File details

Details for the file django_allauth_async-65.16.1.1-py3-none-any.whl.

File metadata

File hashes

Hashes for django_allauth_async-65.16.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 a6c06c3e4a8f2e545f7ab47e0b55eb04bfb8908ebcecb5e3137c706c9d4a3dbc
MD5 f04f8d68a3e08fe54584e92802466c69
BLAKE2b-256 08f3815373dca000d36b7fb9c27f36008b3a15c09deface95b1e48169df64870

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page