Skip to main content

This simple package ships middleware that lets you to set basic auth and IP whitelisting via settings.

Use case

This package has been created in mind for staging and demo sites that need to be completely hidden from the Internet behind a password or IP range.

Requirements

  • Django 1.11 or 2.0

  • Python 3.4, 3.5, 3.6

Installation

The package is on PyPI.

pip install django-basic-auth-ip-whitelist

Configuration

In your Django settings you can configure the following settings.

BASIC_AUTH_LOGIN and BASIC_AUTH_PASSWORD

Credentials that you want to use with your basic authentication.

BASIC_AUTH_WHITELISTED_IP_NETWORKS

Set a list of network ranges (strings) compatible with Python’s ipaddress.ip_network that you want to be able to access the website without authentication from. It must be either a string with networks separated by comma or Python iterable.

BASIC_AUTH_REALM

String specifying the realm of the default response.

Example settings

MIDDLEWARE += [
    'baipw.middleware.BasicAuthIPWhitelistMiddleware'
]
BASIC_AUTH_LOGIN = 'somelogin'
BASIC_AUTH_PASSWORD = 'greatpassword'
BASIC_AUTH_WHITELISTED_IP_NETWORKS = [
    '192.168.0.0/28',
    '2001:db00::0/24',
]

Advanced customisation

Getting IP

If you want to have a custom behaviour when getting IP, you can create a custom function that takes request as a parameter and specify path to it in the BASIC_AUTH_GET_CLIENT_IP_FUNCTION settings, e.g.

BASIC_AUTH_GET_CLIENT_IP_FUNCTION = 'utils.ip.get_client_ip'

BASIC_AUTH_WHITELISTED_HTTP_HOSTS

Set a list of hosts that your website will be open to without basic authentication. This is useful if your website is hosted under multiple domains and you want only one of them to be publicly visible, e.g. by search engines.

This is by no means a security feature. Please do not use to secure your site.

BASIC_AUTH_WHITELISTED_HTTP_HOSTS = [
    'your-public-domain.com',
]

BASIC_AUTH_RESPONSE_TEMPLATE

If you want to display a different template on the 401 page, please use this setting to point at the template.

BASIC_AUTH_RESPONSE_TEMPLATE = '401.html'

BASIC_AUTH_RESPONSE_CLASS

If you want to specify custom response class, you can do so with this setting. Provide the path as a string.

BASIC_AUTH_RESPONSE_CLASS = 'yourmodule.response.CustomUnathorisedResponse'

Skip middleware

You can skip the middleware by setting _skip_basic_auth_ip_whitelist_middleware_check attribute on the request to True.

setattr(request, '_skip_basic_auth_ip_whitelist_middleware_check', True)

This may be handy if you have other middleware that you want to have co-existing different middleware that restrict access to the website.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

django-basic-auth-ip-whitelist-0.2.tar.gz (8.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

django_basic_auth_ip_whitelist-0.2-py3-none-any.whl (12.5 kB view details)

Uploaded Python 3

File details

Details for the file django-basic-auth-ip-whitelist-0.2.tar.gz.

File metadata

File hashes

Hashes for django-basic-auth-ip-whitelist-0.2.tar.gz
Algorithm Hash digest
SHA256 662e23c81657237e1712bd03b5511ed911a3f4731e6a8d2535bb9f829567c750
MD5 2938a45bcfbd384af5e4c77a9fb50bb2
BLAKE2b-256 08dc1dc2fd7205d0d1aa9a42ce8e901d67d8db46c8565177873705d7c17520b5

See more details on using hashes here.

File details

Details for the file django_basic_auth_ip_whitelist-0.2-py3-none-any.whl.

File metadata

File hashes

Hashes for django_basic_auth_ip_whitelist-0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 015d6b6ef7f3a7de9f7ac89ecff81e08a531028813d5818499b6382c713f671c
MD5 ff08b67172a8f9877444bd04421459e3
BLAKE2b-256 059d574bc1e8fa55188374aa026b5f824a2c38472f277410e0beb51347a89eb5

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page