Django Ninja OAuth2 package enables support of OAuth2 / OpenID Connect Authorization Code Flow for your swagger documentation.
Project description
Django Ninja OAuth2
Django Ninja OAuth2 package enables support of OAuth2 / OpenID Connect "Authorization Code Flow" for your swagger documentation.
Requirements
- Python >= 3.8
- django >= 3.1
- pydantic >= 2.0
- Django-Ninja >= 1.1.0
Installation
pip install django-ninja-oauth2
After installation, change settings.py file. Locally it only worked with None. On a real domain it should work with "same-origin-allow-popups".
# in <myapp>/settings.py
SECURE_CROSS_ORIGIN_OPENER_POLICY = None # or "same-origin-allow-popups"
Usage
Initialize NinjaAPIOAuth2 wherever you would initialize the original Django Ninja api.
Set your authorization, token and public key url
By default, if no HTTP Authorization header is provided, required for OAuth2 authentication, it will automatically cancel the request and send the client an error.
If auto_error is set to False, when the HTTP Authorization header is not available, instead of erroring out, the dependency result will be None.
from ninja_oauth2 import NinjaAPIOAuth2, SwaggerOAuth2
from ninja_oauth2.security.oauth2 import OAuth2AuthorizationCodeBearer
oauth2 = OAuth2AuthorizationCodeBearer(
authorization_url="https://test.com/auth/realms/<realm>/protocol/openid-connect/auth",
token_url="https://test.com/auth/realms/<realm>/protocol/openid-connect/token",
public_key_url="https://test.com/auth/realms/<realm>",
auto_error=True # Default True
)
api = NinjaAPIOAuth2(
docs=SwaggerOAuth2(
auth={"clientId": "<client_id>"}
),
auth=oauth2) # Use auth for all endpoints, optional
@api.get("/add", tags=["Main"], auth=oauth2) # Use auth for specific endpoint
def add(request, a: int, b: int):
return {"result": a + b}
If you want to check the encoded jwt token against some condition, you can extend the OAuth2AuthorizationCodeBearer in the following way:
from typing import Optional, Any
from django.http import HttpRequest
from ninja_oauth2 import NinjaAPIOAuth2, SwaggerOAuth2
from ninja_oauth2.security.oauth2 import OAuth2AuthorizationCodeBearer
class MyOAuth2(OAuth2AuthorizationCodeBearer):
# token_info returns the encoded jwt token
def authenticate(self, request: HttpRequest, token_info: dict) -> Optional[Any]:
if token_info["resource_access"]["<clien_id>"]["roles"] == "admin":
return token_info
# Otherwise it will return a 401 unauthorized
oauth2 = MyOAuth2(
authorization_url="https://test.com/auth/realms/<realm>/protocol/openid-connect/auth",
token_url="https://test.com/auth/realms/<realm>/protocol/openid-connect/token",
public_key_url="https://test.com/auth/realms/<realm>"
)
api = NinjaAPIOAuth2(
docs=SwaggerOAuth2(
auth={"clientId": "<client_id>"}
),
auth=oauth2)
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file django_ninja_oauth2-0.1.4.tar.gz
.
File metadata
- Download URL: django_ninja_oauth2-0.1.4.tar.gz
- Upload date:
- Size: 6.5 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: poetry/1.8.2 CPython/3.12.3 Linux/6.8.0-36-generic
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 79be58822e6975863b0099528c1f41f59ffc4db57338538123cd27a0c6748195 |
|
MD5 | 33ac573753271da1710531e068d5b74b |
|
BLAKE2b-256 | d4d5d76ba84b8bc691133750042f8a4682844240f6c7ea4b96ba7f0cfe98c4de |
File details
Details for the file django_ninja_oauth2-0.1.4-py3-none-any.whl
.
File metadata
- Download URL: django_ninja_oauth2-0.1.4-py3-none-any.whl
- Upload date:
- Size: 8.3 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: poetry/1.8.2 CPython/3.12.3 Linux/6.8.0-36-generic
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | f3bb921b61962d4f0c0758556816606de53e6223995ad50beb08942c4e9fe672 |
|
MD5 | cb062e8ab0aeba005a37da152085df06 |
|
BLAKE2b-256 | 6f276efc218da25f8dbb8ec5617bc0bd9830b43c836af1fbf47df23551ed9e5f |