Middleware to allow authorization using Keycloak and Django
Project description
Django Keycloak Authorization
Middleware to allow authorization using Keycloak and Django for django-rest-framework (DRF) and Graphene-based projects. This package should only be used in projects starting from scratch, since it overrides the users' management.
Installation
-
Add the module to your environment
-
With PIP:
pip install django-uw-keycloak
-
By compiling from source:
git clone https://github.com/urbanplatform/django-keycloak-auth && \ cd django-keycloak-auth && \ python3 setup.py install
-
-
Add
django_keycloakto the Django project'sINSTALLED_APPSset in thesettingsfile -
Add
django_keycloak.middleware.KeycloakMiddlewareto the DjangoMIDDLEWAREset in thesettingsfile -
In your Django project's
settingsfile, change the DjangoAUTHENTICATION_BACKENDSto:AUTHENTICATION_BACKENDS = ('django_keycloak.backends.KeycloakAuthenticationBackend',)
-
Add the following configuration to Django settings and replace the values with your own configuration attributes:
KEYCLOAK_CONFIG = { # The Keycloak's Public Server URL (e.g. http://localhost:8080) 'SERVER_URL': '<PUBLIC_SERVER_URL>', # The Keycloak's Internal URL # (e.g. http://keycloak:8080 for a docker service named keycloak) # Optional: Default is SERVER_URL 'INTERNAL_URL': '<INTERNAL_SERVER_URL>', # Override for default Keycloak's base path # Default is '/auth/' 'BASE_PATH': '/auth/', # The name of the Keycloak's realm 'REALM': '<REALM_NAME>', # The ID of this client in the above Keycloak realm 'CLIENT_ID': '<CLIENT_ID>' # The secret for this confidential client 'CLIENT_SECRET_KEY': '<CLIENT_SECRET_KEY>', # The name of the admin role for the client 'CLIENT_ADMIN_ROLE': '<CLIENT_ADMIN_ROLE>', # The name of the admin role for the realm 'REALM_ADMIN_ROLE': '<REALM_ADMIN_ROLE>', # Regex formatted URLs to skip authentication 'EXEMPT_URIS': [], # Flag if the token should be introspected or decoded (default is False) 'DECODE_TOKEN': False, # Flag if the audience in the token should be verified (default is True) 'VERIFY_AUDIENCE': True, # Flag if the user info has been included in the token (default is True) 'USER_INFO_IN_TOKEN': True, # Flag to show the traceback of debug logs (default is False) 'TRACE_DEBUG_LOGS': False, # The token prefix that is expected in Authorization header (default is 'Bearer') 'TOKEN_PREFIX': 'Bearer' }
-
Override the Django user model in the
settingsfile:AUTH_USER_MODEL = "django_keycloak.KeycloakUserAutoId"
-
Configure Django-Rest-Framework authentication classes with
django_keycloak.authentication.KeycloakAuthentication:REST_FRAMEWORK = { # ... other rest framework settings. 'DEFAULT_AUTHENTICATION_CLASSES': [ 'django_keycloak.authentication.KeycloakAuthentication' ], }
Customization
Server URLs
To customise Keycloak's URL path, set BASE_PATH (for example /my_path or /) as follows:
SERVER_URL/auth/admin/...toSERVER_URL/my_path/admin/...SERVER_URL/auth/realms/...toSERVER_URL/realms/...
If your OAuth clients (web or mobile app) use a different URL than your Django service, specify the public URL (https://oauth.example.com) in SERVER_URL and the internal URL (http://keycloak.local) in INTERNAL_URL.
DRY Permissions
The permissions must be set like in other projects. You must set the permissions configuration for each model. Example:
@staticmethod
@authenticated_users
def has_read_permission(request):
roles = request.remote_user.get('client_roles')
return True if 'ADMIN' in roles else False
Keycloak users synchronization
The management command sync_keycloak_users must be ran periodically, in
order to remove from the users no longer available at
Keycloak from the local users. This command can be called using the task named
sync_users_with_keycloak, using Celery. Fot that, you just need to:
-
Add the task to the
CELERY_BEAT_SCHEDULEìn the Django project's settings:CELERY_BEAT_SCHEDULE = { 'sync_users_with_keycloak': { 'task': 'django_keycloak.tasks.sync_users_with_keycloak', 'schedule': timedelta(hours=24), 'options': {'queue': 'sync_users'} }, }
-
Add the
sync_usersqueue to thedocker-compose'sceleryservice:command: celery worker -A citibrain_base -B -E -l info -Q backup,celery,sync_users --autoscale=4,1
Attention: This task is only responsible to delete users from local storage. The creation of new users, on Keycloak, is done when they try to login.
Notes
Support for celery 5: from version 0.7.4 on we should use celery 5 for the user sync. This implies running celery with celery -A app worker ... instead of celery worker -A app ...
Contact
django-keycloak-auth [at] googlegroups [dot] com
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file django_uw_keycloak-2.0.2.tar.gz.
File metadata
- Download URL: django_uw_keycloak-2.0.2.tar.gz
- Upload date:
- Size: 18.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.1 CPython/3.9.15
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4f781604c8db28f4fcd936dc772ebe7dfb7ca0318b201674a4e3c26c3f48547b
|
|
| MD5 |
e554e9945ddffc4953b619f843b9aeee
|
|
| BLAKE2b-256 |
18eba7695293a4b92fa61f8d390910048e9addb1ef10d92d328edb77027977bb
|
File details
Details for the file django_uw_keycloak-2.0.2-py3-none-any.whl.
File metadata
- Download URL: django_uw_keycloak-2.0.2-py3-none-any.whl
- Upload date:
- Size: 25.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.1 CPython/3.9.15
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7254aa7937b66144aae1973c98f2ca14dde53ecd3f61b54ca3b1344f3d2e1fa2
|
|
| MD5 |
b589717e68c88b0ed47c77954e665bea
|
|
| BLAKE2b-256 |
36cef9ec4bc3f603b0b8c7f0d2ac049f4935ea38d29f90c8ebde1510233d0350
|