Skip to main content

Shared Keycloak OIDC authentication SDK for ECC projects

Project description

ecc-auth

ecc-auth is a small shared authentication SDK for ECC Python services that integrate with Keycloak and FastAPI.

It provides:

  • Keycloak configuration via KeycloakConfig
  • Standard FastAPI auth routes via create_auth_router
  • Current-user dependencies via get_current_user and get_current_user_optional
  • JWT verification helpers via verify_access_token

Installation

Once published to PyPI:

pip install ecc-auth

Or with uv:

uv add ecc-auth

Quick Start

from fastapi import FastAPI

from ecc_auth import AuthSessionMiddleware, KeycloakConfig, create_auth_router, init_dependencies

app = FastAPI()
app.add_middleware(AuthSessionMiddleware)

config = KeycloakConfig(
    url="https://keycloak.example.com",
    realm="ecc",
    client_id="example-client",
    client_secret="example-secret",
    tls_insecure=False,
)

init_dependencies(config)
app.include_router(create_auth_router(config), prefix="/api/auth")

Development

This repository is a single Python package repository. The package root, tests, and release metadata all live at the repository root.

Build the package locally:

uv build

Run tests:

uv run pytest

Callback Error Contract

When /api/auth/callback cannot complete, ecc-auth redirects back to the app origin with a stable ?error=<code> query parameter.

Current callback error codes:

  • missing_state
  • invalid_state
  • missing_code
  • csrf_mismatch
  • missing_pkce
  • token_exchange_failed
  • callback_upstream_failed
  • token_not_yet_valid
  • token_validation_failed
  • token_verification_unavailable
  • user_sync_failed
  • callback_failed

Consumer apps should map these codes to user-facing copy instead of exposing raw exception text.

Publishing

This repository includes a GitHub Actions workflow at .github/workflows/publish-python.yml.

Recommended release flow:

  1. Bump version in pyproject.toml.
  2. Commit and push the change.
  3. Create a GitHub release.
  4. Let the workflow build and publish the package to PyPI.

Before the first release, configure a Trusted Publisher for this repository in PyPI and point it at:

  • Repository owner: early-chinese-civilization
  • Repository name: ecc-auth
  • Workflow file: .github/workflows/publish-python.yml
  • Environment name: pypi

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ecc_auth-0.1.2.tar.gz (18.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ecc_auth-0.1.2-py3-none-any.whl (19.2 kB view details)

Uploaded Python 3

File details

Details for the file ecc_auth-0.1.2.tar.gz.

File metadata

  • Download URL: ecc_auth-0.1.2.tar.gz
  • Upload date:
  • Size: 18.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ecc_auth-0.1.2.tar.gz
Algorithm Hash digest
SHA256 004758480c7b1528c201836890280ba6cad00f6335cff57aee89d74cf62eee7f
MD5 961026df8b5f45eb6d733250e51c6f60
BLAKE2b-256 54fa206a73b09566977f7e9f70b36552f6f90b6e5ed892fe922385991dbbd9fe

See more details on using hashes here.

Provenance

The following attestation bundles were made for ecc_auth-0.1.2.tar.gz:

Publisher: publish-python.yml on early-chinese-civilization/ecc-auth

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ecc_auth-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: ecc_auth-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 19.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ecc_auth-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 9f2fb17b9be072e973a4258b2d5692adbfe3f46d14e87651565ac9fe5cc819ad
MD5 85d2996a2c3e191ccd8fb572e05e8ff7
BLAKE2b-256 424c4d0beafbd11fdcc54738a204f70f044fe286e0c0ced6c7fd6f8ce8f6c624

See more details on using hashes here.

Provenance

The following attestation bundles were made for ecc_auth-0.1.2-py3-none-any.whl:

Publisher: publish-python.yml on early-chinese-civilization/ecc-auth

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page