Skip to main content

Common utilities and FIPS-compliant cryptography for EmpowerNow packages

Project description

EmpowerNow Common SDK

PyPI CI

The EmpowerNow Common SDK provides authentication helpers, configuration management and utilities shared across EmpowerNow micro-services and platform integrations.

pip install "empowernow-common[fastapi]"

Quick-start

Async OAuth

from empowernow_common import async_oauth

cfg = {
    "client_id": "svc",
    "client_secret": "***",
    "token_url": "https://auth.empowernow.io/oauth/token",
    "authorization_url": "https://auth.empowernow.io/oauth/authorize",
}

async with async_oauth(**cfg) as oauth:
    token = await oauth.get_token()
    print(token.access_token)

FastAPI integration

from fastapi import FastAPI, Depends
from empowernow_common.fastapi import build_auth_dependency

app = FastAPI()

# Create auth dependency for token validation
auth_dependency = build_auth_dependency(
    idps_yaml_path="/config/idps.yaml",
    default_idp_for_opaque="legacy"
)

@app.get("/protected")
async def protected_route(claims: dict = Depends(auth_dependency)):
    return {"user": claims["subject"]}

See the docs/ folder for full guides. For upgrading to the AuthZEN Draft‑04 API, read docs/authzen_migration_draft04.md.

Optional extras

  • redis – distributed caches
  • kafka – log sink and event bus
  • metrics – Prometheus client
  • fastapi – web-framework helpers

Development

git clone https://github.com/empowernow/empowernow-common.git
cd empowernow-common
pip install -e .[dev]
pre-commit install
pytest -q

Secret Loader

empowernow_common provides a zero-dependency helper to resolve secrets delivered as Docker/K8s secrets or environment variables.

from empowernow_common import load_secret

# read from /run/secrets/primary/db-password
password = load_secret("file:primary:db-password")

# read environment variable MY_API_KEY (dev only)
api_key = load_secret("env:MY_API_KEY")

Pointer grammar:

  • file:<instance>:<id> – Reads <mount>/<instance>/<id> where mount defaults to /run/secrets or $FILE_MOUNT_PATH.
  • filex:<instance>:<id> – Same as file: but returns rich structures: JSON objects or line-based key=value pairs are parsed into a dict.
  • env:<VAR> – Returns the environment variable value.

Providers are pluggable:

from empowernow_common.secret_loader import register_provider

def vault_provider(path: str):
    ...
register_provider("vault", vault_provider)

Audit: pass audit_hook to load_secret to stream access events to Kafka/SIEM.

Shared Kafka Producer

The SDK includes an optional, zero-config Kafka helper so services can publish structured events without re-implementing connection logic.

from empowernow_common.kafka.platform_producer import publish_structured
from empowernow_common.kafka.topics import TOPICS

await publish_structured(
    "pdp.decisions",                     # event_type
    {"decision": "allow", "id": "123"},  # payload (JSON-serialisable)
    topic=TOPICS["pdp.decisions"],       # canonical topic
    key="123"                            # partition key (optional)
)

Key points:

  • Optional dependency – install with pip install empowernow-common[kafka].
  • Reads KAFKA_BOOTSTRAP_SERVERS, SERVICE_NAME, KAFKA_ENABLED env vars.
  • No-ops automatically if Kafka is disabled or aiokafka isn’t installed.
  • empowernow_common.kafka.topics provides a central map so topic names evolve without touching every service.
  • Secret-access audit hook already uses the shared producer; you can register additional hooks via:
    from empowernow_common.kafka.platform_producer import publish
    

See kafka/platform_producer.py for full documentation and kafka/topics.py for the canonical topic list.


© EmpowerNow, Inc. MIT License

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

empowernow_common-2.3.22.tar.gz (142.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

empowernow_common-2.3.22-py3-none-any.whl (153.4 kB view details)

Uploaded Python 3

File details

Details for the file empowernow_common-2.3.22.tar.gz.

File metadata

  • Download URL: empowernow_common-2.3.22.tar.gz
  • Upload date:
  • Size: 142.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.10

File hashes

Hashes for empowernow_common-2.3.22.tar.gz
Algorithm Hash digest
SHA256 896b2665674b67db71369c203dcee8e8fcb2f02d51dc7062a2b6936862424707
MD5 2a3835cc0b6129c40388977fa4985f06
BLAKE2b-256 8a99e2d3e150802b95892d839f2a2a4f6adeff36040824fea0e2912c5cd9d5ed

See more details on using hashes here.

File details

Details for the file empowernow_common-2.3.22-py3-none-any.whl.

File metadata

File hashes

Hashes for empowernow_common-2.3.22-py3-none-any.whl
Algorithm Hash digest
SHA256 972b4e38600e3541af6fa9a0047e8bfef52dd1d38c725b738e460c979a49419a
MD5 4961df7909df8cd207e4d3b0f4500041
BLAKE2b-256 6e559ab85a259ff83dcdfbba18b9a4a3ff6ce07f4d93646ec8c17ad90b967e72

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page