Skip to main content

Common utilities and FIPS-compliant cryptography for EmpowerNow packages

Project description

EmpowerNow Common SDK

PyPI CI

The EmpowerNow Common SDK provides authentication helpers, configuration management and utilities shared across EmpowerNow micro-services and platform integrations.

pip install "empowernow-common[fastapi]"

Quick-start

Async OAuth

from empowernow_common import async_oauth

cfg = {
    "client_id": "svc",
    "client_secret": "***",
    "token_url": "https://auth.empowernow.io/oauth/token",
    "authorization_url": "https://auth.empowernow.io/oauth/authorize",
}

async with async_oauth(**cfg) as oauth:
    token = await oauth.get_token()
    print(token.access_token)

FastAPI integration

from fastapi import FastAPI, Depends
from empowernow_common.fastapi import build_auth_dependency

app = FastAPI()

# Create auth dependency for token validation
auth_dependency = build_auth_dependency(
    idps_yaml_path="/config/idps.yaml",
    default_idp_for_opaque="legacy"
)

@app.get("/protected")
async def protected_route(claims: dict = Depends(auth_dependency)):
    return {"user": claims["subject"]}

See the docs/ folder for full guides. For upgrading to the AuthZEN Draft‑04 API, read docs/authzen_migration_draft04.md.

Optional extras

  • redis – distributed caches
  • kafka – log sink and event bus
  • metrics – Prometheus client
  • fastapi – web-framework helpers

Development

git clone https://github.com/empowernow/empowernow-common.git
cd empowernow-common
pip install -e .[dev]
pre-commit install
pytest -q

Secret Loader

empowernow_common provides a zero-dependency helper to resolve secrets delivered as Docker/K8s secrets or environment variables.

from empowernow_common import load_secret

# read from /run/secrets/primary/db-password
password = load_secret("file:primary:db-password")

# read environment variable MY_API_KEY (dev only)
api_key = load_secret("env:MY_API_KEY")

Pointer grammar:

  • file:<instance>:<id> – Reads <mount>/<instance>/<id> where mount defaults to /run/secrets or $FILE_MOUNT_PATH.
  • filex:<instance>:<id> – Same as file: but returns rich structures: JSON objects or line-based key=value pairs are parsed into a dict.
  • env:<VAR> – Returns the environment variable value.

Providers are pluggable:

from empowernow_common.secret_loader import register_provider

def vault_provider(path: str):
    ...
register_provider("vault", vault_provider)

Audit: pass audit_hook to load_secret to stream access events to Kafka/SIEM.

Shared Kafka Producer

The SDK includes an optional, zero-config Kafka helper so services can publish structured events without re-implementing connection logic.

from empowernow_common.kafka.platform_producer import publish_structured
from empowernow_common.kafka.topics import TOPICS

await publish_structured(
    "pdp.decisions",                     # event_type
    {"decision": "allow", "id": "123"},  # payload (JSON-serialisable)
    topic=TOPICS["pdp.decisions"],       # canonical topic
    key="123"                            # partition key (optional)
)

Key points:

  • Optional dependency – install with pip install empowernow-common[kafka].
  • Reads KAFKA_BOOTSTRAP_SERVERS, SERVICE_NAME, KAFKA_ENABLED env vars.
  • No-ops automatically if Kafka is disabled or aiokafka isn’t installed.
  • empowernow_common.kafka.topics provides a central map so topic names evolve without touching every service.
  • Secret-access audit hook already uses the shared producer; you can register additional hooks via:
    from empowernow_common.kafka.platform_producer import publish
    

See kafka/platform_producer.py for full documentation and kafka/topics.py for the canonical topic list.


© EmpowerNow, Inc. MIT License

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

empowernow_common-3.7.1.tar.gz (384.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

empowernow_common-3.7.1-py3-none-any.whl (437.8 kB view details)

Uploaded Python 3

File details

Details for the file empowernow_common-3.7.1.tar.gz.

File metadata

  • Download URL: empowernow_common-3.7.1.tar.gz
  • Upload date:
  • Size: 384.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.12

File hashes

Hashes for empowernow_common-3.7.1.tar.gz
Algorithm Hash digest
SHA256 82fb37e5552ae967c381f303337311077a2b09895c750ff7eee4de2b15431dae
MD5 86f86e591c662fd931743a64c7ef4072
BLAKE2b-256 e1944307c8f5148b0ca39d4934e2872a08569e9f67408906cb4d61f92f051370

See more details on using hashes here.

File details

Details for the file empowernow_common-3.7.1-py3-none-any.whl.

File metadata

File hashes

Hashes for empowernow_common-3.7.1-py3-none-any.whl
Algorithm Hash digest
SHA256 54c051f88fdb158f28a3b96279b7b28031a21601400f3031ad2351786b1f17df
MD5 fca0da82cf0d37f50b74325d63018f72
BLAKE2b-256 32cefc9566b6864d0768936891fd36a9e534d59924fac10ca8a5d69bc059f1dd

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page