Skip to main content

enlace_auth

Authentication, sessions, an admin dashboard, and per-user stores for the enlace multi-app platform.

enlace itself is auth-agnostic — it composes apps and routes traffic. This package plugs in at compose time and adds:

  • /auth/login, /auth/logout, /auth/register, /auth/whoami, /auth/csrf, /auth/me/password, /auth/shared-login
  • /_admin/api/* — list/create/delete users, admin password reset, view app policy, and grant/revoke per-app access at runtime (optional expiry). Gated by an admin allowlist.
  • per-user data injection via request.state.store
  • PlatformAuthMiddleware + CSRFMiddleware
  • optional OAuth2 / OIDC via Authlib

Quick start

from enlace import build_backend, PlatformConfig
from enlace_auth import plugin as auth_plugin

config = PlatformConfig.from_toml("platform.toml")
app = build_backend(config, plugins=[auth_plugin])

Or, if you serve via uvicorn --factory enlace.compose:create_app, set:

export ENLACE_PLUGINS=enlace_auth:plugin

Configuration

In platform.toml:

[auth]
enabled = true
session_cookie_name = "enlace_session"
session_max_age_seconds = 86400
signing_key_env = "ENLACE_SIGNING_KEY"
secure_cookies = true

[auth.stores]
backend = "file"
path = "~/.enlace/platform_store"

[stores.user_data]
backend = "file"
path = "~/.enlace/user_data"

Plus environment variables:

  • ENLACE_SIGNING_KEY — signing key (32+ chars). Generate with python -c "import secrets; print(secrets.token_urlsafe(32))".
  • ENLACE_ADMIN_EMAILS — comma-separated admin emails (gate /_admin).
  • ENLACE_ALLOW_UNSIGNED=1 — opt-out from fail-fast (diagnostics only).

Per-app access & runtime grants

Each app declares an access level in its app.toml (public | protected:shared | protected:user). A protected:user app may also declare a static baseline allow-list:

access = "protected:user"
allowed_users = ["owner@example.com"]   # always allowed; edit-in-code baseline

On top of that baseline you can grant access at runtime — no redeploy — from the admin dashboard or the CLI. Runtime grants are additive (effective access = allowed_users ∪ active grants) and may carry an optional UTC expiry:

enlace-auth grant vault alice@example.com --expires 2026-12-31   # end of day UTC
enlace-auth list-grants --app vault
enlace-auth revoke-grant vault alice@example.com

Grants live in a grants/ store alongside sessions/ and users/ under [auth.stores] path, so they persist across restarts and redeploys. A grant on an app with an empty allowed_users (open to any authenticated user) is rejected — it would have no additive effect and would unintentionally restrict an open app. To remove a user listed in allowed_users, edit app.toml (that layer is intentionally code-managed); the admin panel manages the runtime layer.

Doctor checks

from enlace.doctor import run_doctor
from enlace_auth.diagnostics import static_checks, http_checks

report = run_doctor(
    config,
    base_url="http://localhost:8000",
    extra_static_checks=static_checks,
    extra_http_checks=http_checks,
)

Status

Extracted from enlace 0.0.11. The Python API is stable; an admin frontend ships separately as a normal enlaced app.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

enlace_auth-0.1.18.tar.gz (80.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

enlace_auth-0.1.18-py3-none-any.whl (68.2 kB view details)

Uploaded Python 3

File details

Details for the file enlace_auth-0.1.18.tar.gz.

File metadata

  • Download URL: enlace_auth-0.1.18.tar.gz
  • Upload date:
  • Size: 80.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.12.1 {"installer":{"name":"uv","version":"0.12.1","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for enlace_auth-0.1.18.tar.gz
Algorithm Hash digest
SHA256 d8c1b14bcf2736dbfacdab8206a40343a0c6a3bf71ca197e75be0d81bb0e65be
MD5 b5def446669c48fcc52c53c8c6d42fcf
BLAKE2b-256 06fef1efa71d4aacd797d7e0d5e24fb4752bc7663940d685bdf34f05e8776629

See more details on using hashes here.

File details

Details for the file enlace_auth-0.1.18-py3-none-any.whl.

File metadata

  • Download URL: enlace_auth-0.1.18-py3-none-any.whl
  • Upload date:
  • Size: 68.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.12.1 {"installer":{"name":"uv","version":"0.12.1","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for enlace_auth-0.1.18-py3-none-any.whl
Algorithm Hash digest
SHA256 1f25807c0f9b9bb57ae5191b46fdb7ae5c33a42b6aa5a499711f255e404bdd31
MD5 549d0b82f2f47d2ea53f38683b369c17
BLAKE2b-256 7bf8ae72d03ed471c218f3311f8c610e75bc8cba48698ffe8a6008dbdc92d68f

See more details on using hashes here.

Release history Release notifications | RSS feed

0.1.22

2 files

0.1.21

2 files

0.1.20

2 files

0.1.19

2 files

This release

0.1.18 This release

2 files

0.1.17

2 files

0.1.16

2 files

0.1.15

2 files

0.1.14

2 files

0.1.13

2 files

0.1.12

2 files

0.1.11

2 files

0.1.10

2 files

0.1.9

2 files

0.1.8

2 files

0.1.7

2 files

0.1.6

2 files

0.1.5

2 files

0.1.4

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page