Skip to main content

Eve JWT authentication

Project description

https://img.shields.io/pypi/v/eve-auth-jwt.svg https://travis-ci.org/rs/eve-auth-jwt.svg?branch=master

An OAuth 2 JWT token validation module for Eve.

Installation

To install eve-auth-jwt, simply:

$ pip install eve-auth-jwt

At Eve initialization:

from eve import Eve
from eve_auth_jwt import JWTAuth

app = Eve(auth=JWTAuth, settings=SETTINGS)

Configuration

This module reads its configuration form Eve settings. Here is the list of new directives:

  • JWT_SECRET (required): Defines the symetric secret token secret used to de/encode the token (async keys support is a TODO).

  • JWT_ISSUER (required): Defines the required token issuer (iss claim).

  • JWT_AUDIENCES: Defines a list of accepted audiences (aud claim). If not provided, only tokens with no audience set will be accepted. The resource level audiences parameter is also available.

  • JWT_ROLES_CLAIM: Defines the claim name for roles. If set, Eve roles check will be activated, and any resources with allowed_roles set will require to have those roles present in the defined token’s claim.

  • JWT_SCOPE_CLAIM: Defines the claim name for scope. If set and the token has a claim of the same name containing the string viewer, only GET and HEAD methods will be granted. All other values are ignored and added to the list of exposed roles with the scope: prefix.

Reading Roles

If access is granted, the authentication module exposes roles and token’s claims thru get_authen_roles() and get_authen_claims() methods. You may access those values from your event hook as follow:

def my_hook(...)
    resource_def = app.config['DOMAIN'][resource_name]
    auth = resource_def['authentication']
    if 'somerole' in auth.get_authen_roles():
        # grant some finer access

Licenses

All source code is licensed under the MIT License.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

eve-auth-jwt-1.0.1.tar.gz (4.0 kB view details)

Uploaded Source

Built Distribution

eve_auth_jwt-1.0.1-py2.py3-none-any.whl (6.3 kB view details)

Uploaded Python 2 Python 3

File details

Details for the file eve-auth-jwt-1.0.1.tar.gz.

File metadata

File hashes

Hashes for eve-auth-jwt-1.0.1.tar.gz
Algorithm Hash digest
SHA256 b06ac0ece38022dc4637d3778094d6b1889f81c8a652a8f3e4c234d81624f46d
MD5 60a3884a6f4ba2215106bf95295673cf
BLAKE2b-256 b8fba763e1934cf092307d102d5774645f2f0a9e29d05c9a90bee679cd8e1396

See more details on using hashes here.

File details

Details for the file eve_auth_jwt-1.0.1-py2.py3-none-any.whl.

File metadata

File hashes

Hashes for eve_auth_jwt-1.0.1-py2.py3-none-any.whl
Algorithm Hash digest
SHA256 622ecb6a7708eb88b3281837ef9c7e5a0981128506f2f508ab9ff4eacc87e34e
MD5 82fe334a8558831f8bf6d45ebc475e98
BLAKE2b-256 aec75298d4b8243f917e5b5d66617afcfd8fc4afbafcd73662ed14664272f23e

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page