
FastAPI-Azure-auth
Azure AD Authentication for FastAPI apps made easy.
🚀 Description
FastAPI is a modern, fast (high-performance), web framework for building APIs with Python, based on standard Python type hints.
At Intility, FastAPI is a popular framework among its developers, with customer-facing and internal services developed entirely on a FastAPI backend.
This package enables our developers (and you 😊) to create features without worrying about authentication and authorization.
Also, we're hiring!
⚡️ Quick start
Azure
Azure docs will be available when create-fastapi-app is developed. In the meantime please use the .NET documentation.
FastAPI
- Install this library:
pip install fastapi-azure-auth
# or
poetry add fastapi-azure-auth
- Include
swagger_ui_oauth2_redirect_urlandswagger_ui_init_oauthin your FastAPI app initialization:
app = FastAPI(
...
swagger_ui_oauth2_redirect_url='/oauth2-redirect',
swagger_ui_init_oauth={
'usePkceWithAuthorizationCodeGrant': True,
'clientId': settings.OPENAPI_CLIENT_ID # SPA app with grants to your app
},
)
-
Ensure you have CORS enabled for your local environment, such as
http://localhost:8000. See main.py and theBACKEND_CORS_ORIGINSin config.py -
Import and configure your Azure authentication:
from fastapi_azure_auth.auth import AzureAuthorizationCodeBearer
azure_scheme = AzureAuthorizationCodeBearer(
app=app,
app_client_id=settings.APP_CLIENT_ID, # Web app
scopes={
f'api://{settings.APP_CLIENT_ID}/user_impersonation': 'User Impersonation',
},
)
- Set your
intility_schemeas a dependency for your wanted views/routers:
app.include_router(api_router, prefix=settings.API_V1_STR, dependencies=[Depends(azure_scheme)])
⚙️ Configuration
For those using a non-Intility tenant, you also need to make changes to the provider_config:
from fastapi_azure_auth.provider_config import provider_config
intility_scheme = AzureAuthorizationCodeBearer(
...
)
provider_config.tenant_id = 'my-own-tenant-id'
If you want, you can deny guest users to access your API by passing the allow_guest_users=False
to AzureAuthorizationCodeBearer:
intility_scheme = AzureAuthorizationCodeBearer(
...
allow_guest_users=False
)
💡 Nice to knows
A User object is attached to the request state if the token is valid. Unparsed claims can be accessed at
request.state.user.claims.
from fastapi_azure_auth.user import User
from fastapi import Request
@router.get(...)
async def world(request: Request) -> dict:
user: User = request.state.user
return {'user': user}
Metadata
Release files for fastapi-azure-auth 1.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| fastapi-azure-auth-1.1.0.tar.gz | 8.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| fastapi_azure_auth-1.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 16.6 kB
Release files / fastapi-azure-auth-1.1.0.tar.gz
| Download URL | fastapi-azure-auth-1.1.0.tar.gz |
|---|---|
| Size | 8.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b609ca6dcfa1d2ede8b603bfd56c4528ee5761252b0dcee8235b582e082c7b89
|
|
BLAKE2b-256 checksum How to use checksums |
a228db4ea691a562e9f9e05471dddc0d174ffd59d293f5ce6c68e12a8efc073d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
poetry/1.1.7 CPython/3.9.6 Linux/5.8.0-1039-azure
|
Release files / fastapi_azure_auth-1.1.0-py3-none-any.whl
| Download URL | fastapi_azure_auth-1.1.0-py3-none-any.whl |
|---|---|
| Size | 8.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c35a95b06bbfc7766aa89cbfba96594ea44bef90712416be990dfd60de1e937c
|
|
BLAKE2b-256 checksum How to use checksums |
3ab5cc57f9d80c51e18cf64396b88c87a9732991a7d7b495fc5f5f2f6a9f6685
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
poetry/1.1.7 CPython/3.9.6 Linux/5.8.0-1039-azure
|