Flask-HMAC
This module provides an authentication to Flask routes. The intended use case is for use with REST APIs. It’s simply designed to check that a client is entitled to access a particular route in a Flask application, based on the fact that it must possess a copy of the secret key.
Usage
Server
app = Flask(__name__)
app.config['HMAC_KEY'] = 's3cr3tk3y' # define the secret key in an app config
@app.route("/no_auth_view")
def no_auth_view():
return "no_auth_view"
@app.route("/hmac_auth_view")
@hmac.auth() # decorate view
def hmac_auth_view():
return "hmac_auth_view"
@app.route("/hmac_auth_view")
@hmac.auth(only=["foo"]) # decorate view, only allows foo client access
def hmac_auth_view():
return "hmac_auth_view"
Client
Call without payload
sig = hmac.make_hmac() # generate signature
response = requests.get(
'/hmac_auth_view',
headers={hmac.header: sig}
)
You can also use multiple keys between different applications. Secret keys are stored in HMAC_KEYS in the app settings as a dictionary:
app.config['HMAC_KEYS'] = {
'aservice': 'akey',
'bservice': 'bkey'
}
Then the secret key has to generated with make_hmac_for method.
hmac.make_hmac_for('aservice', request_data) # data is optional
# signature validation for multiple keys
hmac.validate_service_signature(request)
Call with payload
Request payload has to be used as a data for HMAC generation.
data = json.dumps({'foo': 'boo'})
sig = hmac.make_hmac(data) # generate signature
response = requests.post(
'/hmac_auth_view',
data=data,
headers={hmac.header: sig}
)
You can define custom errors overwriting abort method:
class MyHmac(Hmac):
def abort(self):
message = {'status': '403', 'message': 'not authorized'}
response = jsonify(message)
response.status_code = 403
return response
For HMAC auth of all views you can use Flask’s before_request:
@app.before_request
def before_request():
try:
hmac.validate_signature(request)
except HmacException:
return abort(400)
Generate signature for/from another application:
sig = make_hmac(self, data, key=another_app_key)
Change Log
1.2.1
New HMAC_ERROR_CODE configuration option to allow different HTTP Status code responses on failure
1.2
BREAKING CHANGE: @hmac.auth decorator now needs to be called as @hmac.auth()
New only argument for @hmac.auth() to only allow specific clients access
1.1.2
Swaps urlsafe_b64encode for b64encode
1.1.1
Support multiple keys
0.1.1
Able to change secret key in make_hmac method
Method validate_signature created which can be used outside of Hmac class
Custom exceptions
0.0.1
Initial release including the core feature set
Metadata
Release files for flaskhmac 1.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| flaskhmac-1.2.1.tar.gz | 5.1 kB | Details |
Release files / flaskhmac-1.2.1.tar.gz
| Download URL | flaskhmac-1.2.1.tar.gz |
|---|---|
| Size | 5.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3292ccc10b2649dd1fc400d460d16fad6c50c2e49c036634b39c82b30d8d2b22
|
|
BLAKE2b-256 checksum How to use checksums |
68e307697177942de0c927ab44482d0aea1b98a987d559751c4bc0f14b0d56ea
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |