Skip to main content

Flask Authentication

Flask Endpoints for User Management and Authentication Middleware

  1. Endpoints
  2. Authentication

Endpoints

from frappyflaskauth import register_endpoints
from flask import Flask

app = Flask(__name__)
# create store instances for users
user_store = ...
# this is a minimal configuration
register_endpoints(app, user_store)

Parameters

  • app - the Flask app instance
  • user_store - an store class providing user related methods
  • token_store - optional - if you want login sessions to survive a server restart
  • options_override - default {} - a dictionary containing configuration options that override the defaults:

Options

  • api_prefix - default /api/user - the API prefix used for all endpoints (e.g. /api/user/login)
  • token_expiration - default 86400 - the number of seconds a login session is valid for before it expires
  • default_permissions - default [] - the initial permissions any user receives on creation (local users)
  • user_admin_permission - default admin - the permission a user requires to be able to invoke user management endpoints like update permissions, delete users, fetch all users, update passwords of other users.
  • no_user_management - default False - if you don't want any user management endpoints to be registered
  • api_keys - default False - if you need API keys to access endpoints (integrated into check_login_state). API keys are provided in the Authorization header prefixed with Token $KEY (where $KEY is the user's API key)
  • allow_own_profile_edit - default False - if this is set to true, any user can update their own profile info (user.profile).
  • page_size - default 25 - the number of users returned with the /users endpoint (lists all users)

Authentication

To check if a user is authenticated and get the currently logged in user in your own endpoints, simply use the check_login_state function. It will

  • extract the authentication header
    • return a 401, if no authentication header is present
  • check if that header is valid and associated with a user
    • return a 401, if the header is invalid or expired
  • has the option to check if the associated user has a specific permission
    • return a 403, if the user doesn't have the required permission
  • return the user object to the caller, if all checks are successful
  • specific restrictions for API key access
    • return a 403, if the user tries to use an API key to access an endpoint not configured for this
from frappyflaskauth import check_login_state
from flask import Flask, jsonify

app = Flask(__name__)

@app.route("/api/my-endpoint", methods=["GET"])
def my_custom_endpoint():
    user = check_login_state("view")
    # execution will only go past this point, if user is logged in AND has "view" permission
    print(user.id, user.permissions)  # this is the currently logged in user
    return jsonify({})

@app.route("/api/my-endpoint", methods=["GET"])
def my_logged_in_endpoint():
    _ = check_login_state()  # simply check if the user is logged in, ignore the returned user
    return jsonify({})

@app.route("/api/my-endpoint", methods=["GET"])
def my_api_key_enabled_endpoint():
    _ = check_login_state(allow_api_key=True)

Parameters:

  • permission, default None which is a string that is checked against the user.permissions field (which is a list)
  • allow_api_key, default False which is a flag enabling API keys to access the endpoint protected by this function call.

Release files for frappyflaskauth 1.6.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for frappyflaskauth 1.6.3
File Size Uploaded
frappyflaskauth-1.6.3.tar.gz 9.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for frappyflaskauth 1.6.3
File Interpreter ABI Platform
frappyflaskauth-1.6.3-py3-none-any.whl Python 3 none any Details

Total release size: 20.2 kB

Release files / frappyflaskauth-1.6.3.tar.gz

Download URL frappyflaskauth-1.6.3.tar.gz
Size 9.8 kB
Tags Source
SHA-256 checksum
How to use checksums
a6e5f402117b0ac1e03e401f04d6693fb674fc11f417d091b03e17763f245dd7
BLAKE2b-256 checksum
How to use checksums
e1933c79b4334edd156693f130eedda0122b9957ea49e604cd1f0c50d8f876c2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.11.5

Release files / frappyflaskauth-1.6.3-py3-none-any.whl

Download URL frappyflaskauth-1.6.3-py3-none-any.whl
Size 10.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0d44aed61c7d8ea89a61c5f6a66f0e635da5e209059c6b3694485af201d2544e
BLAKE2b-256 checksum
How to use checksums
305e9f5095fcce998c6d5429ac5ac4dcd3f6489029cd9b710cb45b46e98435fa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.11.5

Release history Release notifications | RSS feed

This release

1.6.3 This release

2 release files

1.6.2

2 release files

1.6.1

2 release files

1.6.0

2 release files

1.5.2

2 release files

1.5.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page