Skip to main content

hedron-workbench

PyPI Python License: MIT

Optional Posit Workbench / RStudio Server deployment adapter for Hedron.

An existing FastAPI Hedron app can run unchanged behind Workbench by switching the launch command. Installing or importing this package does not wrap your application. RS_SERVER_URL is discovery-only and never grants trust.

Also available as hedron[workbench].

Package maturity: Beta · Train: 0.46.x · pin >=0.46.0,<0.47

Supported Workbench floor is 2025.05.1; current verified lane is 2026.07.0.

Behavior is reimplemented from observed fastapi-workbench 0.3.4 (MIT) with attribution. This package does not depend on or vendor that project.

Install

pip install "hedron-workbench>=0.46.0,<0.47"
# or
uv add "hedron[workbench]>=0.46.0,<0.47"

Hedron application facade

Import HedronWorkbench in place of Hedron. With no Workbench signal it is an ordinary Hedron application: local Uvicorn, generic ASGI root_path, routes, middleware, and cookies retain Hedron behavior.

from hedron_workbench import HedronWorkbench

app = HedronWorkbench(
    title="My app",
    session_secret="replace-me",
)

Run the same object locally with Uvicorn or on Workbench with the launcher:

uvicorn app:app --reload
hedron run app:app  # auto-selects the Workbench launcher when RS_SERVER_URL is present
hedron-workbench run app:app

For local proxy reproduction, use HedronWorkbench(workbench_mount="/s/session/p/123"). The explicit mount is applied before Hedron creates session/CSRF cookies and also handles prefixed request paths when the ASGI server does not set root_path.

The class cannot execute rserver-url itself: dynamic discovery needs a bound listener port before the module is imported. The launcher performs that ordering and passes the resolved deployment into the class.

Launcher path

hedron-workbench run app:app
hedron-workbench check --format json
hedron-workbench run app:create_app --factory

The launcher binds a loopback socket, runs rserver-url when RS_SERVER_URL is set, exports HEDRON_ROOT_PATH before importing the app (so session/CSRF cookie Path is correct), recognizes HedronWorkbench as already adapted, and serves with one normalizer.

External binds require the explicit --allow-external-bind flag. The built-in runner supports --reload and --workers: its parent binds and discovers once, then execs Uvicorn's supervisor/workers with the inherited listener and resolved mount. Reload and multiple workers cannot be enabled together.

workbenchify(app) remains available for adapting an already-created generic ASGI application. The response boundary repairs Hedron-owned cookies whose path is still /; third-party cookies remain application-owned.

app.workbench_status() returns a redacted deployment diagnostic without exposing session IDs, URL credentials, or token-shaped values.

Public links and email invites

Use the facade to build links that leave the current browser, such as email invites, OAuth callbacks, and password resets:

from fastapi import Request


@app.post("/invite")
def send_invite(request: Request):
    accept_url = app.external_url_for(
        "accept_invite",
        request=request,
        invite_id="abc123",
        query={"token": "signed-single-use-token"},
    )
    # enqueue email containing accept_url

external_url* is deliberately durable: a disposable Workbench /s/.../p/... session URL is rejected. Use browser_url* for a link that stays in the current interactive session, and deploy durable invitations/callbacks to a stable URL (typically Posit Connect or an explicit external_base_url). On Posit Connect, a request can supply the platform's app-base header, but it is accepted only when its path exactly matches ASGI root_path and Connect's protected runtime marker is present (or an immediate proxy peer is explicitly trusted). Outside either platform, configure a stable base explicitly:

app = HedronWorkbench(
    title="My app",
    session_secret="replace-me",
    external_base_url="https://apps.example.com/my-app",
)

If no trusted base exists, link generation raises ValueError; it never falls back to an untrusted inbound Host header. Route paths must remain local and query parameters are encoded structurally. A Workbench discovery result that contains only a mount path also fails for public links because its inferred origin is loopback; configure workbench_public_base_url for browser-only links or a stable external_base_url for durable links.

Hands-off URL adaptation

Hedron-owned component URL attributes (href, form actions, HTMX request and history paths, assets), safe local response redirects, HTMX redirect/location headers, OpenAPI, static assets, cookies, and WebSockets are mount-aware. A request-time ASGI root_path from Posit Connect or a generic proxy is sufficient; the app does not need to manually call local_href or mounted_redirect. Connect's authenticated proxy adds its content prefix to cookie paths but passes redirect locations through, so the adapter de-scopes only Hedron-owned cookies before Connect's outer rewrite and still mounts local response headers itself.

Mounted pages expose window.Hedron.href(), .fetch(), .eventSource(), .websocketUrl(), and .websocket() for application JavaScript. Python code can use app.href_for(), app.redirect_for(), app.browser_url_for(), and app.external_url_for(). app.external_base(request=...) captures a validated, immutable base for a background job; app.deployment_capabilities() explains whether that base is browser-only or durable.

Raw trusted HTML, arbitrary JavaScript strings, third-party ASGI response bodies, third-party cookies, and a stable sharing destination cannot be inferred safely. Those remain explicit integration points.

Diagnostics and topology profiles

hedron-workbench doctor --format json
hedron-workbench doctor app:app --live --mount /s/example/p/8050
hedron-workbench run app:app --topology launcher-kubernetes

doctor --live binds, discovers when applicable, imports the app after the handoff, and ASGI-probes generated URLs and cookie paths. Topology profiles cover local, local Launcher, Kubernetes Launcher, Slurm Launcher, and external reverse proxy deployments. Remote Launcher profiles select a reachable bind by default; proxy CIDRs must still be explicitly bounded (wildcard trust remains rejected).

Non-goals

Flask/Django/WSGI, bundling rserver-url, automated Connect publishing, treating Workbench or Connect login as Hedron identity, or guessing a durable deployment from an ephemeral session.

License

MIT. See the repository license.

Metadata

Release files for hedron-workbench 0.46.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for hedron-workbench 0.46.0
File Size Uploaded
hedron_workbench-0.46.0.tar.gz 10.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for hedron-workbench 0.46.0
File Interpreter ABI Platform
hedron_workbench-0.46.0-py3-none-any.whl Python 3 none any Details

Total release size: 21.3 kB

Release files / hedron_workbench-0.46.0.tar.gz

Download URL hedron_workbench-0.46.0.tar.gz
Size 10.0 kB
Tags Source
SHA-256 checksum
How to use checksums
ca9654970ea67b92c063ae4d929b95de61e4e4bc125bc08fb40fb48fdb912af1
BLAKE2b-256 checksum
How to use checksums
1dd58fa4bcb83f881d7265ab0a0f447294fa527e5728b7d8e3cbd85f5650a722
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.12.1 {"installer":{"name":"uv","version":"0.12.1","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / hedron_workbench-0.46.0-py3-none-any.whl

Download URL hedron_workbench-0.46.0-py3-none-any.whl
Size 11.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
db9f8fd5e9cba8551de928f912628f0b81b687b76d1cd6d44624685f27a23b04
BLAKE2b-256 checksum
How to use checksums
7516c466ff112035cc9333d8ed2ca1c88f3ba0b83405ec69686186f08be7d1e1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.12.1 {"installer":{"name":"uv","version":"0.12.1","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

0.67.0

2 release files

0.66.2

2 release files

0.66.1

2 release files

0.66.0

2 release files

0.65.0

2 release files

0.64.1

2 release files

0.64.0

2 release files

0.63.0

2 release files

0.62.0

2 release files

0.61.0

2 release files

0.60.2

2 release files

0.60.1

2 release files

0.60.0

2 release files

0.59.0

2 release files

0.58.1

2 release files

0.58.0

2 release files

0.57.0

2 release files

0.56.0

2 release files

0.55.0

2 release files

0.54.0

2 release files

0.53.0

2 release files

0.52.0

2 release files

0.51.2

2 release files

0.51.1

2 release files

0.51.0

2 release files

0.50.3

2 release files

0.50.2

2 release files

0.50.1

2 release files

0.50.0

2 release files

0.49.1

2 release files

0.49.0

2 release files

0.48.0

2 release files

0.47.0

2 release files

This release

0.46.0 This release

2 release files

0.45.0

2 release files

0.44.0

2 release files

0.43.0

2 release files

0.42.0

2 release files

0.41.0

2 release files

0.40.0

2 release files

0.39.0

2 release files

0.38.0

2 release files

0.37.0

2 release files

0.36.0

2 release files

0.35.0

2 release files

0.34.0

2 release files

0.33.0

2 release files

0.32.0

2 release files

0.31.0

2 release files

0.30.0

2 release files

0.29.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page