Skip to main content

WSGI authentication middleware

This app is just one piece in our bigger authorization scheme for microservices. Its purpose is make migrating to session cookies simpler by ensuring that backend microservices only need to deal with JWTs that contain all the needed claims.

Architecture decisions

  • The session UUIDs are stored in a redis database that can be reached by the wrapped Flask app.
  • The session UUIDs are passed as cookie values.
  • The redis database contains a JWT for each valid session UUID. The middleware doesn’t care about the actual contents of the JWT it just needs to be there.
  • The session UUIDs in the cookie are signed using itsdangerous. The middleware only handles session UUIDs with a valid signature.

Usage

from impact_stack.auth_wsgi_middleware import AuthMiddleware

app = Flask(__name__)
AuthMiddleware.init_app(app)

Configuration variables

The middleware reads its configuration from the Flask app.config dictionary. All variables are prefixed with AUTH_….

variable description
AUTH_SECRET_KEY The secret key used to verify the cookie value’s signature. It defaults to SECRET_KEY.
AUTH_SIGNATURE_ALGORITHM A hash function to use as digest method for signing the session IDs. Defaults to hashlib.sha256
AUTH_COOKIE_NAME Name of the cookie from which the the session UUID is read. Defaults to session_uuid.
AUTH_REDIS_URL URL to a redis database (see the redis-py documentation for more information)).
AUTH_REDIS_CLIENT_CLASS The redis client class used by the middleware. Mostly needed for testing. Defaults to redis.Redis
AUTH_HEADER_TYPE Prefix used when adding the JWT to the HTTP Authorization header. Defaults to the value of JWT_HEADER_TYPE which in turn defaults to 'Bearer'.

Metadata

Release files for impact-stack-auth-wsgi-middleware 0.8.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for impact-stack-auth-wsgi-middleware 0.8.0
File Size Uploaded
impact_stack_auth_wsgi_middleware-0.8.0.tar.gz 22.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for impact-stack-auth-wsgi-middleware 0.8.0
File Interpreter ABI Platform
impact_stack_auth_wsgi_middleware-0.8.0-py3-none-any.whl Python 3 none any Details

Total release size: 39.0 kB

Release files / impact_stack_auth_wsgi_middleware-0.8.0.tar.gz

Download URL impact_stack_auth_wsgi_middleware-0.8.0.tar.gz
Size 22.1 kB
Tags Source
SHA-256 checksum
How to use checksums
a10ab431b24a6326b5c46e2b0175d92833ca6de6763ba41d007ae9558fd6157b
BLAKE2b-256 checksum
How to use checksums
b2f53484adb3014164d2f9c1db0ad7baab6256c738955e5edd652c8f00de46ac
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.12

Release files / impact_stack_auth_wsgi_middleware-0.8.0-py3-none-any.whl

Download URL impact_stack_auth_wsgi_middleware-0.8.0-py3-none-any.whl
Size 16.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
36a0b47039e59318b7938ec7aec03a90bb1d9042c5104e86d780e4e8d4188925
BLAKE2b-256 checksum
How to use checksums
4a9f2c28b621b4e9007944346859079c56bde8f6d0a07b3d9aa1a994961ca997
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.12

Release history Release notifications | RSS feed

This release

0.8.0 This release

2 release files

0.7.0

2 release files

0.5.3

1 release file

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page