Skip to main content

Simple JWT token flask service security library.

Project description

[Build Status PyPI version

jwt_authenticator

jwt_authenticator is a simply python library for adding JWT token authentication/authorization in flask web sites/services. It controls access either by checking for just a validated token, or optionally, a single role claim from the token. Access is controlled by decorating the endpoint functions with an attribute.

Installation

Use the package manager pip to install jwt_authenticator.

pip install jwt-authenticator

If using RS256, you must also:

pip install cryptography

Usage

In the main application initialization area

from flask import Flask
from jwt_authenticator import AuthenticationHandler

APP = Flask(__name__)
AuthenticationHandler.load_configuration(APP)

In the endpoints

from jwt_authenticator import AuthenticationHandler, AuthError

@api.route('/<name>', methods=['GET'])
@AuthenticationHandler.requires_auth("admin")
def get_one(name):
    return f"Hello {name}"

@api.route('/<name>', methods=['GET'])
@AuthenticationHandler.requires_auth()
def get_one(name):
    return f"Hello {name}"

Configuration

jwt_authenticator requires two configuration values to work. These can be specified either in the normal Flask application configuration or as environment variables. Environment variable values will override application configuration values, when

AuthenticationHanlder.load_configuration(app)

is called.

APP.config (i.e. flask application configuration)

  • SECRET - the key used to sign the JWT token. Option if JWKS_URL specified.
  • AUDIENCE - the audience claim used in the JWT token
  • JKWS_URL - [OPTIONAL] OIDC key discovery URL
  • GROUPS_CLAIM - [OPTIONAL] which claim has the list of groups. Defaults to "groups"

Environment Variables

  • JWT_SECRET - will override SECRET
  • JWT_AUDIENCE - will override AUDIENCE
  • JWKS_URL - will override JWKS_URL
  • GROUPS_CLAIM - will override GROUPS_CLAIM

Contributing

Pull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.

Please make sure to update tests as appropriate.

Building

  • Requires 'make'
make init
make test
make package

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

jwt_authenticator-1.0.6.tar.gz (6.4 kB view details)

Uploaded Source

Built Distribution

jwt_authenticator-1.0.6-py3-none-any.whl (6.1 kB view details)

Uploaded Python 3

File details

Details for the file jwt_authenticator-1.0.6.tar.gz.

File metadata

  • Download URL: jwt_authenticator-1.0.6.tar.gz
  • Upload date:
  • Size: 6.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/5.1.1 CPython/3.12.7

File hashes

Hashes for jwt_authenticator-1.0.6.tar.gz
Algorithm Hash digest
SHA256 a2c6ca528818360e9848d6435bc0902e07c7f8eaed274a3e4bc76758f67321f5
MD5 5240e4cdac293e70cc3b978febd47fbe
BLAKE2b-256 861cf5fbf0b667fb86c27f222b365d8dc38a8dd591aaeaf6aad56e25513f3d25

See more details on using hashes here.

File details

Details for the file jwt_authenticator-1.0.6-py3-none-any.whl.

File metadata

File hashes

Hashes for jwt_authenticator-1.0.6-py3-none-any.whl
Algorithm Hash digest
SHA256 2f8123906792249de52a4c522b2eec66a90ff2cbdd5999a2cb9c3b969ff22f6b
MD5 5b52ccee1aa8f8c62b935d142a112daf
BLAKE2b-256 ad6dc0dacb37dc15f4506dda189be33b4c034a774cb3a53e76c62bdac36a3895

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page