Skip to main content

MAuth Client for Python

Project description

MAuth Client Python

MAuth Client Python is an authentication library to manage the information needed to both sign and authenticate requests and responses for Medidata's MAuth authentication system.

Pre-requisites

To use MAuth Authenticator you will need:

  • An MAuth app ID
  • An MAuth private key (with the public key registered with Medidata's MAuth server)

Installation

To resolve packages using pip, add the following to ~/.pip/pip.conf:

[global]
index-url = https://<username>:<password>@mdsol.jfrog.io/mdsol/api/pypi/pypi-packages/simple/

Install using pip:

$ pip install mauth-client

Or directly from GitHub:

$ pip install git+https://github.com/mdsol/mauth-client-python.git

This will also install the dependencies.

To resolve using a requirements file, the index URL can be specified in the first line of the file:

--index-url https://<username>:<password>@mdsol.jfrog.io/mdsol/api/pypi/pypi-packages/simple/
mauth-client==<latest version>

Usage

Signing Outgoing Requests

import requests
from mauth_client.requests_mauth import MAuth

# MAuth configuration
APP_UUID = "<MAUTH_APP_UUID>"
private_key = open("private.key", "r").read()
mauth = MAuth(APP_UUID, private_key)

# Call an MAuth protected resource, in this case an iMedidata API
# listing the studies for a particular user
user_uuid = "10ac3b0e-9fe2-11df-a531-12313900d531"
url = "https://innovate.imedidata.com/api/v2/users/{}/studies.json".format(user_uuid)

# Make the requests call, passing the auth client
result = requests.get(url, auth=mauth)

# Print results
if result.status_code == 200:
    print([r["uuid"] for r in result.json()["studies"]])
print(result.text)

The mauth_sign_versions option can be set as an environment variable to specify protocol versions to sign outgoing requests:

Key Value
MAUTH_SIGN_VERSIONS (optional) Comma-separated protocol versions to sign requests. Defaults to v1.

This option can also be passed to the constructor:

mauth_sign_versions = "v1,v2"
mauth = MAuth(APP_UUID, private_key, mauth_sign_versions)

Authenticating Incoming Requests

MAuth Client Python supports AWS Lambda functions and Flask applications to authenticate MAuth signed requests.

The following variables are required to be configured in the environment variables:

Key Value
APP_UUID APP_UUID for the AWS Lambda function
PRIVATE_KEY Encrypted private key for the APP_UUID
MAUTH_URL MAuth service URL (e.g. https://mauth-innovate.imedidata.com)

The following variables can optionally be set in the environment variables:

Key Value
MAUTH_API_VERSION (optional) MAuth API version. Only v1 exists as of this writing. Defaults to v1.
MAUTH_MODE (optional) Method to authenticate requests. local or remote. Defaults to local.
V2_ONLY_AUTHENTICATE (optional) Authenticate requests with only V2. Defaults to False.

AWS Lambda functions

from mauth_client.lambda_authenticator import LambdaAuthenticator

authenticator = LambdaAuthenticator(method, url, headers, body)
authentic, status_code, message = authenticator.is_authentic()
app_uuid = authenticator.get_app_uuid()

WSGI Applications

To apply to a WSGI application you should use the MAuthWSGIMiddleware. You can make certain paths exempt from authentication by passing the exempt option with a set of paths to exempt.

Here is an example for Flask. Note that requesting app's UUID and the protocol version will be added to the request environment for successfully authenticated requests.

from flask import Flask, request, jsonify
from mauth_client.consts import ENV_APP_UUID, ENV_PROTOCOL_VERSION
from mauth_client.middlewares import MAuthWSGIMiddleware

app = Flask("MyApp")
app.wsgi_app = MAuthWSGIMiddleware(app.wsgi_app, exempt={"/app_status"})

@app.get("/")
def root():
    return jsonify({
        "msg": "authenticated",
        "app_uuid": request.environ[ENV_APP_UUID],
        "protocol_version": request.environ[ENV_PROTOCOL_VERSION],
    })

@app.get("/app_status")
    return "this route is exempt from authentication"

ASGI Applications

To apply to an ASGI application you should use the MAuthASGIMiddleware. You can make certain paths exempt from authentication by passing the exempt option with a set of paths to exempt.

Here is an example for FastAPI. Note that requesting app's UUID and the protocol version will be added to the ASGI scope for successfully authenticated requests.

from fastapi import FastAPI, Request
from mauth_client.consts import ENV_APP_UUID, ENV_PROTOCOL_VERSION
from mauth_client.middlewares import MAuthASGIMiddleware

app = FastAPI()
app.add_middleware(MAuthASGIMiddleware, exempt={"/app_status"})

@app.get("/")
async def root(request: Request):
    return {
        "msg": "authenticated",
        "app_uuid": request.scope[ENV_APP_UUID],
        "protocol_version": request.scope[ENV_PROTOCOL_VERSION],
    }

@app.get("/app_status")
async def app_status():
    return {
        "msg": "this route is exempt from authentication",
    }

Contributing

See CONTRIBUTING

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

mauth_client-1.6.5.tar.gz (17.1 kB view details)

Uploaded Source

Built Distribution

mauth_client-1.6.5-py3-none-any.whl (21.7 kB view details)

Uploaded Python 3

File details

Details for the file mauth_client-1.6.5.tar.gz.

File metadata

  • Download URL: mauth_client-1.6.5.tar.gz
  • Upload date:
  • Size: 17.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.7.1 CPython/3.10.12 Linux/6.5.0-1021-azure

File hashes

Hashes for mauth_client-1.6.5.tar.gz
Algorithm Hash digest
SHA256 432e66ca0d4e1659ce6156dec5ce6389f7f435c407e29f3f557238fa55cf7e34
MD5 dfa3e8c1e2bcb3ebc1587aa53083169f
BLAKE2b-256 6025a374a3b4263526d73e778640426586ddd28db71c3e149b622d09fe00ddaf

See more details on using hashes here.

File details

Details for the file mauth_client-1.6.5-py3-none-any.whl.

File metadata

  • Download URL: mauth_client-1.6.5-py3-none-any.whl
  • Upload date:
  • Size: 21.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.7.1 CPython/3.10.12 Linux/6.5.0-1021-azure

File hashes

Hashes for mauth_client-1.6.5-py3-none-any.whl
Algorithm Hash digest
SHA256 4d5163227708ba7f203fc277c348b5856d806ed4aa2e2609b37f3d0b35284c35
MD5 4bb97729023f92a8c6a0227a2db68e1e
BLAKE2b-256 2f91e593cb2e3d96c83eef77c33b56130d05db9eae341bba608fb151e9a0389c

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page