Verify JWTs with multiple public keys, FastAPI middleware for auth
NOTE: Due to https://github.com/encode/starlette/discussions/2446 .env file is no longer supported for configuration.
Creating signing keys
multikeyjwt genkey ./jwtsign.key
see –help for more info
Docker
For more controlled deployments and to get rid of “works on my computer” -syndrome, we always make sure our software works under docker.
It’s also a quick way to get started with a standard development environment.
SSH agent forwarding
We need buildkit:
export DOCKER_BUILDKIT=1
And also the exact way for forwarding agent to running instance is different on OSX:
export DOCKER_SSHAGENT="-v /run/host-services/ssh-auth.sock:/run/host-services/ssh-auth.sock -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock"
and Linux:
export DOCKER_SSHAGENT="-v $SSH_AUTH_SOCK:$SSH_AUTH_SOCK -e SSH_AUTH_SOCK"
Creating a development container
Build image, create container and start it:
docker build --ssh default --target devel_shell -t multikeyjwt:devel_shell . docker create --name multikeyjwt_devel -v `pwd`":/app" -it `echo $DOCKER_SSHAGENT` multikeyjwt:devel_shell docker start -i multikeyjwt_devel
pre-commit considerations
If working in Docker instead of native env you need to run the pre-commit checks in docker too:
docker exec -i multikeyjwt_devel /bin/bash -c "pre-commit install" docker exec -i multikeyjwt_devel /bin/bash -c "pre-commit run --all-files"
You need to have the container running, see above. Or alternatively use the docker run syntax but using the running container is faster:
docker run --rm -it -v `pwd`":/app" multikeyjwt:devel_shell -c "pre-commit run --all-files"
Test suite
You can use the devel shell to run py.test when doing development, for CI use the “tox” target in the Dockerfile:
docker build --ssh default --target tox -t multikeyjwt:tox . docker run --rm -it -v `pwd`":/app" `echo $DOCKER_SSHAGENT` multikeyjwt:tox
Production docker
There’s a “production” target as well for running the application, remember to change that architecture tag to arm64 if building on ARM:
docker build --ssh default --target production -t multikeyjwt:latest . docker run -it --name multikeyjwt multikeyjwt:amd64-latest
Development
TLDR:
Create and activate a Python 3.11 virtualenv (assuming virtualenvwrapper):
mkvirtualenv -p `which python3.11` my_virtualenv
change to a branch:
git checkout -b my_branch
install Poetry: https://python-poetry.org/docs/#installation
Install project deps and pre-commit hooks:
poetry install pre-commit install pre-commit run --all-files
Ready to go.
Remember to activate your virtualenv whenever working on the repo, this is needed because pylint and mypy pre-commit hooks use the “system” python for now (because reasons).
Release files for multikeyjwt 1.7.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| multikeyjwt-1.7.0.tar.gz | 10.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| multikeyjwt-1.7.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 22.9 kB
Release files / multikeyjwt-1.7.0.tar.gz
| Download URL | multikeyjwt-1.7.0.tar.gz |
|---|---|
| Size | 10.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
73050fc3dd685c36dbbdcd8d4602b963fad39818f4b8a99b0104f50fc5b257f6
|
|
BLAKE2b-256 checksum How to use checksums |
91d8343cea7e5c83966d78aa51bdab3fb9061ef457ad1c61efc1a7aeba9aab3a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.11.7
|
Release files / multikeyjwt-1.7.0-py3-none-any.whl
| Download URL | multikeyjwt-1.7.0-py3-none-any.whl |
|---|---|
| Size | 12.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
19c2ef3f1b040c5c1c799422bab55f8429308ec73ef64e24db3dc85b393cbc3f
|
|
BLAKE2b-256 checksum How to use checksums |
98570b2eb40df649668034afaa1b1260d5bc5f6a8f26f1d807c2900715e01583
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.11.7
|