Skip to main content

ns_jwt: JSON Web Tokens for Notary Service

We will use RS256 (public/private key) variant of JWT signing. (Source: https://pyjwt.readthedocs.io/en/latest/usage.html#encoding-decoding-tokens-with-rs256-rsa). For signing, , NS is assumed to be in possession of a public-private keypair. Presidio can access the public key through static configuration or, possibly, by querying an endpoint on NS, that is specified in the token.

NS tokens carry the following claims:

name description type
data-set SAFE Token that points to the dataset. Presidio is able to synthesize a token with linked assertions based on data-set, project-id and user id String, Private
project-id CoManage/NS name of the project, universally unique and distinct. String, Private
ns-token SAFE Token of the NS generated from its public key String, Private
ns-name Human-readable NS name String, Private
iss NS FQDN String, Registered
sub OSF DCE rendering of DN attributes from user’s X.509 cert String, Public
exp Expiration date Date, Registered
iat Issued at date Date, Registered
name Full name of subject String, Public

For dates, a JSON numeric value representing the number of seconds from 1970-01-01T00:00:00Z UTC until the specified UTC date/time, ignoring leap seconds. This is equivalent to the IEEE Std 1003.1, 2013 Edition definition "Seconds Since the Epoch", in which each day is accounted for by exactly 86400 seconds, other than that non-integer values can be represented. See RFC 3339 for details regarding date/times in general and UTC in particular.

Setup and configuration

No external configuration except for dependencies (PyJWT, cryptography, python-dateutil).

As above, use a virtual environment

virtualenv -p $(which python3) venv
source venv/bin/activate
pip install --editable ns_jwt
pip install pytest

Testing

Simply execute the command below. The test relies on having public.pem and private.pem (public and private portions of an RSA key) to be present in the tests/ directory. You can generate new pairs using tests/gen-keypair.sh (relies on openssl installation).

pytest -v ns_jwt

Teardown and Cleanup

None needed.

Troubleshooting

CI Logon or other JWTs may not decode outright using PyJWT due to binascii.Error: Incorrect padding and jwt.exceptions.DecodeError: Invalid crypto padding. This is due to lack of base64 padding at the end of the token. Read it in as a string, then add the padding prior to decoding:

import jwt

with open('token_file.jwt') as f:
  token_string = f.read()

jwt.decode(token_string + "==", verify=False)

Any number of = can be added (at least 2) to fix the padding. If token is read in as a byte string, convert to utf-8 first: jwt_str = str(jwt_bin, 'utf-8'), then add padding (Source: https://gist.github.com/perrygeo/ee7c65bb1541ff6ac770)

Metadata

Release files for ns-jwt 0.1.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ns-jwt 0.1.4
File Size Uploaded
ns_jwt-0.1.4.tar.gz 5.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ns-jwt 0.1.4
File Interpreter ABI Platform
ns_jwt-0.1.4-py3-none-any.whl Python 3 none any Details

Total release size: 10.5 kB

Release files / ns_jwt-0.1.4.tar.gz

Download URL ns_jwt-0.1.4.tar.gz
Size 5.2 kB
Tags Source
SHA-256 checksum
How to use checksums
7ded120f4b31ecb0d5f058058f95be0a8c0bf34cf2b80a56ffc77428e5a8152d
BLAKE2b-256 checksum
How to use checksums
eadcacd658a6247a7faeb250534c428961f85e80bdcd330ff144c27f7db48d49
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.7.1 importlib_metadata/4.10.0 pkginfo/1.8.2 requests/2.27.1 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.10.0

Release files / ns_jwt-0.1.4-py3-none-any.whl

Download URL ns_jwt-0.1.4-py3-none-any.whl
Size 5.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c62233a7c37c4bf8b0fbe1f700abc052d68e6a6820a88b7fe4074c0c71eecb7a
BLAKE2b-256 checksum
How to use checksums
98bf85e4a951fbe48a2d0bd3961947339089c2b23cbda6b684641004ecf4e171
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.7.1 importlib_metadata/4.10.0 pkginfo/1.8.2 requests/2.27.1 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.10.0

Release history Release notifications | RSS feed

This release

0.1.4 This release

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page