Skip to main content

A facade package used to perform required keycloak actions which will be made available throughout each Orodha service.

Project description

Orodha-Keycloak

This package is a facade interfacing with python-keycloak used by Orodha services in order to make requests to a keycloak server.

Requirements

Along with the requirements in the requirements.txt file, in order for this package to function properly you need to configure keycloak in a certain way.

Here is a tutorial for setting up keycloak clients and service accounts with the keycloak CLI.

The long and short of it is that in order for this package to work you need to set up a keycloak Realm, that has at least one client which you configure to use a confidential access type and secret_key, along with the ability to use service accounts.

Once you do this, you have to give you service account the required permissions for

  • creating users
  • deleting users
  • querying users
  • decoding tokens
  • exchanging tokens

Usage

In order to download this package, you simply have to run the command

python3 -m pip install orodha-keycloak

After downloading the package you can import it to a file with the statement

from orodha_keycloak import OrodhaKeycloakClient

You can find further descriptions of this class in the following section as well as the method class and method docstrings for the class.

Description

This package contains two classes: OrodhaKeycloakClient and OrodhaCredentials. OrodhaKeycloakClient expects an OrodhaCredentials object loaded with the values needed by keycloak. The OrodhaCredentials class expects the following arguments to be in the environment or passed in as kwargs upon instantiation:

  • server_url: the main url for our keycloak server. example: http://keycloak:{port}/auth/
  • realm_name: The name of the keycloak realm that you want to interfacing with.
  • client_id: The client_id of the keycloak client for your service worker you want to use.

The next three are special. in order to create a connection you either have to pass a client_secret_key to the class, or you have to pass a username and a password to the class. If you do not have one of these two choices you will get an error.

  • client_secret_key: Obtained from keycloak, used for connecting securely to the keycloak client.
  • username / password: The username and password of a keycloak user that you want to log in as in order to take actions on the keycloak realm.

If you would like OrodhaCredentials to populate itself from the environment, load these required variables into the environment, making sure that the keys are capitalized and begin with ORODHA_KEYCLOAK, like so:

ORODHA_KEYCLOAK_SERVER_URL

The OrodhaKeycloakClient class is used to make requests and obtain information from our keycloak server. The current methods available on this class are:

  • add_user: Adds a user to keycloak with a password.
  • delete_user: Deletes a keycloak user with a given user_id.
  • get_user: Takes either a user_id or a token and returns the user if they exist.
  • get_exchange_token: Takes target_user which can either be a keycloak username or user id, and returns a token used for impersonating the target_user in requests.
  • decode_jwt: Small helper function which decodes a JWT token using the client connection.

decode_jwt response schema:

{'id': 'ddcbcb65-4515-4e72-8b0e-9e844cb7f06a', 'createdTimestamp': 1695143223350, 'username': 'demoadmin', 'enabled': True, 'totp': False, 'emailVerified': False, 'disableableCredentialTypes': [], 'requiredActions': [], 'notBefore': 0, 'access': {'manageGroupMembership': True, 'view': True, 'mapRoles': True, 'impersonate': True, 'manage': True}}

More may be added in future versions.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

orodha_keycloak-1.2.0.tar.gz (7.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

orodha_keycloak-1.2.0-py3-none-any.whl (8.3 kB view details)

Uploaded Python 3

File details

Details for the file orodha_keycloak-1.2.0.tar.gz.

File metadata

  • Download URL: orodha_keycloak-1.2.0.tar.gz
  • Upload date:
  • Size: 7.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.2 CPython/3.8.10

File hashes

Hashes for orodha_keycloak-1.2.0.tar.gz
Algorithm Hash digest
SHA256 563d9bc0ad1a5e3d27a6fd3c7d9aa983ac9a2766c0889313dd9a354b44fcbe8a
MD5 1ed308c200a6c01eabfd2b59683b6469
BLAKE2b-256 6f67f47d6b1027fdab2758018e952ad0ecea2dbb1e8126a3cebccab8fa0882bf

See more details on using hashes here.

File details

Details for the file orodha_keycloak-1.2.0-py3-none-any.whl.

File metadata

File hashes

Hashes for orodha_keycloak-1.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 c06834e8fe48d9cf88dfcd5fe91af97dff533a7a81f2eb4b36de4f23b479412a
MD5 47e82cd35622e961216ad1e54d11da83
BLAKE2b-256 29d87396da3626833fd2976c65ca9cebf958db4e9414cae0e432a669f0f9bed2

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page