Skip to main content

Pebble client tool for authenticate user and licence management written in Python

Project description

Introduction

This library offer a client for authenticate user and licence management written in Python compatible with may python API Server.

Installation

Requirements

The following procedures explains the installation of the following packages :

  • Python 3.9 or higher

  • pip (provided with Python package)

  • PyJWT (tested with version 2.8.0)

  • cryptography (tested with version 41.0.5)

Solution 1 : requirement.txt configuration

If your project use a requirement.txt configuration file, simply add the following.

requirement.txt file addition:

pebbleauthclient>=0.2.0

Then run this command on your project :

pip install -r requirements.txt

Or in Dockerfile :

RUN pip install -r requirements.txt

Solution 2 : Local installation

Check python3 is properly installed on your local machine (with pip working), then run the following in the application directory.

pip install pebbleauthclient

Or in Dockerfile :

RUN pip install pebbleauthclient

Usage

Configuration

Before you can work with the library, you must define a system environment variable with the URI of the public Json Web Key Set (remote JWKS file).

This file will be requested and store temporary on your API Server. Your server should be able to write on ./var/credentials/auth/jwks.json . If the file does not exist, it will be created.

If you start your server directly from a terminal, run this command on your terminal before starting your server :

export PBL_JWKS_REMOTE_URI=https://SERVER_URI/path/jwks.json

If you start your server within a Docker container, you should add this line to your Dockefile :

ENV PBL_JWKS_REMOTE_URI=https://SERVER_URI/path/jwks.json

Other configurations

You can add more configuration by defining some more environment variables on your system. These configurations have values by default that works for most of the cases.

Environment variable

Default

Description

PBL_JWKS_REMOTE_URI

Unset

MANDATORY URI of the remote jwks.json file. This file contains all active public keys to decode token.

PBL_CERTS_FOLDER

./var/credentials/auth

Local folder for temporary store authentication credentials. Storing locally the credentials improves server response.

PBL_JWKS_EXP_TIME

86400

Duration in seconds after which Keys Set (JWKS) is considered as expired. All local copy of the keys must be destroyed and the remote server will be requested to create the new copy.

Test keys pair

JWKS URI (for PBL_JWKS_REMOTE_URI environment variable)

https://storage.googleapis.com/pebble-public-cdn/test_auth/jwks_test.json

Public and private keys used to sign a token

https://storage.googleapis.com/pebble-public-cdn/test_auth/public_test.pem

https://storage.googleapis.com/pebble-public-cdn/test_auth/private_test.pem

Authenticate with token string

from pebbleauthclient.auth import auth

try:
    authToken = auth("---A_valid_token---")

    print(authToken)
    print(authToken.get_user())
    print(authToken.get_authenticated_licence())
except Exception as e:
    print("ERROR: " + e)

Authenticate with HTTP Authorization header

from http.server import HTTPServer, BaseHTTPRequestHandler
from pebbleauthclient.auth import auth_from_http_headers


class HandleRequest(BaseHTTPRequestHandler):

    def do_GET(self):
        try:
            auth_token = auth_from_http_headers(self.headers)
            licence = auth_token.get_authenticated_licence()
            user = auth_token.get_user()

            print(licence)
            print(user)

            self.send_response(200)
            self.send_header('Content-Type', 'text/plain')
            self.end_headers()

            self.wfile.write(bytes("Welcome " + user.username, 'utf-8'))

        except Exception:
            self.send_response(401)
            self.end_headers()


server = HTTPServer(('', 8084), HandleRequest)
print("Server is waiting...")
server.serve_forever()
server.server_close()

Check the audience

Audience identifies the recipients that the token is intended for. Each resource server MUST be identified by its audience name and the authorization process MUST check that this audience exists in the token.

To check the audience, add an options dictionary to the auth() or auth_from_http_headers() functions.

# Check that the provided token has a valid audience for api.pebble.solutions/v5/my-resource
auth_token = auth("----my.valid.token----", options={
    'audience': "api.pebble.solutions/v5/my-resource"
})

# Check that token communicate through authorization header has a valid audience
# for api.pebble.solutions/v5/my-resource
auth_token = auth_from_http_headers(headers, options={
    'audience': "api.pebble.solutions/v5/my-resource"
})

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pebbleauthclient-0.2.2.tar.gz (12.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pebbleauthclient-0.2.2-py3-none-any.whl (13.0 kB view details)

Uploaded Python 3

File details

Details for the file pebbleauthclient-0.2.2.tar.gz.

File metadata

  • Download URL: pebbleauthclient-0.2.2.tar.gz
  • Upload date:
  • Size: 12.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.2 CPython/3.9.6

File hashes

Hashes for pebbleauthclient-0.2.2.tar.gz
Algorithm Hash digest
SHA256 e9a14b6effa1cfd238d6bbfa7d2365062d4dcc90afe8577fbe2d94c344f90c2a
MD5 3a07bb51b336bd4ce170fc026f8b9624
BLAKE2b-256 d8c6aea813710bdafe9e215c07a818d648cb6dddacc51f03d9b3bbeec8ffe8e7

See more details on using hashes here.

File details

Details for the file pebbleauthclient-0.2.2-py3-none-any.whl.

File metadata

File hashes

Hashes for pebbleauthclient-0.2.2-py3-none-any.whl
Algorithm Hash digest
SHA256 cfcaa41ceb86fd24b24ae9dfa1ce493f40c8abf3f1854a54ccdacf68614001fb
MD5 8f88035d6c8ae0e9c020ad62aa0b3d68
BLAKE2b-256 e24b1e48fc8e1da44bfaff328b1fd26738ee87a22c6da35ad81a90fcef9919a2

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page