Pebble client tool for authenticate user and licence management written in Python
Project description
Introduction
This library offer a client for authenticate user and licence management written in Python compatible with may python API Server.
Installation
Requirements
The following procedures explains the installation of the following packages :
Python 3.9 or higher
pip (provided with Python package)
PyJWT (tested with version 2.8.0)
cryptography (tested with version 41.0.5)
Solution 1 : requirement.txt configuration
If your project use a requirement.txt configuration file, simply add the following.
requirement.txt file addition:
pebbleauthclient>=0.2.0
Then run this command on your project :
pip install -r requirements.txt
Or in Dockerfile :
RUN pip install -r requirements.txt
Solution 2 : Local installation
Check python3 is properly installed on your local machine (with pip working), then run the following in the application directory.
pip install pebbleauthclient
Or in Dockerfile :
RUN pip install pebbleauthclient
Usage
Configuration
Before you can work with the library, you must define a system environment variable with the URI of the public Json Web Key Set (remote JWKS file).
This file will be requested and store temporary on your API Server. Your server should be able to write on ./var/credentials/auth/jwks.json . If the file does not exist, it will be created.
If you start your server directly from a terminal, run this command on your terminal before starting your server :
export PBL_JWKS_REMOTE_URI=https://SERVER_URI/path/jwks.json
If you start your server within a Docker container, you should add this line to your Dockefile :
ENV PBL_JWKS_REMOTE_URI=https://SERVER_URI/path/jwks.json
Other configurations
You can add more configuration by defining some more environment variables on your system. These configurations have values by default that works for most of the cases.
Environment variable |
Default |
Description |
|---|---|---|
PBL_JWKS_REMOTE_URI |
Unset |
MANDATORY URI of the remote jwks.json file. This file contains all active public keys to decode token. |
PBL_CERTS_FOLDER |
./var/credentials/auth |
Local folder for temporary store authentication credentials. Storing locally the credentials improves server response. |
PBL_JWKS_EXP_TIME |
86400 |
Duration in seconds after which Keys Set (JWKS) is considered as expired. All local copy of the keys must be destroyed and the remote server will be requested to create the new copy. |
Test keys pair
JWKS URI (for PBL_JWKS_REMOTE_URI environment variable)
https://storage.googleapis.com/pebble-public-cdn/test_auth/jwks_test.json
Public and private keys used to sign a token
https://storage.googleapis.com/pebble-public-cdn/test_auth/public_test.pem
https://storage.googleapis.com/pebble-public-cdn/test_auth/private_test.pem
Authenticate with token string
from pebbleauthclient.auth import auth
try:
authToken = auth("---A_valid_token---")
print(authToken)
print(authToken.get_user())
print(authToken.get_authenticated_licence())
except Exception as e:
print("ERROR: " + e)
Check the audience
Audience identifies the recipients that the token is intended for. Each resource server MUST be identified by its audience name and the authorization process MUST check that this audience exists in the token.
To check the audience, add an options dictionary to the auth() or auth_from_http_headers() functions.
# Check that the provided token has a valid audience for api.pebble.solutions/v5/my-resource
auth_token = auth("----my.valid.token----", options={
'audience': "api.pebble.solutions/v5/my-resource"
})
# Check that token communicate through authorization header has a valid audience
# for api.pebble.solutions/v5/my-resource
auth_token = auth_from_http_headers(headers, options={
'audience': "api.pebble.solutions/v5/my-resource"
})
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file pebbleauthclient-0.2.1.tar.gz.
File metadata
- Download URL: pebbleauthclient-0.2.1.tar.gz
- Upload date:
- Size: 12.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.2 CPython/3.9.6
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9eab25aefc842230818e863fe0a25f90b07d11aa279b9726a11d8849dc0dc377
|
|
| MD5 |
d03e6c0443fe7406e756ced6aa96a95d
|
|
| BLAKE2b-256 |
30bb82827f471e0fc4c475b4b6cfad5a4f8770016ea91e8f662f69605dd3caf5
|
File details
Details for the file pebbleauthclient-0.2.1-py3-none-any.whl.
File metadata
- Download URL: pebbleauthclient-0.2.1-py3-none-any.whl
- Upload date:
- Size: 13.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.2 CPython/3.9.6
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
f2e9f66f0b155a711ffae5c8d13e42887343abb792fcea75a0fd87f418100cdb
|
|
| MD5 |
66eedfc39c3c919252575e0c14b6d33d
|
|
| BLAKE2b-256 |
94448a7f077e1986089faaa6b1bb8a219107ace322e913c89377dbfc156cf458
|