Skip to main content

httpsig

https://travis-ci.org/ahknight/httpsig.svg?branch=master https://travis-ci.org/ahknight/httpsig.svg?branch=develop

Sign HTTP requests with secure signatures according to the IETF HTTP Signatures specification (Draft 15). This is a fork of module to fully support both RSA and HMAC schemes as well as unit test both schemes to prove they work. It was updated from draft 12 to 15 for the sole purpose of being used with the federation project in supporting http signatures used by most Activitypub platforms. Note that the implementation may not be fully compliant with Draft 15.

See the original project, original Python module, original spec, and current IETF draft for more details on the signing scheme.

Requirements

Optional:

For testing:

  • tox

  • pyenv (optional, handy way to access multiple versions)

    $ for VERS in 2.7.15 3.4.9 3.5.6 3.6.7 3.7.1; do pyenv install -s $VERS; done

Usage

Real documentation is forthcoming, but for now this should get you started.

For simple raw signing:

import httpsig

secret = open('rsa_private.pem', 'rb').read()

sig_maker = httpsig.Signer(secret=secret, algorithm='hs2019', sign_algorithm=httpsig.PSS())
sig_maker.sign('hello world!')

For general use with web frameworks:

import httpsig

key_id = "Some Key ID"
secret = open('rsa_private.pem', 'rb').read()

hs = httpsig.HeaderSigner(key_id, secret, algorithm="hs2019", sign_algorithm=httpsig.PSS(), headers=['(request-target)', 'host', 'date'])
signed_headers_dict = hs.sign({"Date": "Tue, 01 Jan 2014 01:01:01 GMT", "Host": "example.com"}, method="GET", path="/api/1/object/1")

For use with requests:

import json
import requests
from httpsig.requests_auth import HTTPSignatureAuth

secret = open('rsa_private.pem', 'rb').read()

auth = HTTPSignatureAuth(key_id='Test', secret=secret, sign_algorithm=httpsig.PSS())
z = requests.get('https://api.example.com/path/to/endpoint',
                         auth=auth, headers={'X-Api-Version': '~6.5', 'Date': 'Tue, 01 Jan 2014 01:01:01 GMT')

Class initialization parameters

Note that keys and secrets should be bytes objects. At attempt will be made to convert them, but if that fails then exceptions will be thrown.

httpsig.Signer(secret, algorithm='hs2019', sign_algorithm=httpsig.PSS())

secret, in the case of an RSA signature, is a string containing private RSA pem. In the case of HMAC, it is a secret password. algorithm should be set to ‘hs2019’ the other six signatures are now deprecated: rsa-sha1, rsa-sha256, rsa-sha512, hmac-sha1, hmac-sha256, hmac-sha512. sign_algorithm The digital signature algorithm derived from keyId. Currently supported algorithms: httpsig.PSS

httpsig.requests_auth.HTTPSignatureAuth(key_id, secret, algorithm='hs2019', sign_algorithm=httpsig.PSS(), headers=None)

key_id is the label by which the server system knows your secret. headers is the list of HTTP headers that are concatenated and used as signing objects. By default it is the specification’s minimum, the Date HTTP header. secret and algorithm are as above. sign_algorithm The digital signature algorithm derived from keyId. Currently supported algorithms: httpsig.PSS

Tests

To run tests:

python setup.py test

or:

tox

Known Limitations

  1. Multiple values for the same header are not supported. New headers with the same name will overwrite the previous header. It might be possible to replace the CaseInsensitiveDict with the collection that the email package uses for headers to overcome this limitation.

  2. Keyfiles with passwords are not supported. There has been zero vocal demand for this so if you would like it, a PR would be a good way to get it in.

  3. Draft 2 added support for ecdsa-sha256. This is available in PyCryptodome but has not been added to httpsig. PRs welcome.

License

Both this module and the original module are licensed under the MIT license.

httpsig Changes

1.6.0 (2023-Feb-8)

  • Added support for the created and expires headers

1.3.0 (2019-Nov-28)

  • Relax pycryptodome requirements (PR#14 by cveilleux)

  • Ability to supply another signature header like Signature (PR#15 by rbignon)

  • Fixed #2; made Signer.sign() public

  • Dropped Python 3.3, added Python 3.7.

1.2.0 (2018-Mar-28)

  • Switched to pycryptodome instead of PyCrypto (PR#11 by iandouglas)

  • Updated tests with the test data from Draft 8 and verified it still passes.

  • Dropped official Python 3.2 support (pip dropped it so it can’t be properly tested)

  • Cleaned up the code to be more PEP8-like.

1.1.2 (2015-Feb-11)

  • HMAC verification is now constant-time.

1.1.1 (2015-Feb-11)

  • (pulled)

1.1.0 (2014-Jul-24)

  • Changed “(request-line)” to “(request-target)” to comply with Draft 3.

1.0.3 (2014-Jul-09)

  • Unified the default signing algo under one setting. Setting httpsig.sign.DEFAULT_SIGN_ALGORITHM changes it for all future instances.

  • Handle invalid params a little better.

1.0.2 (2014-Jul-02)

  • Ensure we treat headers as ASCII strings.

  • Handle a case in the authorization header where there’s garbage (non-keypairs) after the method name.

1.0.1 (2014-Jul-02)

  • Python 3 support (2.7 + 3.2-3.4)

  • Updated tox and Travis CI configs to test the supported Python versions.

  • Updated README.

1.0.0 (2014-Jul-01)

  • Written against http://tools.ietf.org/html/draft-cavage-http-signatures-02

  • Added “setup.py test” and tox support.

  • Added sign/verify unit tests for all currently-supported algorithms.

  • HeaderSigner and HeaderVerifier now share the same message-building logic.

  • The HTTP method in the message is now properly lower-case.

  • Resolved unit test failures.

  • Updated Verifier and HeaderVerifier to handle verifying both RSA and HMAC sigs.

  • Updated versioneer.

  • Updated contact/author info.

  • Removed stray keypair in test dir.

  • Removed SSH agent support.

  • Removed suport for reading keyfiles from disk as this is a huge security hole if this is used in a server framework like drf-httpsig.

1.0b1 (2014-Jun-23)

  • Removed HTTP version from request-line, per spec (breaks backwards compatability).

  • Removed auto-generation of missing Date header (ensures client compatability).

http-signature (previous)

0.2.0 (unreleased)

  • Update to newer spec (incompatible with prior version).

  • Handle request-line meta-header.

  • Allow secret to be a PEM encoded string.

  • Add test cases from spec.

0.1.4 (2012-10-03)

  • Account for ssh now being re-merged into paramiko: either package is acceptable (but paramiko should ideally be >= 1.8.0)

0.1.3 (2012-10-02)

  • Stop enabling allow_agent by default

  • Stop requiring ssh package by default – it is imported only when allow_agent=True

  • Changed logic around ssh-agent: if one key is available, don’t bother with any other authentication method

  • Changed logic around key file usage: if decryption fails, prompt for password

  • Bug fix: ssh-agent resulted in a nonsensical error if it found no correct keys (thanks, petervolpe)

  • Introduce versioneer.py

Metadata

Release files for python-httpsig-socialhome 1.6.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for python-httpsig-socialhome 1.6.0
File Size Uploaded
python-httpsig-socialhome-1.6.0.tar.gz 23.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for python-httpsig-socialhome 1.6.0
File Interpreter ABI Platform
python_httpsig_socialhome-1.6.0-py2.py3-none-any.whl Python 3, Python 2 none any Details

Total release size: 47.0 kB

Release files / python-httpsig-socialhome-1.6.0.tar.gz

Download URL python-httpsig-socialhome-1.6.0.tar.gz
Size 23.5 kB
Tags Source
SHA-256 checksum
How to use checksums
3e1db35a061627d45c47dae80e8378bd98fb105b16dcc129e423ee0d35601903
BLAKE2b-256 checksum
How to use checksums
f04635a96cb4a6aa314720bb289b8a7c24662ed35870ca309b6d39006318d676
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.10.4

Release files / python_httpsig_socialhome-1.6.0-py2.py3-none-any.whl

Download URL python_httpsig_socialhome-1.6.0-py2.py3-none-any.whl
Size 23.5 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
7bc7c6a352373e39ef62f9d258e42e69a52aad9e3fe2cfd8d9424eacad64a467
BLAKE2b-256 checksum
How to use checksums
5a2279a69f49acc565c2a84e3af052540e16fd0e1bb75364105a45b0473d871a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.10.4

Release history Release notifications | RSS feed

This release

1.6.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page