Skip to main content

This is a repoze.who plugin for Hawk Access Authentication:

https://npmjs.org/package/hawk

To access resources using Hawk Access Authentication, the client must have obtained a set of Hawk credentials including an id and secret key. They use these credentials to make signed requests to the server.

When accessing a protected resource, the server will generate a 401 challenge response with the scheme “Hawk” as follows:

> GET /protected_resource HTTP/1.1
> Host: example.com

< HTTP/1.1 401 Unauthorized
< WWW-Authenticate: Hawk

The client will use their Hawk credentials to build a request signature and include it in the Authorization header like so:

> GET /protected_resource HTTP/1.1
> Host: example.com
> Authorization: Hawk id="h480djs93hd8",
>                     ts="1336363200",
>                     nonce="dj83hs9s",
>                     mac="bhCQXTVyfj5cmA9uKkPFx1zeOXM="

< HTTP/1.1 200 OK
< Content-Type: text/plain
<
< For your eyes only:  secret data!

This plugin uses the tokenlib library for verifying Hawk credentials:

https://github.com/mozilla-services/tokenlib

If this library does not meet your needs, you can provide a custom callback function to decode the Hawk id token.

0.2.0 - 2013-08-19

  • Allow setting a custom master secret, which is passed through to tokenlib.

0.1.0 - 2013-08-19

  • Initial release.

Release files for repoze.who.plugins.hawkauth 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for repoze.who.plugins.hawkauth 0.2.0
File Size Uploaded
repoze.who.plugins.hawkauth-0.2.0.tar.gz 8.0 kB Details

Release files / repoze.who.plugins.hawkauth-0.2.0.tar.gz

Download URL repoze.who.plugins.hawkauth-0.2.0.tar.gz
Size 8.0 kB
Tags Source
SHA-256 checksum
How to use checksums
2e22aeaed7550c8f7cbbb8a72650a91fd7cbb25d23d8eeb00d1c62e2dc5fc0eb
BLAKE2b-256 checksum
How to use checksums
a344ad9933e5c3a270d5697f5e5a80bf7b422eeb1fa72a8444f69ed05c67f387
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

0.2.0 This release

1 release file

0.1.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page