repoze.who.plugins.macauth
Project description
This is a repoze.who plugin for MAC Access Authentication:
To access resources using MAC Access Authentication, the client must have obtained a set of MAC credentials including an id and secret key. They use these credentials to make signed requests to the server.
When accessing a protected resource, the server will generate a 401 challenge response with the scheme “MAC” as follows:
> GET /protected_resource HTTP/1.1 > Host: example.com < HTTP/1.1 401 Unauthorized < WWW-Authenticate: MAC
The client will use their MAC credentials to build a request signature and include it in the Authorization header like so:
> GET /protected_resource HTTP/1.1 > Host: example.com > Authorization: MAC id="h480djs93hd8", > ts="1336363200", > nonce="dj83hs9s", > mac="bhCQXTVyfj5cmA9uKkPFx1zeOXM=" < HTTP/1.1 200 OK < Content-Type: text/plain < < For your eyes only: secret data!
This plugin uses the tokenlib library for verifying MAC credentials:
If this library does not meet your needs, you can provide a custom callback function to decode the MAC id token.
0.1.0 - 2012-02-27
Initial release.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Hashes for repoze.who.plugins.macauth-0.1.0.tar.gz
Algorithm | Hash digest | |
---|---|---|
SHA256 | 1e284b4dbd2f1b5553c96875836d2b68fc9fd0ad7af7b6b6efdfea4725754a8a |
|
MD5 | 3cced02daa83625ae5aeebe473832ad1 |
|
BLAKE2b-256 | e390b2bd160def9c598c0d139b97ea632fe5256f4201570a6cd3532600b7b5eb |