Skip to main content

Keycloak brand/instance authentication for python projects

Project description

sag_py_auth_brand

Maintainability Coverage Status Known Vulnerabilities

This provides a way to secure your fastapi with keycloak jwt bearer authentication. This library bases on sag_py_auth and adds support for instances/brands.

What it does

  • Secure your api endpoints
  • Verifies auth tokens: signature, expiration, issuer, audience
  • Verifies the brand/customer over a token role (+ alias support)
  • Verifies the instance over a token role
  • Verifies the stage over a realm role
  • Allows to set additional permissions by specifying further token roles

How to use

Installation

pip install sag_py_auth_brand

Secure your apis

First create the fast api dependency with the auth config:

from sag_py_auth import TokenRole
from sag_py_auth_brand.models import AuthConfig
from sag_py_auth_brand.brand_jwt_auth import BrandJwtAuth
from fastapi import Depends

auth_config = BrandAuthConfig("https://authserver.com/auth/realms/projectName", "myaudience", "myinstance", "mystage")
required_roles = [TokenRole("clientname", "adminrole")]
requires_admin = Depends(BrandJwtAuth(auth_config, required_roles))

Afterwards you can use it in your route like that:

@app.post("/posts", dependencies=[requires_admin], tags=["posts"])
async def add_post(post: PostSchema) -> dict:

Or if you use sub routes, auth can also be enforced for the entire route like that:

router = APIRouter()
router.include_router(sub_router, tags=["my_api_tag"], prefix="/subroute",dependencies=[requires_admin])

Get brand information

See sag_py_auth to find out how to access the token and user info.

Furthermore you can get the brand by accessing it over the context:

from sag_py_auth_brand.request_brand_context import get_brand as get_brand_from_context
brand = get_brand_from_context()

This works in async calls but not in sub threads (without additional changes).

See:

Log the brand

It is possible to log the brand by adding a filter.

import logging
from sag_py_auth_brand.request_brand_logging_filter import RequestBrandLoggingFilter

console_handler = logging.StreamHandler(sys.stdout)
console_handler.addFilter(RequestBrandLoggingFilter())

The filter provides the field request_brand with the brand.

How a token has to look like

{

    "iss": "https://authserver.com/auth/realms/projectName",
    "aud": ["audienceOne", "audienceTwo"],
    "typ": "Bearer",
    "azp": "public-project-swagger",
    "preferred_username": "preferredUsernameValue",
    .....
    "realm_access": {
        "roles": ["myStage"]
    },
    "resource_access": {
        "role-instance": {
            "roles": ["myInstance"]
        },
        "role-brand": {
            "roles": ["myBrand"]
        },
        "role-endpoint": {
            "roles": ["permissionOne", "permissionTwo"]
        },
        "role-brand-alias": {
            "roles": ["myBrand", "myBrandAliasOne", "myBrandAliasTwo"]
        }
    }
}
  • role-endpoint is just required for permission checks of the api endpoint
  • role-brand-alias is optional for the alias feature. If you don't use aliases it can be left ayway.
  • role-brand-alias must contain exactly one original brand together with one or multiple aliases

How to publish

  • Update the version in setup.py and commit your change
  • Create a tag with the same version number
  • Let github do the rest

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sag-py-auth-brand-0.1.0.tar.gz (8.0 kB view details)

Uploaded Source

Built Distribution

sag_py_auth_brand-0.1.0-py3-none-any.whl (7.0 kB view details)

Uploaded Python 3

File details

Details for the file sag-py-auth-brand-0.1.0.tar.gz.

File metadata

  • Download URL: sag-py-auth-brand-0.1.0.tar.gz
  • Upload date:
  • Size: 8.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.1 CPython/3.11.2

File hashes

Hashes for sag-py-auth-brand-0.1.0.tar.gz
Algorithm Hash digest
SHA256 7e41ae2836f69b21c9ce0aa7e984ff3cb49e3a15abc830c202d954dd2266b519
MD5 ca083987940c574ade3f8835b1790e20
BLAKE2b-256 ca7631cd8d561b1056f46614a794f037d13843d404573b3f1605fabe35c7f682

See more details on using hashes here.

File details

Details for the file sag_py_auth_brand-0.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for sag_py_auth_brand-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 de1021a12c16fb1bb032913fc0dce7ed2814e4cbf158c9575751232b5ff6ae2f
MD5 6d79d4070f133e550a4deebd4b8e4607
BLAKE2b-256 421f8ba059abb129f49b87191bd2d650d6fe8412b75e11199543a8f2c1c38055

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page