Keycloak brand/instance authentication for python projects
Project description
sag_py_auth_brand
This provides a way to secure your fastapi with keycloak jwt bearer authentication. This library bases on sag_py_auth and adds support for instances/brands.
What it does
- Secure your api endpoints
- Verifies auth tokens: signature, expiration, issuer, audience
- Verifies the brand/customer over a token role (+ alias support)
- Verifies the instance over a token role
- Verifies the stage over a realm role
- Allows to set additional permissions by specifying further token roles
How to use
Installation
pip install sag-py-auth-brand
Secure your apis
First create the fast api dependency with the auth config:
from sag_py_auth import TokenRole
from sag_py_auth_brand.models import AuthConfig
from sag_py_auth_brand.brand_jwt_auth import BrandJwtAuth
from fastapi import Depends
auth_config = BrandAuthConfig("https://authserver.com/auth/realms/projectName", "myaudience", "myinstance", "mystage")
required_roles = [TokenRole("clientname", "adminrole")]
requires_admin = Depends(BrandJwtAuth(auth_config, required_roles))
Afterwards you can use it in your route like that:
@app.post("/posts", dependencies=[requires_admin], tags=["posts"])
async def add_post(post: PostSchema) -> dict:
Or if you use sub routes, auth can also be enforced for the entire route like that:
router = APIRouter()
router.include_router(sub_router, tags=["my_api_tag"], prefix="/subroute",dependencies=[requires_admin])
Get brand information
See sag_py_auth to find out how to access the token and user info.
Furthermore you can get the brand by accessing it over the context:
from sag_py_auth_brand.request_brand_context import get_brand as get_brand_from_context
brand = get_brand_from_context()
This works in async calls but not in sub threads (without additional changes).
See:
- https://docs.python.org/3/library/contextvars.html
- https://kobybass.medium.com/python-contextvars-and-multithreading-faa33dbe953d
Log the brand
It is possible to log the brand by adding a filter.
import logging
from sag_py_auth_brand.request_brand_logging_filter import RequestBrandLoggingFilter
console_handler = logging.StreamHandler(sys.stdout)
console_handler.addFilter(RequestBrandLoggingFilter())
The filter provides the field request_brand with the brand.
How a token has to look like
{
"iss": "https://authserver.com/auth/realms/projectName",
"aud": ["audienceOne", "audienceTwo"],
"typ": "Bearer",
"azp": "public-project-swagger",
"preferred_username": "preferredUsernameValue",
.....
"realm_access": {
"roles": ["myStage"]
},
"resource_access": {
"role-instance": {
"roles": ["myInstance"]
},
"role-brand": {
"roles": ["myBrand"]
},
"role-endpoint": {
"roles": ["permissionOne", "permissionTwo"]
},
"role-brand-alias": {
"roles": ["myBrand", "myBrandAliasOne", "myBrandAliasTwo"]
}
}
}
- role-endpoint is just required for permission checks of the api endpoint
- role-brand-alias is optional for the alias feature. If you don't use aliases it can be left ayway.
- role-brand-alias must contain exactly one original brand together with one or multiple aliases
How to publish
- Update the version in setup.py and commit your change
- Create a tag with the same version number
- Let github do the rest
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file sag-py-auth-brand-0.2.0.tar.gz
.
File metadata
- Download URL: sag-py-auth-brand-0.2.0.tar.gz
- Upload date:
- Size: 8.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.1 CPython/3.11.3
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 99c84fb162bbc113bd97ebf4d8d86fe70d0d8b84af90a0ea7d1abfd4a176695d |
|
MD5 | ad24ceafea14fb274dd0424a4be31379 |
|
BLAKE2b-256 | 0281faa5edd23ab3c144a18a9d90dc3cfcd8ec6a58d48dd080a52002ceb9a30b |
File details
Details for the file sag_py_auth_brand-0.2.0-py3-none-any.whl
.
File metadata
- Download URL: sag_py_auth_brand-0.2.0-py3-none-any.whl
- Upload date:
- Size: 7.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.1 CPython/3.11.3
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 4633360d8bfaf62b0c72962f8cc6e75015bafb98e7e65c637c78ee88f8b312e7 |
|
MD5 | 5c61ef3ec473f469390cc6a4ca38df95 |
|
BLAKE2b-256 | a61ac2db38910445abd3dd1eb45957b8293cfc85dd059f9a0ef7bc4bbadbaf39 |