Skip to main content

Keycloak authentication for python projects

Project description

sag_py_auth

Maintainability Coverage Status Known Vulnerabilities

This provides a way to secure your fastapi with keycloak jwt bearer authentication.

What it does

  • Secure your api endpoints
  • Verifies auth tokens: signature, expiration, issuer, audience
  • Allows to set permissions by specifying roles and realm roles

How to use

Installation

pip install sag_py_auth

Secure your apis

First create the fast api dependency with the auth config:

from sag_py_auth import AuthConfig, JwtAuth, TokenRole
from fastapi import Depends

auth_config = AuthConfig("https://authserver.com/auth/realms/projectName", "myaudience")
required_roles = [TokenRole("clientname", "adminrole")]
required_realm_roles = ["additionalrealmrole"]
requires_admin = Depends(JwtAuth(auth_config, required_roles, required_realm_roles))

Afterwards you can use it in your route like that:

@app.post("/posts", dependencies=[requires_admin], tags=["posts"])
async def add_post(post: PostSchema) -> dict:

Or if you use sub routes, auth can also be enforced for the entire route like that:

router = APIRouter()
router.include_router(sub_router, tags=["my_api_tag"], prefix="/subroute",dependencies=[requires_admin])

Get user information

The Jwt call directly returns a token object that can be used to get additional information.

Furthermore you can access the context directly:

from sag_py_auth import get_token as get_token_from_context
token = get_token_from_context()

This works in async calls but not in sub threads (without additional changes).

See:

Methods available on the token object

  • get_field_value: to get the value of a claim field (or an empty string if not present)
  • get_roles: Gets the roles of a specific client
  • has_role: Verify if a spcific client has a role
  • get_realm_roles: Get the realm roles
  • has_realm_role: Check if the user has a specific realm role

Log user data

It is possible to log the preferred_username and the azp value (party that created the token) of the token by adding a filter.

import logging
from sag_py_auth import UserNameLoggingFilter

console_handler = logging.StreamHandler(sys.stdout)
console_handler.addFilter(UserNameLoggingFilter())

The filter provides the following two fields as soon as the user is authenticated: user_name, authorized_party

How to publish

  • Update the version in setup.py and commit your change
  • Create a tag with the same version number
  • Let github do the rest

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sag-py-auth-0.1.3.tar.gz (11.8 kB view details)

Uploaded Source

Built Distribution

sag_py_auth-0.1.3-py3-none-any.whl (8.7 kB view details)

Uploaded Python 3

File details

Details for the file sag-py-auth-0.1.3.tar.gz.

File metadata

  • Download URL: sag-py-auth-0.1.3.tar.gz
  • Upload date:
  • Size: 11.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.1 CPython/3.11.2

File hashes

Hashes for sag-py-auth-0.1.3.tar.gz
Algorithm Hash digest
SHA256 7d695f799a9a255f58a7fe1c3134aa56faa54dec3e73b44ed11df71674f9c302
MD5 b4e7573113d9c7a3447dcf79bcaa88af
BLAKE2b-256 13ccb3824aca41bb95a97a3659807ef1a9cd1eefe6b47106fdbe8e7682a012de

See more details on using hashes here.

File details

Details for the file sag_py_auth-0.1.3-py3-none-any.whl.

File metadata

  • Download URL: sag_py_auth-0.1.3-py3-none-any.whl
  • Upload date:
  • Size: 8.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.1 CPython/3.11.2

File hashes

Hashes for sag_py_auth-0.1.3-py3-none-any.whl
Algorithm Hash digest
SHA256 97732dffa80454f72668ab31d5b1cce88a74ad5233a3a7cd7c9465a3d26386ba
MD5 c1dc3b563f9a569d9f35c81ed726f48d
BLAKE2b-256 7e0b8f13bd6bd6e001a78826b219b0ae7db36550bf09d6a959c5f5344589f9ff

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page