Skip to main content

sanic-authz

build Coverage Status Version PyPI - Wheel Pyversions Download Discord

sanic-authz is an authorization middleware for Sanic. It is based on PyCasbin.

Installation

pip install sanic-authz

Module Usage:

import casbin
from sanic import Sanic, response
from sanic.request import Request
from sanic_authz.middleware import CasbinAuthMiddleware

app = Sanic("SanicAuthzExample")
enforcer = casbin.Enforcer("rbac_model.conf", "policy.csv")

# Registration middleware
CasbinAuthMiddleware(sanic_app, enforcer)

# CasbinAuthMiddleware is a global middleware.
# The authorization check will be performed automatically on each request.
# You don't need to manually invoke the middleware in your route handlers.
@app.route("/")
async def homepage(request):
    return response.text("Hello, world!")

Custom subject_getter:

By default, the middleware extracts user identity from the X-User header field. Client requests need to include the X-User header:

curl -H "X-User: alice" http://localhost:8000/data

You can customize the subject_getter to adapt to different authentication mechanisms. For example, JWT authentication:

def jwt_subject_getter(request: Request) -> str:
    token = request.headers.get("Authorization", "").replace("Bearer ", "")
    payload = decode_jwt(token)
    return payload.get("user_id", "anonymous")

CasbinAuthMiddleware(app, enforcer, subject_getter=jwt_subject_getter)

session authentication:

def session_subject_getter(request: Request) -> str:
    return request.ctx.session.get("user_id", "anonymous")

CasbinAuthMiddleware(app, enforcer, subject_getter=session_subject_getter)

Documentation

The authorization determines a request based on {subject, object, action}, which means what subject can perform what action on what object. In this plugin, the meanings are:

  1. subject: the logged-in user name
  2. object: the URL path for the web resource like "dataset1/item1"
  3. action: HTTP method like GET, POST, PUT, DELETE, or the high-level actions you defined like "read-file", "write-blog"

For how to write authorization policy and other details, please refer to the PyCasbin's documentation.

Getting Help

License

This project is licensed under the Apache 2.0 license.

Metadata

Release files for sanic-authz 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sanic-authz 1.0.0
File Size Uploaded
sanic_authz-1.0.0.tar.gz 368.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sanic-authz 1.0.0
File Interpreter ABI Platform
sanic_authz-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 769.5 kB

Release files / sanic_authz-1.0.0.tar.gz

Download URL sanic_authz-1.0.0.tar.gz
Size 368.1 kB
Tags Source
SHA-256 checksum
How to use checksums
d4360c8294618198669c5a448b183a13efe8f8a928d32a3be74bbd288b5915f2
BLAKE2b-256 checksum
How to use checksums
97135e2763c90ab2e361da4b3d605cf1d59073eb3b27ece42c91e61360b36de2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.11

Release files / sanic_authz-1.0.0-py3-none-any.whl

Download URL sanic_authz-1.0.0-py3-none-any.whl
Size 401.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1834e62133182d748d559cf2c76f57dc7bcbdceaab31bdbaabc5bfa65cce3b8c
BLAKE2b-256 checksum
How to use checksums
e9dd3520a5ae4d895ce5fedd858050a2e5aca434540c3bba6f6e916adb21b1f7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.11

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page