Skip to main content

Best security utils for FastAPI: Argon2, rate limiting, logging

Project description

secure-python-utils

Production-grade security toolkit for FastAPI/Python
A modern, fast, and secure toolkit to help build robust APIs and backends with Python and FastAPI.

Features

  • Argon2 password hashing for secure credential storage
  • Easy-to-use rate limiting to protect your endpoints
  • Structured, configurable logging utilities

Installation

pip install secure-python-utils

Quick Start

# Example of using all core features from secure-python-utils

from fastapi import FastAPI, Request
from secure_python_utils.password_hasher.argon2 import PasswordService
from secure_python_utils.rate_limiter.redis_limiter import RateLimiter
from secure_python_utils.logger import LoggerConfig

# Initialize FastAPI application
app = FastAPI()

# Initialize and configure the rate limiter (replace with your Redis URI)
rate_limiter = RateLimiter("redis://localhost:6379")
rate_limiter.init_app(app)

# Initialize the logger to log messages to a file
logger = LoggerConfig.get_logger("app.log")

@app.post("/register")
@rate_limiter.limit("10/minute")  # Limit this endpoint to 10 requests per minute per client
async def register(request: Request, password: str):
    # Hash the user's password securely
    hashed_password = PasswordService.hash(password)
    logger.info("Register endpoint called and password hashed")
    # Here you would save hashed_password to your database
    return {"message": "User registered", "password_hash": hashed_password}

@app.post("/login")
@rate_limiter.limit("20/minute")  # Limit this endpoint to 20 requests per minute per client
async def login(request: Request, password: str, stored_hash: str):
    # Verify the provided password against the stored hash
    if PasswordService.verify(stored_hash, password):
        logger.info("User authentication successful")
        return {"message": "Login successful"}
    else:
        logger.warning("Failed login attempt due to invalid credentials")
        return {"message": "Invalid credentials"}, 401

@app.get("/info")
@rate_limiter.limit("30/minute")  # Limit this endpoint to 30 requests per minute per client
async def info(request: Request):
    logger.info("Info endpoint accessed")
    return {"status": "Service is running"}

# Example of manual password hashing and verification outside FastAPI endpoints
if __name__ == "__main__":
    # Hash a password (for demonstration)
    password = "MySecretPassword!"
    hash_value = PasswordService.hash(password)
    print(f"Manual hash: {hash_value}")

    # Manually verify password
    is_ok = PasswordService.verify(hash_value, password)
    print(f"Manual verification passed: {is_ok}")

    # Manually log an event
    logger.info("Manual password hashing and verification completed")

Why secure-python-utils?

  • Plug-and-play security features for Python and FastAPI
  • Built using industry best practices (Argon2 for hashing, structured logging, robust rate limiting)
  • Clean integration; suitable for production environments

Roadmap

  • JWT authentication utilities
  • Advanced logging handlers and formats
  • User account management features

Contributing

Contributions are welcome! Please open issues or submit pull requests for improvements.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

secure_python_utils-0.1.1.tar.gz (6.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

secure_python_utils-0.1.1-py3-none-any.whl (7.1 kB view details)

Uploaded Python 3

File details

Details for the file secure_python_utils-0.1.1.tar.gz.

File metadata

  • Download URL: secure_python_utils-0.1.1.tar.gz
  • Upload date:
  • Size: 6.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.7

File hashes

Hashes for secure_python_utils-0.1.1.tar.gz
Algorithm Hash digest
SHA256 585f9ac8620e445b9140c6dde0235b273d24841f60385138a3f0bf1d701299f4
MD5 45df2251868816fa4168f3dea6fb7e03
BLAKE2b-256 37d3d3202c214dcd60265ba7ba887e0e1c441d5bc90ab77b8df23ab11f8906f9

See more details on using hashes here.

File details

Details for the file secure_python_utils-0.1.1-py3-none-any.whl.

File metadata

File hashes

Hashes for secure_python_utils-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 0675072d8cf2eabbb7977a07ef3efba7bc342e7ad786ff8eaf91c0a23a3476e7
MD5 3c090b0256144ea68e94c1ad96733f86
BLAKE2b-256 57c51c290817988d942c52bb035641cb60e4be705096bcbc3ea62149f97b1d51

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page