Best security utils for FastAPI: Argon2, rate limiting, logging
Project description
secure-python-utils
Production-grade security toolkit for FastAPI/Python
A modern, fast, and secure toolkit to help build robust APIs and backends with Python and FastAPI.
Features
- Argon2 password hashing for secure credential storage
- Easy-to-use rate limiting to protect your endpoints
- Structured, configurable logging utilities
Installation
pip install secure-python-utils==0.1.4
Quick Start
# Example of using all core features from secure-python-utils
from fastapi import FastAPI, Request
from secure_python_utils.password_hasher.argon2 import PasswordService
from secure_python_utils.rate_limiter.redis_limiter import RateLimiter
from secure_python_utils.logger import LoggerConfig
# Initialize FastAPI application
app = FastAPI()
# Initialize and configure the rate limiter (replace with your Redis URI)
rate_limiter = RateLimiter("redis://localhost:6379")
rate_limiter.init_app(app)
# Initialize the logger to log messages to a file
logger = LoggerConfig.get_logger("app.log")
@app.post("/register")
@rate_limiter.limit("10/minute") # Limit this endpoint to 10 requests per minute per client
async def register(request: Request, password: str):
# Hash the user's password securely
hashed_password = PasswordService.hash(password)
logger.info("Register endpoint called and password hashed")
# Here you would save hashed_password to your database
return {"message": "User registered", "password_hash": hashed_password}
@app.post("/login")
@rate_limiter.limit("20/minute") # Limit this endpoint to 20 requests per minute per client
async def login(request: Request, password: str, stored_hash: str):
# Verify the provided password against the stored hash
if PasswordService.verify(stored_hash, password):
logger.info("User authentication successful")
return {"message": "Login successful"}
else:
logger.warning("Failed login attempt due to invalid credentials")
return {"message": "Invalid credentials"}, 401
@app.get("/info")
@rate_limiter.limit("30/minute") # Limit this endpoint to 30 requests per minute per client
async def info(request: Request):
logger.info("Info endpoint accessed")
return {"status": "Service is running"}
# Example of manual password hashing and verification outside FastAPI endpoints
if __name__ == "__main__":
# Hash a password (for demonstration)
password = "MySecretPassword!"
hash_value = PasswordService.hash(password)
print(f"Manual hash: {hash_value}")
# Manually verify password
is_ok = PasswordService.verify(hash_value, password)
print(f"Manual verification passed: {is_ok}")
# Manually log an event
logger.info("Manual password hashing and verification completed")
Why secure-python-utils?
- Plug-and-play security features for Python and FastAPI
- Built using industry best practices (Argon2 for hashing, structured logging, robust rate limiting)
- Clean integration; suitable for production environments
Roadmap
- JWT authentication utilities
- Advanced logging handlers and formats
- User account management features
Contributing
Contributions are welcome! Please open issues or submit pull requests for improvements.
License
MIT
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file secure_python_utils-0.1.4.tar.gz.
File metadata
- Download URL: secure_python_utils-0.1.4.tar.gz
- Upload date:
- Size: 6.5 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
26e427fb57d6475a973a0799308167d53a9e9849482648d3c004ca98666a03b5
|
|
| MD5 |
15211cee0aecf80de4968c4a9429836e
|
|
| BLAKE2b-256 |
17162dfee73ae2909a54475e839a0f9c9f9b1a7059dffb391b91c706a1c6a9ac
|
File details
Details for the file secure_python_utils-0.1.4-py3-none-any.whl.
File metadata
- Download URL: secure_python_utils-0.1.4-py3-none-any.whl
- Upload date:
- Size: 7.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
686ad411ee9c3b59844e7ab27a39f92b965bdd8f01512dc8c49b1876facf7586
|
|
| MD5 |
8bd3eb6aecd67bb7dbb401d0941fc6e1
|
|
| BLAKE2b-256 |
69e3f9eed9e8b59ecdd6b4e9554d6bc0811fec72c065c0475b142c5862d10571
|