Skip to main content

simple_module_users

Email+password user management for simple_module apps. Replaces Keycloak/Auth0 for the common case: local accounts, admin invites, password reset, optional public signup. Built on fastapi-users.

Install

pip install simple_module_users

Pre-wired into any app scaffolded with smpy new.

What it provides

  • Email + password registration, login, logout, password reset.
  • Admin invite flow — admin enters an email, recipient clicks a link, sets a password, is logged in.
  • Public signup toggle (SM_USERS_ALLOW_SIGNUP, default false).
  • Bootstrap admin via env vars (SM_USERS_BOOTSTRAP_EMAIL + SM_USERS_BOOTSTRAP_PASSWORD) — idempotent, only creates if the users table is empty.
  • smpy users create-admin CLI for ad-hoc admin creation.
  • Inertia pages for login/register/invite-accept/admin-invite.
  • Console mailer (logs to stdout) or SMTP mailer (SM_USERS_MAILER=smtp).

Usage

CLI:

uv run smpy users create-admin --email admin@example.com --password 'change-me'

Bootstrap-on-boot (.env):

SM_USERS_BOOTSTRAP_EMAIL=admin@example.com
SM_USERS_BOOTSTRAP_PASSWORD=change-me

Program:

from auth.deps import CurrentUser  # type: ignore[import-not-found]


@router.get("/profile")
async def profile(user: CurrentUser):
    return {"email": user.email}

Depends on

  • simple_module_core, simple_module_db, simple_module_hosting, simple_module_settings, simple_module_auth
  • fastapi-users[sqlalchemy,oauth]>=15,<16, aiosmtplib, cachetools, typer

Social sign-in (Google, GitHub, Microsoft, OIDC)

OAuth providers are configured in the admin UI at /settings/modules → Users (no environment variables). Each provider activates once its client id and secret are set; the secret is masked in the UI. Changes apply live — no restart.

Microsoft (Entra ID). Register an app in the Entra admin center and set the redirect URI to <base-url>/api/users/auth/microsoft/callback. Configure under the Microsoft OAuth group:

  • oauth_microsoft_client_id, oauth_microsoft_client_secret
  • oauth_microsoft_tenantcommon (any work/school or personal account, the default), organizations (work/school only), or your tenant GUID to restrict sign-in to one tenant.

Each provider's callback URL is <base-url>/api/users/auth/<provider>/callback (google, github, microsoft, oidc).

Note: for Microsoft guest/external accounts the identity email comes from the Graph userPrincipalName, which may not be a plain email (e.g. user_ext.com#EXT#@tenant.onmicrosoft.com). For tenant members it is the user's email.

Migrating from SM_USERS_OAUTH_* env vars

Earlier versions read provider credentials from SM_USERS_OAUTH_* environment variables. These are no longer read at runtime. Migrate existing values into the settings store once with:

uv run smpy settings import-from-env

License

MIT — see LICENSE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

simple_module_users-0.0.27.tar.gz (90.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

simple_module_users-0.0.27-py3-none-any.whl (87.8 kB view details)

Uploaded Python 3

File details

Details for the file simple_module_users-0.0.27.tar.gz.

File metadata

  • Download URL: simple_module_users-0.0.27.tar.gz
  • Upload date:
  • Size: 90.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for simple_module_users-0.0.27.tar.gz
Algorithm Hash digest
SHA256 c808b4f8f8645e64c0b3699d0d289dc6187457b9883b296c265bc8b949661a1f
MD5 a4749e9e19d028a5f950f77fe03f56b0
BLAKE2b-256 6fea3e716548b5bd4b0a44194086874083f71509743f75dcb5de58048a97596c

See more details on using hashes here.

Provenance

The following attestation bundles were made for simple_module_users-0.0.27.tar.gz:

Publisher: release.yml on antosubash/simple_module_python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file simple_module_users-0.0.27-py3-none-any.whl.

File metadata

File hashes

Hashes for simple_module_users-0.0.27-py3-none-any.whl
Algorithm Hash digest
SHA256 de87a2c4dc54332f6dccd95fc006f75113e1a3409bd1cc959e4d8680004138c6
MD5 c9e646a031fec93ad381798bad0f898d
BLAKE2b-256 523dd910cde7273fd8e723d236f642bb65126708ae74a8f355cc73b6f76f796e

See more details on using hashes here.

Provenance

The following attestation bundles were made for simple_module_users-0.0.27-py3-none-any.whl:

Publisher: release.yml on antosubash/simple_module_python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.0.33

2 files

0.0.32

2 files

0.0.31

2 files

0.0.30

2 files

0.0.29

2 files

0.0.28

2 files

This release

0.0.27 This release

2 files

0.0.26

2 files

0.0.25

2 files

0.0.24

2 files

0.0.23

2 files

0.0.22

2 files

0.0.21

2 files

0.0.20

2 files

0.0.19

2 files

0.0.18

2 files

0.0.17

2 files

0.0.16

2 files

0.0.15

2 files

0.0.14

2 files

0.0.13

2 files

0.0.12

2 files

0.0.11

2 files

0.0.10

2 files

0.0.9

2 files

0.0.8

2 files

0.0.7

2 files

0.0.6

2 files

0.0.5

2 files

0.0.4

2 files

0.0.3

2 files

0.0.2

2 files

0.0.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page