Skip to main content

simple_module_users

Email+password user management for simple_module apps. Replaces Keycloak/Auth0 for the common case: local accounts, admin invites, password reset, optional public signup. Built on fastapi-users.

Install

pip install simple_module_users

Pre-wired into any app scaffolded with smpy new.

What it provides

  • Email + password registration, login, logout, password reset.
  • Admin invite flow — admin enters an email, recipient clicks a link, sets a password, is logged in.
  • Public signup toggle (SM_USERS_ALLOW_SIGNUP, default false).
  • Bootstrap admin via env vars (SM_USERS_BOOTSTRAP_EMAIL + SM_USERS_BOOTSTRAP_PASSWORD) — idempotent, only creates if the users table is empty.
  • smpy users create-admin CLI for ad-hoc admin creation.
  • Inertia pages for login/register/invite-accept/admin-invite.
  • Console mailer (logs to stdout) or SMTP mailer (SM_USERS_MAILER=smtp).

Usage

CLI:

uv run smpy users create-admin --email admin@example.com --password 'change-me'

Bootstrap-on-boot (.env):

SM_USERS_BOOTSTRAP_EMAIL=admin@example.com
SM_USERS_BOOTSTRAP_PASSWORD=change-me

Program:

from auth.deps import CurrentUser  # type: ignore[import-not-found]


@router.get("/profile")
async def profile(user: CurrentUser):
    return {"email": user.email}

Depends on

  • simple_module_core, simple_module_db, simple_module_hosting, simple_module_settings, simple_module_auth
  • fastapi-users[sqlalchemy,oauth]>=15,<16, aiosmtplib, cachetools, typer

Social sign-in (Google, GitHub, Microsoft, OIDC)

OAuth providers are configured in the admin UI at /settings/modules → Users (no environment variables). Each provider activates once its client id and secret are set; the secret is masked in the UI. Changes apply live — no restart.

Microsoft (Entra ID). Register an app in the Entra admin center and set the redirect URI to <base-url>/api/users/auth/microsoft/callback. Configure under the Microsoft OAuth group:

  • oauth_microsoft_client_id, oauth_microsoft_client_secret
  • oauth_microsoft_tenantcommon (any work/school or personal account, the default), organizations (work/school only), or your tenant GUID to restrict sign-in to one tenant.

Each provider's callback URL is <base-url>/api/users/auth/<provider>/callback (google, github, microsoft, oidc).

Note: for Microsoft guest/external accounts the identity email comes from the Graph userPrincipalName, which may not be a plain email (e.g. user_ext.com#EXT#@tenant.onmicrosoft.com). For tenant members it is the user's email.

Migrating from SM_USERS_OAUTH_* env vars

Earlier versions read provider credentials from SM_USERS_OAUTH_* environment variables. These are no longer read at runtime. Migrate existing values into the settings store once with:

uv run smpy settings import-from-env

License

MIT — see LICENSE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

simple_module_users-0.0.29.tar.gz (90.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

simple_module_users-0.0.29-py3-none-any.whl (87.9 kB view details)

Uploaded Python 3

File details

Details for the file simple_module_users-0.0.29.tar.gz.

File metadata

  • Download URL: simple_module_users-0.0.29.tar.gz
  • Upload date:
  • Size: 90.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for simple_module_users-0.0.29.tar.gz
Algorithm Hash digest
SHA256 ec2ad718fccdcb5f998c64cf6ae00aad1482b3feacaa7f0660d75b77a6f66ebc
MD5 5a1956aa19ac4f25eb04ba8362d60f4b
BLAKE2b-256 0656af1827abad321d6643f14795e120e6cf0d0295ec40b470eb5ca19e02aa85

See more details on using hashes here.

Provenance

The following attestation bundles were made for simple_module_users-0.0.29.tar.gz:

Publisher: release.yml on antosubash/simple_module_python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file simple_module_users-0.0.29-py3-none-any.whl.

File metadata

File hashes

Hashes for simple_module_users-0.0.29-py3-none-any.whl
Algorithm Hash digest
SHA256 35310d571f3eddb9f38820735cd1eb1d2dcc8279f2404ab9b195034e3bc0c875
MD5 67fff5e100fd48ca0edc548eaace8e91
BLAKE2b-256 f938396f1eb07680d8825a6d2c38e034ee1a3e80bb736b6624fbf29b5aba3556

See more details on using hashes here.

Provenance

The following attestation bundles were made for simple_module_users-0.0.29-py3-none-any.whl:

Publisher: release.yml on antosubash/simple_module_python

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.0.33

2 files

0.0.32

2 files

0.0.31

2 files

0.0.30

2 files

This release

0.0.29 This release

2 files

0.0.28

2 files

0.0.27

2 files

0.0.26

2 files

0.0.25

2 files

0.0.24

2 files

0.0.23

2 files

0.0.22

2 files

0.0.21

2 files

0.0.20

2 files

0.0.19

2 files

0.0.18

2 files

0.0.17

2 files

0.0.16

2 files

0.0.15

2 files

0.0.14

2 files

0.0.13

2 files

0.0.12

2 files

0.0.11

2 files

0.0.10

2 files

0.0.9

2 files

0.0.8

2 files

0.0.7

2 files

0.0.6

2 files

0.0.5

2 files

0.0.4

2 files

0.0.3

2 files

0.0.2

2 files

0.0.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page