Two-layer RBAC (system + company) helpers for FastAPI / Flask / any Python backend — paired with the snipe-auth-rbac TS sibling.
Project description
snipe-auth-rbac (Python)
Python sibling of the
snipe-auth-rbac
npm package. Two-layer RBAC (system + per-company roles) for
FastAPI, Flask, or any Python backend that talks to a Supabase /
Postgres database.
The full picture — including the SQL schema, the TypeScript / React side, and the admin UI building blocks — lives in the top-level repo.
Install
pip install "snipe-auth-rbac[fastapi]"
Optional extras:
| Extra | What it pulls in |
|---|---|
fastapi |
fastapi, starlette — needed for auth_rbac.deps |
supabase |
supabase-py |
dev |
ruff, pytest |
Apply the SQL once
The tables and resolver functions live in a dedicated rbac
schema. The simplest path on Supabase is the bundled npm CLI (a
plain Node script — no JS knowledge needed):
npx snipe-auth-rbac install
supabase db push
# Then in Studio → Settings → API → Exposed schemas → add `rbac`
For other Postgres tooling, the canonical SQL files live at
sql/0001_initial.sql
and 0002_seed_defaults.sql in the repo.
FastAPI integration
from fastapi import FastAPI, Depends
from auth_rbac import PermissionsService, ResourceDescriptor
from auth_rbac.deps import (
configure_auth_rbac,
active_company_middleware,
require_permission,
require_system_permission,
)
from app.integrations.supabase import get_supabase_client
RESOURCES = [
ResourceDescriptor("system_audit", "system", "Audit-Log", group="Plattform"),
ResourceDescriptor("properties", "company", "Liegenschaften", group="Stammdaten"),
ResourceDescriptor("payments", "company", "Zahlungen", group="Finanzen"),
]
app = FastAPI()
service = PermissionsService(supabase=get_supabase_client(), resources=RESOURCES)
# Fail loudly on boot if the migration hasn't been applied or
# `rbac` isn't in the project's PostgREST exposed-schemas list.
service.require_schema()
# Upsert the typed registry into rbac.resources on every boot.
# Adding a new entry to RESOURCES + redeploying makes the matrix
# UI grow a new column — no manual migration step.
service.sync_resources()
async def resolve_user_id(request):
return request.state.user_id # adapter to your existing auth dep
configure_auth_rbac(service=service, user_id_resolver=resolve_user_id)
app.middleware("http")(active_company_middleware)
@app.get("/payments")
async def list_payments(_=Depends(require_permission("payments", "read"))):
...
@app.post("/system/companies")
async def create_company(
_=Depends(require_system_permission("system_companies", "write")),
):
...
Other backends
auth_rbac.deps is FastAPI-specific, but PermissionsService
itself is plain Python. For Flask / Litestar / starlette-bare:
from auth_rbac import PermissionsService
# Where you'd normally check role:
allowed = service.user_can(
user_id=current_user.id,
resource="payments",
action="update",
company_id=request.state.company_id,
)
if not allowed:
abort(403)
Hydrating the full profile
For a /me/profile endpoint that returns every role + permission
the user holds in one round-trip:
profile = service.hydrate_profile(user_id)
# profile.system_roles, profile.system_permissions,
# profile.memberships -> [CompanyMembership(roles, permissions, …)]
The result is cached for 30 seconds per user. Swap
_ProfileCache for a Redis implementation if you need
cross-process invalidation.
Pre-filling templates
service.apply_template_defaults(role_id="…", only_missing=True)
# Reads default_permissions JSONB on the role and inserts
# rbac.role_permissions rows for every resource that matches.
License
MIT.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file snipe_auth_rbac-0.5.0.tar.gz.
File metadata
- Download URL: snipe_auth_rbac-0.5.0.tar.gz
- Upload date:
- Size: 13.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
78dd51884cfca123c9fa0983943ba7a85f7c467f19a44bbf22d1aa2c7d5ed89a
|
|
| MD5 |
04341f1b9909a6de30fd7b442c18f693
|
|
| BLAKE2b-256 |
99a41f78a1c35c9694c35b9d41733476b83a8cc5a468d75baf2e38603721f039
|
File details
Details for the file snipe_auth_rbac-0.5.0-py3-none-any.whl.
File metadata
- Download URL: snipe_auth_rbac-0.5.0-py3-none-any.whl
- Upload date:
- Size: 15.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7720a661983c33f1ab24f8c836e8b6fa93e7f54234e5f55a02b94bd737ecf870
|
|
| MD5 |
20d175f3d928134b31e6066c0eebcc2a
|
|
| BLAKE2b-256 |
13a72453eaf6cddd3d822862f991cb3f9ab16fc0793eb494267e18ceea3229a9
|