This release is a pre-release and may not be stable for production use.
Swarmauri Middleware HttpSig
HttpSigMiddleware verifies a base64-encoded HMAC-SHA256 signature on every
incoming request body. The middleware compares the provided signature (default
header X-Signature) with one generated from the request payload using a
shared secret. Missing or incorrect signatures are rejected with 401.
Features
- Validates request payloads with an HMAC-SHA256 digest
- Uses constant-time comparisons to mitigate timing attacks
- Configurable signature header via the
header_nameargument - Logs and rejects requests that do not supply a valid signature
Installation
Choose the tool that matches your workflow:
# pip
pip install swarmauri_middleware_httpsig
# Poetry
poetry add swarmauri_middleware_httpsig
# uv
uv add swarmauri_middleware_httpsig
Example
The snippet below wires the middleware into FastAPI via the @app.middleware
decorator, signs a request body, and demonstrates the 401 response that
occurs when a tampered signature is supplied. The middleware raises
HTTPException, so the example also converts those errors to JSON responses.
import base64
import hashlib
import hmac
import json
from fastapi import FastAPI, HTTPException, Request
from fastapi.testclient import TestClient
from fastapi.responses import JSONResponse
from swarmauri_middleware_httpsig import HttpSigMiddleware
app = FastAPI()
http_sig = HttpSigMiddleware(secret_key="supersecret")
@app.middleware("http")
async def verify_signature(request: Request, call_next):
try:
return await http_sig.dispatch(request, call_next)
except HTTPException as exc:
return JSONResponse(status_code=exc.status_code, content={"detail": exc.detail})
@app.post("/echo")
async def echo(payload: dict) -> dict:
return payload
def create_signature(secret: str, body: bytes) -> str:
digest = hmac.new(secret.encode(), body, hashlib.sha256).digest()
return base64.b64encode(digest).decode()
if __name__ == "__main__":
client = TestClient(app)
body = json.dumps({"message": "hello"}).encode()
signature = create_signature("supersecret", body)
ok = client.post(
"/echo",
data=body,
headers={
"X-Signature": signature,
"Content-Type": "application/json",
},
)
assert ok.status_code == 200
print("Verified response:", ok.json())
bad = client.post(
"/echo",
data=body,
headers={
"X-Signature": "tampered",
"Content-Type": "application/json",
},
)
assert bad.status_code == 401
print("Unauthorized status:", bad.status_code)
Want to help?
If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.
Metadata
Release files for swarmauri_middleware_httpsig 0.11.0.dev1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_middleware_httpsig-0.11.0.dev1.tar.gz | 7.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_middleware_httpsig-0.11.0.dev1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 16.9 kB
Release files / swarmauri_middleware_httpsig-0.11.0.dev1.tar.gz
| Download URL | swarmauri_middleware_httpsig-0.11.0.dev1.tar.gz |
|---|---|
| Size | 7.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
49a177a0e4723be6642bc4fce6408b5e97ca82a6a5e5cdacfd9b9f0f7e9b816c
|
|
BLAKE2b-256 checksum How to use checksums |
07a340df966d3671b50cc5e6566e4dd6f4917443a1b0a6a2f3fce6f14354821d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_middleware_httpsig-0.11.0.dev1-py3-none-any.whl
| Download URL | swarmauri_middleware_httpsig-0.11.0.dev1-py3-none-any.whl |
|---|---|
| Size | 9.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
df71dab8cb38b229af8acd4048544afdc5c9bd5f401b56fe35b59d65faeeba0d
|
|
BLAKE2b-256 checksum How to use checksums |
dc71042137ba0bd0e6b423c63ca4441a3965de94342a3b4d3d74a0a2c2089f30
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|