Synapse authentication module which allows for authenticating and registering using JWTs
Project description
Synapse Token Authenticator
Synapse Token Authenticator is a synapse auth provider which allows for token authentication (and optional registration) using JWTs (Json Web Tokens).
Table of Contents
Installation
TODO: requires publishing on pypi.
pip install synapse-token-authenticator
Configuration
Here are the available configuration options:
# provide only one of secret, keyfile
secret: symetrical secret
keyfile: path to asymetrical keyfile
# Algorithm of the tokens, defaults to HS512
#algorithm: HS512
# Allow registration of new users using these tokens, defaults to false
#allow_registration: false
# Require tokens to have an expiracy set, defaults to true
#require_expiracy: true
It is recommended to have require_expiracy
set to true
(default). As for allow_registration
, it depends on usecase: If you only want to be able to log in existing users, leave it at false
(default). If nonexistant users should be simply registered upon hitting the login endpoint, set it to true
.
Usage
First you have to generate a JWT with the correct claims. The sub
claim is the localpart or full mxid of the user you want to log in as. Be sure that the algorithm and secret match those of the configuration. An example of the claims is as follows:
{
"sub": "alice",
"exp": 1516239022
}
Next you need to post this token to the /login
endpoint of synapse. Be sure that the type
is com.famedly.login.token
and that identifier.user
is, again, either the localpart or the full mxid. For example the post body could look as following:
{
"type": "com.famedly.login.token",
"identifier": {
"type": "m.id.user",
"user": "alice"
},
"token": "<jwt here>"
}
Testing
The tests uses twisted's testing framework trial, with the development enviroment managed by hatch. Running the tests and generating a coverage report can be done like this:
hatch run cov
License
synapse-token-authenticator
is distributed under the terms of the
AGPL-3.0 license.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Hashes for synapse_token_authenticator-0.2.0.tar.gz
Algorithm | Hash digest | |
---|---|---|
SHA256 | ebcf15ad69ded712cdcbc5c58cb6ac5d9ebe441f10f751fbb3f1dfc274ba7136 |
|
MD5 | d9ff5c2fff4f1e984f88e5a2287b5d09 |
|
BLAKE2b-256 | 9c75d96081d47db67ad3aa706aea52a6c1c8926910ed71e3f765db45e39bf3a3 |
Hashes for synapse_token_authenticator-0.2.0-py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | a42a06f62d27d5df14bfb138ddb0d3e52a03d3fb021e3cb23fa5842e066488ef |
|
MD5 | 7708cf25ee82f5a7271d78566a094e9a |
|
BLAKE2b-256 | c45ea3d12371fed1d36ebb32f4b8b8f82423cba349aeec23740b1f7aeaf47361 |