Async user / group / permission management library backed by a Rust core (SQLite, Argon2, JWT, optional HTTP relay)
Project description
user-permission-py
ユーザーとグループを管理するための非同期ライブラリ user-permission の Python バインディング です。
Rust 実装本体は別リポジトリに分離されました: mokuichi147/user-permission
このリポジトリは PyO3 + maturin による薄いラッパーのみを含み、PyPI パッケージ user-permission をビルド・公開します。
クイックスタート (サーバーを試す)
インストール不要で、uvx から直接サーバーを起動できます。
uvx user-permission serve --webui
ブラウザで http://127.0.0.1:8000/ui を開くと Web 管理画面が利用できます。 オプション一覧は サーバー起動 を参照してください。
インストール
pip install user-permission
依存パッケージはありません (Rust 拡張に同梱)。Python 3.9 以降の abi3 wheel を公開しています。
ソースからビルドする場合:
maturin develop # 開発用に現在の venv に組み込む
maturin build --release # リリース wheel をビルド
使い方
初期化
import asyncio
from user_permission import Database
async def main():
# 初回実行時にシークレットキーを自動生成(以降はファイルから読み込み)
async with Database("app.db", secret="secret.key") as db:
user = await db.users.create("alice", "password123")
group = await db.groups.create("admins")
asyncio.run(main())
ユーザー管理
user = await db.users.create("alice", "password123", display_name="Alice")
user = await db.users.get_by_id(1)
user = await db.users.get_by_username("alice")
users = await db.users.list_all()
await db.users.update(user.id, password="new_password")
await db.users.update(user.id, display_name="Alice Smith")
await db.users.update(user.id, is_active=False)
await db.users.delete(user.id)
認証・トークン
from datetime import timedelta
token = await db.users.authenticate("alice", "password123")
token = await db.users.authenticate(
"alice", "password123", expires_delta=timedelta(hours=24)
)
payload = db.token_manager.verify_token(token)
print(payload["sub"]) # ユーザーID(文字列)
print(payload["username"]) # ユーザー名
print(payload["is_admin"]) # bool
グループ管理
group = await db.groups.create("admins", description="Administrator group")
group = await db.groups.get_by_id(1)
group = await db.groups.get_by_name("admins")
groups = await db.groups.list_all()
await db.groups.update(group.id, description="Updated description")
await db.groups.delete(group.id)
グループメンバー管理
await db.groups.add_user(group.id, user.id)
await db.groups.remove_user(group.id, user.id)
members = await db.groups.get_members(group.id)
groups = await db.groups.get_user_groups(user.id)
サーバー起動
import asyncio
from user_permission import serve
asyncio.run(serve(host="0.0.0.0", port=8001, prefix="/api", webui=True))
CLI からも起動できます。
user-permission serve --host 0.0.0.0 --port 8001 --prefix /api --webui
| オプション | デフォルト | 説明 |
|---|---|---|
--host |
127.0.0.1 |
バインドアドレス |
--port |
8000 |
バインドポート |
--database |
user_permission.db |
SQLiteデータベースのパス |
--secret |
secret.key |
シークレットキーファイルのパス |
--prefix |
(なし) | APIルートプレフィックス(例: /api) |
--webui |
無効 | Web管理画面を有効化 |
--webui-prefix |
/ui |
管理画面のURLプレフィックス |
リレー(中継)
Database に URL を渡すと、ローカル SQLite と中央サーバーを同じインターフェースで切り替えられます。
from user_permission import Database
# ファイルパス → ローカル SQLite
db = Database("app.db", secret="secret.key")
# URL → リモートサーバーへ HTTP 中継
async with Database("http://localhost:8001") as db:
token = await db.login("alice", "password123")
users = await db.users.list_all()
db.login(...) で取得したトークンは Database が内部に保持し、以降のリクエストの Authorization: Bearer に自動付与されます。
REST API・管理者ロール・スキーマ
REST エンドポイント仕様、groups.is_admin による管理者ロールの扱い、データベーススキーマは
Rust リポジトリの README を参照してください。
開発
# Python wheel をビルドして現在の venv に組み込む
maturin develop
# Python 統合テスト
pip install pytest pytest-asyncio
pytest tests/python
# リリース wheel をビルド
maturin build --release
リリース
pyproject.toml のバージョンを更新し、v で始まる Git タグを push すると GitHub Actions が
全プラットフォームの wheel をビルドして PyPI に公開します (詳細は .github/workflows/release.yml)。
ライセンス
MIT OR Apache-2.0
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distributions
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file user_permission-0.5.2.tar.gz.
File metadata
- Download URL: user_permission-0.5.2.tar.gz
- Upload date:
- Size: 39.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b4753f4a9e70ae3e65403a72025a9a293fccec1a23da6715af530e9eea14695d
|
|
| MD5 |
12ccf5ff18abb96eb94e7d33895a8da4
|
|
| BLAKE2b-256 |
a83589e1789863f1ec253e552f0fa6f79ac1a3b5f1a77029a15f8ae0fbd09e57
|
Provenance
The following attestation bundles were made for user_permission-0.5.2.tar.gz:
Publisher:
release.yml on Mokuichi147/user-permission-py
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
user_permission-0.5.2.tar.gz -
Subject digest:
b4753f4a9e70ae3e65403a72025a9a293fccec1a23da6715af530e9eea14695d - Sigstore transparency entry: 1625773479
- Sigstore integration time:
-
Permalink:
Mokuichi147/user-permission-py@f1747111c12bb8ed9acb198d535281adba03e3f8 -
Branch / Tag:
refs/tags/v0.5.2 - Owner: https://github.com/Mokuichi147
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f1747111c12bb8ed9acb198d535281adba03e3f8 -
Trigger Event:
push
-
Statement type:
File details
Details for the file user_permission-0.5.2-cp39-abi3-win_amd64.whl.
File metadata
- Download URL: user_permission-0.5.2-cp39-abi3-win_amd64.whl
- Upload date:
- Size: 4.1 MB
- Tags: CPython 3.9+, Windows x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
d446134f92c3239888275d5581967ec73f177dd3d587633682d83085afbd7769
|
|
| MD5 |
499bd465d435460da75f2c3187778a4f
|
|
| BLAKE2b-256 |
bd68d7dd8a75552518abf1cf0621f7d85179af33b33b0cafdc2f8ff8fcff0c44
|
Provenance
The following attestation bundles were made for user_permission-0.5.2-cp39-abi3-win_amd64.whl:
Publisher:
release.yml on Mokuichi147/user-permission-py
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
user_permission-0.5.2-cp39-abi3-win_amd64.whl -
Subject digest:
d446134f92c3239888275d5581967ec73f177dd3d587633682d83085afbd7769 - Sigstore transparency entry: 1625773604
- Sigstore integration time:
-
Permalink:
Mokuichi147/user-permission-py@f1747111c12bb8ed9acb198d535281adba03e3f8 -
Branch / Tag:
refs/tags/v0.5.2 - Owner: https://github.com/Mokuichi147
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f1747111c12bb8ed9acb198d535281adba03e3f8 -
Trigger Event:
push
-
Statement type:
File details
Details for the file user_permission-0.5.2-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.
File metadata
- Download URL: user_permission-0.5.2-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
- Upload date:
- Size: 3.9 MB
- Tags: CPython 3.9+, manylinux: glibc 2.17+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1fb49b7bd2cc3a37eede69682d73b210da2a625baf24240e9677e84ba144c41d
|
|
| MD5 |
d91dd513e04cdeda0149b1897a4ec191
|
|
| BLAKE2b-256 |
498c1478d564a1829f3c4788dc45d23602987ef9cdd42c6ad92935d1022e5260
|
Provenance
The following attestation bundles were made for user_permission-0.5.2-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:
Publisher:
release.yml on Mokuichi147/user-permission-py
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
user_permission-0.5.2-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl -
Subject digest:
1fb49b7bd2cc3a37eede69682d73b210da2a625baf24240e9677e84ba144c41d - Sigstore transparency entry: 1625773546
- Sigstore integration time:
-
Permalink:
Mokuichi147/user-permission-py@f1747111c12bb8ed9acb198d535281adba03e3f8 -
Branch / Tag:
refs/tags/v0.5.2 - Owner: https://github.com/Mokuichi147
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f1747111c12bb8ed9acb198d535281adba03e3f8 -
Trigger Event:
push
-
Statement type:
File details
Details for the file user_permission-0.5.2-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.
File metadata
- Download URL: user_permission-0.5.2-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
- Upload date:
- Size: 3.7 MB
- Tags: CPython 3.9+, manylinux: glibc 2.17+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1db76b5fab4135231039520e8e900ddd1f90e63fbc0be6a080fac9c098b2866b
|
|
| MD5 |
acd6e0934286ff173a955b9c4a421b6f
|
|
| BLAKE2b-256 |
95956573d289cebb0b0b8c085db6dc8aa5b7631052eb46c988254f7319f66ec7
|
Provenance
The following attestation bundles were made for user_permission-0.5.2-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:
Publisher:
release.yml on Mokuichi147/user-permission-py
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
user_permission-0.5.2-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl -
Subject digest:
1db76b5fab4135231039520e8e900ddd1f90e63fbc0be6a080fac9c098b2866b - Sigstore transparency entry: 1625773509
- Sigstore integration time:
-
Permalink:
Mokuichi147/user-permission-py@f1747111c12bb8ed9acb198d535281adba03e3f8 -
Branch / Tag:
refs/tags/v0.5.2 - Owner: https://github.com/Mokuichi147
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f1747111c12bb8ed9acb198d535281adba03e3f8 -
Trigger Event:
push
-
Statement type:
File details
Details for the file user_permission-0.5.2-cp39-abi3-macosx_11_0_arm64.whl.
File metadata
- Download URL: user_permission-0.5.2-cp39-abi3-macosx_11_0_arm64.whl
- Upload date:
- Size: 3.5 MB
- Tags: CPython 3.9+, macOS 11.0+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
24cdebcc09a108dbec4ee2d1d9cb7607d9a4696d2dbfcef4451471fbb1e59c93
|
|
| MD5 |
06fea708435accfe4bad74713f6041ba
|
|
| BLAKE2b-256 |
d91d32e7ea1e2580b4d9e289ab39e5465e8bff7daf5f6193baa028ae50d819b0
|
Provenance
The following attestation bundles were made for user_permission-0.5.2-cp39-abi3-macosx_11_0_arm64.whl:
Publisher:
release.yml on Mokuichi147/user-permission-py
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
user_permission-0.5.2-cp39-abi3-macosx_11_0_arm64.whl -
Subject digest:
24cdebcc09a108dbec4ee2d1d9cb7607d9a4696d2dbfcef4451471fbb1e59c93 - Sigstore transparency entry: 1625773572
- Sigstore integration time:
-
Permalink:
Mokuichi147/user-permission-py@f1747111c12bb8ed9acb198d535281adba03e3f8 -
Branch / Tag:
refs/tags/v0.5.2 - Owner: https://github.com/Mokuichi147
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f1747111c12bb8ed9acb198d535281adba03e3f8 -
Trigger Event:
push
-
Statement type:
File details
Details for the file user_permission-0.5.2-cp39-abi3-macosx_10_12_x86_64.whl.
File metadata
- Download URL: user_permission-0.5.2-cp39-abi3-macosx_10_12_x86_64.whl
- Upload date:
- Size: 3.8 MB
- Tags: CPython 3.9+, macOS 10.12+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
14e40fc937c99e619e2aebbb111a4acb45eb0924d1ee9d8d77585822c5bb5cfe
|
|
| MD5 |
f8ad7941775a13978143a3bfcedccb89
|
|
| BLAKE2b-256 |
321e32cd75f5c7cc1b77d5cfcb3ca7a42c0f6e70ad84c119e177844e0c9b17a9
|
Provenance
The following attestation bundles were made for user_permission-0.5.2-cp39-abi3-macosx_10_12_x86_64.whl:
Publisher:
release.yml on Mokuichi147/user-permission-py
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
user_permission-0.5.2-cp39-abi3-macosx_10_12_x86_64.whl -
Subject digest:
14e40fc937c99e619e2aebbb111a4acb45eb0924d1ee9d8d77585822c5bb5cfe - Sigstore transparency entry: 1625773636
- Sigstore integration time:
-
Permalink:
Mokuichi147/user-permission-py@f1747111c12bb8ed9acb198d535281adba03e3f8 -
Branch / Tag:
refs/tags/v0.5.2 - Owner: https://github.com/Mokuichi147
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@f1747111c12bb8ed9acb198d535281adba03e3f8 -
Trigger Event:
push
-
Statement type: