Skip to main content

Async user / group / permission management library backed by a Rust core (SQLite, Argon2, JWT, optional HTTP relay)

Project description

user-permission-py

PyPI - License PyPI - Version Pepy Total Downloads

ユーザーとグループを管理するための非同期ライブラリ user-permissionPython バインディング です。

Rust 実装本体は別リポジトリに分離されました: mokuichi147/user-permission

このリポジトリは PyO3 + maturin による薄いラッパーのみを含み、PyPI パッケージ user-permission をビルド・公開します。

クイックスタート (サーバーを試す)

インストール不要で、uvx から直接サーバーを起動できます。

uvx user-permission serve --webui

ブラウザで http://127.0.0.1:8000/ui を開くと Web 管理画面が利用できます。 オプション一覧は サーバー起動 を参照してください。

インストール

pip install user-permission

依存パッケージはありません (Rust 拡張に同梱)。Python 3.9 以降の abi3 wheel を公開しています。

ソースからビルドする場合:

maturin develop          # 開発用に現在の venv に組み込む
maturin build --release  # リリース wheel をビルド

使い方

初期化

import asyncio
from user_permission import Database

async def main():
    # 初回実行時にシークレットキーを自動生成(以降はファイルから読み込み)
    async with Database("app.db", secret="secret.key") as db:
        user = await db.users.create("alice", "password123")
        group = await db.groups.create("admins")

asyncio.run(main())

ユーザー管理

user = await db.users.create("alice", "password123", display_name="Alice")
user = await db.users.get_by_id(1)
user = await db.users.get_by_username("alice")
users = await db.users.list_all()

await db.users.update(user.id, password="new_password")
await db.users.update(user.id, display_name="Alice Smith")
await db.users.update(user.id, is_active=False)
await db.users.delete(user.id)

認証・トークン

from datetime import timedelta

token = await db.users.authenticate("alice", "password123")
token = await db.users.authenticate(
    "alice", "password123", expires_delta=timedelta(hours=24)
)

payload = db.token_manager.verify_token(token)
print(payload["sub"])        # ユーザーID(文字列)
print(payload["username"])   # ユーザー名
print(payload["is_admin"])   # bool

グループ管理

group = await db.groups.create("admins", description="Administrator group")
group = await db.groups.get_by_id(1)
group = await db.groups.get_by_name("admins")
groups = await db.groups.list_all()

await db.groups.update(group.id, description="Updated description")
await db.groups.delete(group.id)

グループメンバー管理

await db.groups.add_user(group.id, user.id)
await db.groups.remove_user(group.id, user.id)
members = await db.groups.get_members(group.id)
groups = await db.groups.get_user_groups(user.id)

サーバー起動

import asyncio
from user_permission import serve

asyncio.run(serve(host="0.0.0.0", port=8001, prefix="/api", webui=True))

CLI からも起動できます。

user-permission serve --host 0.0.0.0 --port 8001 --prefix /api --webui
オプション デフォルト 説明
--host 127.0.0.1 バインドアドレス
--port 8000 バインドポート
--database user_permission.db SQLiteデータベースのパス
--secret secret.key シークレットキーファイルのパス
--prefix (なし) APIルートプレフィックス(例: /api
--webui 無効 Web管理画面を有効化
--webui-prefix /ui 管理画面のURLプレフィックス

リレー(中継)

Database に URL を渡すと、ローカル SQLite と中央サーバーを同じインターフェースで切り替えられます。

from user_permission import Database

# ファイルパス → ローカル SQLite
db = Database("app.db", secret="secret.key")

# URL → リモートサーバーへ HTTP 中継
async with Database("http://localhost:8001") as db:
    token = await db.login("alice", "password123")
    users = await db.users.list_all()

db.login(...) で取得したトークンは Database が内部に保持し、以降のリクエストの Authorization: Bearer に自動付与されます。

サービスクライアント認証(client-credentials)

サービス間連携向けに、平文パスワードを持たずに読み取り専用のスコープ付きトークンを発行できます。 クライアントには users:read / groups:read のスコープのみ付与でき、書き込みや管理操作はできません。

from user_permission import Database, SCOPE_USERS_READ

# 管理側(ローカル)でサービスクライアントを発行。secret は発行時のみ取得可能。
async with Database("app.db", secret="secret.key") as db:
    client, secret = await db.service_clients.create("reader", [SCOPE_USERS_READ])

# リレー側はサービストークンでログインし、スコープ内のみ読み取れる。
async with Database("http://localhost:8001") as relay:
    await relay.login_client_credentials(client.client_id, secret)
    users = await relay.users.list_all()  # users:read があるので OK

バックエンド非依存のユーティリティ

ローカル / リレーのどちらでも同じ呼び出しで動作します。

# トークンを検証してユーザーを解決(無効・期限切れ・サービストークンは None)
user = await db.verify_token_and_get_user(token)

# 管理者が不在なら作成して昇格(リレーでは no-op)
await db.bootstrap_admin_if_needed("admin", "password123")

REST API・管理者ロール・スキーマ

REST エンドポイント仕様、groups.is_admin による管理者ロールの扱い、データベーススキーマは Rust リポジトリの README を参照してください。

開発

# Python wheel をビルドして現在の venv に組み込む
maturin develop

# Python 統合テスト
pip install pytest pytest-asyncio
pytest tests/python

# リリース wheel をビルド
maturin build --release

リリース

pyproject.toml のバージョンを更新し、v で始まる Git タグを push すると GitHub Actions が 全プラットフォームの wheel をビルドして PyPI に公開します (詳細は .github/workflows/release.yml)。

ライセンス

MIT OR Apache-2.0

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

user_permission-0.5.3.tar.gz (42.1 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

user_permission-0.5.3-cp39-abi3-win_amd64.whl (4.3 MB view details)

Uploaded CPython 3.9+Windows x86-64

user_permission-0.5.3-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (4.1 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.17+ x86-64

user_permission-0.5.3-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl (3.8 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.17+ ARM64

user_permission-0.5.3-cp39-abi3-macosx_11_0_arm64.whl (3.7 MB view details)

Uploaded CPython 3.9+macOS 11.0+ ARM64

user_permission-0.5.3-cp39-abi3-macosx_10_12_x86_64.whl (4.0 MB view details)

Uploaded CPython 3.9+macOS 10.12+ x86-64

File details

Details for the file user_permission-0.5.3.tar.gz.

File metadata

  • Download URL: user_permission-0.5.3.tar.gz
  • Upload date:
  • Size: 42.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for user_permission-0.5.3.tar.gz
Algorithm Hash digest
SHA256 e0ba8095ff49626596fb6bca54b09f497dcbf19c6600395a44c4cc331e0b4cb2
MD5 88bc5f7c73b0844c0c7b55b43e48bbd0
BLAKE2b-256 737cd6316aeb6b2ee6ae1195b9af9d920131e9975033e25fbb709ebd218118c6

See more details on using hashes here.

Provenance

The following attestation bundles were made for user_permission-0.5.3.tar.gz:

Publisher: release.yml on Mokuichi147/user-permission-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file user_permission-0.5.3-cp39-abi3-win_amd64.whl.

File metadata

File hashes

Hashes for user_permission-0.5.3-cp39-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 3cb31f33ff2c724e02e8446f0208a9b3b790dfbe230f028b4e9da69ec235baa6
MD5 520453ae6b2a1559972205e6b2290c9d
BLAKE2b-256 66acfa7240aed4b625425be147cb5244da21db562ae5d603c71d99026865c3d4

See more details on using hashes here.

Provenance

The following attestation bundles were made for user_permission-0.5.3-cp39-abi3-win_amd64.whl:

Publisher: release.yml on Mokuichi147/user-permission-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file user_permission-0.5.3-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for user_permission-0.5.3-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 11fba3ecac4b2e0ee0c03b5d26a627051b58ab68021caac91fae04b0c7312417
MD5 ba39d4a28f0fd4a58b59a1849ff9e190
BLAKE2b-256 fc76d6a4f0ab2bae31bb43f8f6faaf42f083e556184491c5c26f83dfc59ae662

See more details on using hashes here.

Provenance

The following attestation bundles were made for user_permission-0.5.3-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: release.yml on Mokuichi147/user-permission-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file user_permission-0.5.3-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for user_permission-0.5.3-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 84cdef1a50b02f41f0042a9a15cb9b33b83f9810d19a5f69054fb08d8b92185c
MD5 7d809817aecc258a529df22a728a039b
BLAKE2b-256 2e978101a0fdd37054d8092b8b284912828637c3a7c8a6d181a91dd07916742b

See more details on using hashes here.

Provenance

The following attestation bundles were made for user_permission-0.5.3-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:

Publisher: release.yml on Mokuichi147/user-permission-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file user_permission-0.5.3-cp39-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for user_permission-0.5.3-cp39-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 1aac809d9be07adf57c8a8ebb6d6aa1942f0e027221ff536e3568b9faca66042
MD5 3689f22f30ddf03df745a046d7ccb7d4
BLAKE2b-256 9cfc2bbd4e3ae8af1b0225ebcbaadb47dbf30de008a224b1ac29261e1410df9e

See more details on using hashes here.

Provenance

The following attestation bundles were made for user_permission-0.5.3-cp39-abi3-macosx_11_0_arm64.whl:

Publisher: release.yml on Mokuichi147/user-permission-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file user_permission-0.5.3-cp39-abi3-macosx_10_12_x86_64.whl.

File metadata

File hashes

Hashes for user_permission-0.5.3-cp39-abi3-macosx_10_12_x86_64.whl
Algorithm Hash digest
SHA256 a3fc8b7774deffee4953edf3f034f63b71b7260bf03288e6ba914a91738787ad
MD5 5fef41ac3d8078c55770de08668c3847
BLAKE2b-256 0daa8f47b25fd96d21865598cf84a89373c575892ef173b0d0bee2a817a23382

See more details on using hashes here.

Provenance

The following attestation bundles were made for user_permission-0.5.3-cp39-abi3-macosx_10_12_x86_64.whl:

Publisher: release.yml on Mokuichi147/user-permission-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page