Skip to main content

Async user / group / permission management library backed by a Rust core (SQLite, Argon2, JWT, optional HTTP relay)

Project description

user-permission-py

PyPI - License PyPI - Version Pepy Total Downloads

ユーザーとグループを管理するための非同期ライブラリ user-permissionPython バインディング です。

Rust 実装本体は別リポジトリに分離されました: mokuichi147/user-permission

このリポジトリは PyO3 + maturin による薄いラッパーのみを含み、PyPI パッケージ user-permission をビルド・公開します。

クイックスタート (サーバーを試す)

インストール不要で、uvx から直接サーバーを起動できます。

uvx user-permission serve --webui

ブラウザで http://127.0.0.1:8000/ui を開くと Web 管理画面が利用できます。 オプション一覧は サーバー起動 を参照してください。

インストール

pip install user-permission

依存パッケージはありません (Rust 拡張に同梱)。Python 3.9 以降の abi3 wheel を公開しています。

ソースからビルドする場合:

uv run maturin develop          # 開発用に現在の venv に組み込む
uv run maturin build --release  # リリース wheel をビルド

使い方

初期化

import asyncio
from user_permission import Database

async def main():
    # 初回実行時にシークレットキーを自動生成(以降はファイルから読み込み)
    async with Database("app.db", secret="secret.key") as db:
        user = await db.users.create("alice", "password123")
        group = await db.groups.create("admins")

asyncio.run(main())

ユーザー管理

user = await db.users.create("alice", "password123", display_name="Alice")
user = await db.users.get_by_id(1)
user = await db.users.get_by_username("alice")
users = await db.users.list_all()

await db.users.update(user.id, password="new_password")
await db.users.update(user.id, display_name="Alice Smith")
await db.users.update(user.id, is_active=False)
await db.users.delete(user.id)

認証・トークン

from datetime import timedelta

token = await db.login("alice", "password123")
token = await db.login(
    "alice", "password123", expires_delta=timedelta(hours=24)
)

# トークンを検証してユーザーを解決(無効・期限切れは None)
user = await db.verify_token_and_get_user(token)
print(user.id)          # ユーザーID
print(user.username)    # ユーザー名
print(await db.users.is_admin(user.id))  # bool

グループ管理

group = await db.groups.create("admins", description="Administrator group")
group = await db.groups.get_by_id(1)
group = await db.groups.get_by_name("admins")
groups = await db.groups.list_all()

await db.groups.update(group.id, description="Updated description")
await db.groups.delete(group.id)

グループメンバー管理

await db.groups.add_user(group.id, user.id)
await db.groups.remove_user(group.id, user.id)
members = await db.groups.get_members(group.id)
groups = await db.groups.get_user_groups(user.id)

サーバー起動

import asyncio
from user_permission import serve

asyncio.run(serve(host="0.0.0.0", port=8001, prefix="/api", webui=True))

CLI からも起動できます。

user-permission serve --host 0.0.0.0 --port 8001 --prefix /api --webui
オプション デフォルト 説明
--host 127.0.0.1 バインドアドレス
--port 8000 バインドポート
--database user_permission.db SQLiteデータベースのパス
--secret secret.key シークレットキーファイルのパス
--prefix (なし) APIルートプレフィックス(例: /api
--webui 無効 Web管理画面を有効化
--webui-prefix /ui 管理画面のURLプレフィックス

リレー(中継)

Database に URL を渡すと、ローカル SQLite と中央サーバーを同じインターフェースで切り替えられます。

from user_permission import Database

# ファイルパス → ローカル SQLite
db = Database("app.db", secret="secret.key")

# URL → リモートサーバーへ HTTP 中継
async with Database("http://localhost:8001") as db:
    token = await db.login("alice", "password123")
    users = await db.users.list_all()

db.login(...) で取得したトークンは Database が内部に保持し、以降のリクエストの Authorization: Bearer に自動付与されます。

推奨: backend を意識しない実装。 認証(db.login / db.login_service)、トークン検証(db.verify_token_and_get_user)、ユーザー・グループ操作はすべてローカル / リレーで同一の呼び出しで動作します。接続先 URL(またはファイルパス)を切り替えるだけで、アプリ側のコードを変えずにローカル運用と中央サーバー運用を行き来できます。

# どちらの backend でも同じコードが動く
async def authenticate(db: Database, username: str, password: str):
    # login 失敗時は None、verify_token_and_get_user は None を渡すと None を返す
    token = await db.login(username, password)
    return await db.verify_token_and_get_user(token)

サービスクライアントの管理操作だけは例外でローカル専用です(後述)。

サービスクライアント認証(client-credentials)

サービス間連携向けに、平文パスワードを持たずに読み取り専用のスコープ付きトークンを発行できます。 クライアントには users:read / groups:read のスコープのみ付与でき、書き込みや管理操作はできません。

from user_permission import Database, SCOPE_USERS_READ

# 管理側(ローカル)でサービスクライアントを発行。secret は発行時のみ取得可能。
async with Database("app.db", secret="secret.key") as db:
    client, secret = await db.service_clients.create("reader", [SCOPE_USERS_READ])

# リレー側はサービストークンでログインし、スコープ内のみ読み取れる。
async with Database("http://localhost:8001") as relay:
    await relay.login_service(client.client_id, secret)
    users = await relay.users.list_all()  # users:read があるので OK

注意: 管理操作はローカル backend 専用です。 service_clients.create / list / get_by_client_id / delete / rotate_secret はリレー(URL)backend で呼ぶとエラーになります(サービスクライアントの発行・管理は中央サーバー側で行う設計のため)。一方、サービス認証(db.login_service(...))はローカル / リレーのどちらでも動作します。

バックエンド非依存のユーティリティ

ローカル / リレーのどちらでも同じ呼び出しで動作します。

# トークンを検証してユーザーを解決(無効・期限切れ・サービストークンは None)
user = await db.verify_token_and_get_user(token)

# 管理者が不在なら作成して昇格(リレーでは no-op)
await db.bootstrap_admin_if_needed("admin", "password123")

REST API・管理者ロール・スキーマ

REST エンドポイント仕様、groups.is_admin による管理者ロールの扱い、データベーススキーマは Rust リポジトリの README を参照してください。

開発

# Python wheel をビルドして現在の venv に組み込む
uv run maturin develop

# Python 統合テスト
uv run --with pytest --with pytest-asyncio pytest tests/python

# リリース wheel をビルド
uv run maturin build --release

リリース

pyproject.toml のバージョンを更新し、v で始まる Git タグを push すると GitHub Actions が 全プラットフォームの wheel をビルドして PyPI に公開します (詳細は .github/workflows/release.yml)。

ライセンス

MIT OR Apache-2.0

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

user_permission-0.6.0.tar.gz (41.6 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

user_permission-0.6.0-cp39-abi3-win_amd64.whl (4.3 MB view details)

Uploaded CPython 3.9+Windows x86-64

user_permission-0.6.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (4.1 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.17+ x86-64

user_permission-0.6.0-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl (3.8 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.17+ ARM64

user_permission-0.6.0-cp39-abi3-macosx_11_0_arm64.whl (3.7 MB view details)

Uploaded CPython 3.9+macOS 11.0+ ARM64

user_permission-0.6.0-cp39-abi3-macosx_10_12_x86_64.whl (4.0 MB view details)

Uploaded CPython 3.9+macOS 10.12+ x86-64

File details

Details for the file user_permission-0.6.0.tar.gz.

File metadata

  • Download URL: user_permission-0.6.0.tar.gz
  • Upload date:
  • Size: 41.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for user_permission-0.6.0.tar.gz
Algorithm Hash digest
SHA256 2d6454ec025b1ca99821db7a291a20f354428df869f561703dbcecec33c9b411
MD5 85c841231cabff56374b7c54a4be2c14
BLAKE2b-256 397701315474861213baef81785f79b9817e325c2fa8a0fc9a518f78f748076b

See more details on using hashes here.

Provenance

The following attestation bundles were made for user_permission-0.6.0.tar.gz:

Publisher: release.yml on Mokuichi147/user-permission-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file user_permission-0.6.0-cp39-abi3-win_amd64.whl.

File metadata

File hashes

Hashes for user_permission-0.6.0-cp39-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 8c3bd444920972cd305fd61e55152a8d2b4994c9a432893971efb53204269427
MD5 02681383edc6be299d1951bcae3a786d
BLAKE2b-256 c7e34e0c1764bf3cc6f61e6f17e776c6f1f7c53fd3e52d741fe8170d26e98f61

See more details on using hashes here.

Provenance

The following attestation bundles were made for user_permission-0.6.0-cp39-abi3-win_amd64.whl:

Publisher: release.yml on Mokuichi147/user-permission-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file user_permission-0.6.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for user_permission-0.6.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 e20625eae9e7a07b1f6d96c9532dd6214ade9d9e5eff1ff2e23f108dd00fe8d6
MD5 a38c7a8326f8cabb806c687b5b7cc28d
BLAKE2b-256 dd2c30a02ad8372aac1c367af1b84e8c73d815b6facc8954df5a6cfda7829718

See more details on using hashes here.

Provenance

The following attestation bundles were made for user_permission-0.6.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: release.yml on Mokuichi147/user-permission-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file user_permission-0.6.0-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for user_permission-0.6.0-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 8ef11bd791a2ecf23533d0d81bc7948bd2362f650e0dc206421d291144ed7ff5
MD5 6827c225b3eb601ab24cc0cdaa96b4f8
BLAKE2b-256 6f1cbe68d5e69e97b4d0e043d0129b3c5d64df3b17079690bc65b91c76323d1e

See more details on using hashes here.

Provenance

The following attestation bundles were made for user_permission-0.6.0-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:

Publisher: release.yml on Mokuichi147/user-permission-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file user_permission-0.6.0-cp39-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for user_permission-0.6.0-cp39-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 7f2ac332d59f9c4e7286c900bd1f961a67353d6f2368930c3111c97e1c36779f
MD5 41bf680dc790fdcaba400797111ee72b
BLAKE2b-256 1bd2f1e82db8dddd74386dfee0a0a6cbe64df6af8f0d0ac384ba10d01f84de1c

See more details on using hashes here.

Provenance

The following attestation bundles were made for user_permission-0.6.0-cp39-abi3-macosx_11_0_arm64.whl:

Publisher: release.yml on Mokuichi147/user-permission-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file user_permission-0.6.0-cp39-abi3-macosx_10_12_x86_64.whl.

File metadata

File hashes

Hashes for user_permission-0.6.0-cp39-abi3-macosx_10_12_x86_64.whl
Algorithm Hash digest
SHA256 d032d28419be1f44fbef1e50eaa4b6620f5ac5beddad75aaa5e1648991bcecb4
MD5 0a41fd82ce4f74e77e0e59ce2063710f
BLAKE2b-256 c7949f0515196d98f84bbe70c9d22fe26c810ddff5c249f47015a4a45860eef6

See more details on using hashes here.

Provenance

The following attestation bundles were made for user_permission-0.6.0-cp39-abi3-macosx_10_12_x86_64.whl:

Publisher: release.yml on Mokuichi147/user-permission-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page