Skip to main content

sessions for aiohttp.web

Project description

aiohttp_session

The library provides sessions for aiohttp.web.

Usage

The library allows to store user-specific data into session object.

The session object has dict-like interface (operations like session[key] = value, value = session[key] etc. are present).

Before processing session in web-handler you have to register session middleware in aiohttp.web.Application.

A trivial usage example:

import asyncio
import time
import base64
from cryptography import fernet
from aiohttp import web
from aiohttp_session import setup, get_session, session_middleware
from aiohttp_session.cookie_storage import EncryptedCookieStorage

async def handler(request):
    session = await get_session(request)
    last_visit = session['last_visit'] if 'last_visit' in session else None
    text = 'Last visited: {}'.format(last_visit)
    return web.Response(body=text.encode('utf-8'))

def make_app():
    app = web.Application()
    # secret_key must be 32 url-safe base64-encoded bytes
    fernet_key = fernet.Fernet.generate_key()
    secret_key = base64.urlsafe_b64decode(fernet_key)
    setup(app, EncryptedCookieStorage(secret_key))
    app.router.add_route('GET', '/', handler)
    return app

web.run_app(make_app())

All storages uses HTTP Cookie named AIOHTTP_COOKIE_SESSION for storing data.

Available session storages are:

  • aiohttp_session.SimpleCookieStorage() – keeps session data as plain JSON string in cookie body. Use the storage only for testing purposes, it’s very non-secure.

  • aiohttp_session.cookie_storage.EncryptedCookieStorage(secret_key) – stores session data into cookies as SimpleCookieStorage but encodes it via AES cipher. secrect_key is a bytes key for AES encryption/decryption, the length should be 32 bytes.

    Requires cryptography library:

    $ pip install aiohttp_session[secure]
  • aiohttp_session.redis_storage.RedisStorage(redis_pool) – stores JSON-ed data into redis, keepeng into cookie only redis key (random UUID). redis_pool is aioredis pool object, created by yield from aioredis.create_pool(...) call.

    Requires aioredis library:

    $ pip install aiohttp_session[aioredis]

License

aiohttp_session is offered under the Apache 2 license.

Changes

0.8.0 (2016-12-04)

  • Use time.time() instead of time.monotonic() for absolute times #81

0.7.0 (2016-09-24)

  • Fix tests to be compatible with aiohttp upstream API for client cookies

0.6.0 (2016-09-08)

  • Add expires field automatically to support older browsers #43

  • Respect session.max_age in redis storage #45

  • Always pass default max_age from storage into session #45

0.5.0 (2016-02-21)

  • Handle cryptography.fernet.InvalidToken exception by providing an empty session #29

0.4.0 (2016-01-06)

  • Add optional NaCl encrypted storage #20

  • Relax EncryptedCookieStorage to accept base64 encoded string, e.g. generated by Fernet.generate_key.

  • Add setup() function

  • Save the session even on exception in the middleware chain

0.3.0 (2015-11-20)

  • Reflect aiohttp changes: minimum required Python version is 3.4.1

  • Use explicit ‘aiohttp_session’ package

0.2.0 (2015-09-07)

  • Add session.created property #14

  • Replaced PyCrypto with crypthography library #16

0.1.2 (2015-08-07)

  • Add manifest file #15

0.1.1 (2015-04-20)

  • Fix #7: stop cookie name growing each time session is saved

0.1.0 (2015-04-13)

  • First public release

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

aiohttp-session-0.8.0.tar.gz (91.7 kB view details)

Uploaded Source

Built Distribution

aiohttp_session-0.8.0-py3-none-any.whl (10.3 kB view details)

Uploaded Python 3

File details

Details for the file aiohttp-session-0.8.0.tar.gz.

File metadata

File hashes

Hashes for aiohttp-session-0.8.0.tar.gz
Algorithm Hash digest
SHA256 256b13e47797b4b66188264782f7d89ceaa4a225db0342823aa14c2c0ba4f370
MD5 e0381b7203d65fc0be362d77a206ed1b
BLAKE2b-256 4f99c324dd62926f6cfefc3466f1e8b79104599959389ab1264515d1408dc38f

See more details on using hashes here.

Provenance

File details

Details for the file aiohttp_session-0.8.0-py3-none-any.whl.

File metadata

File hashes

Hashes for aiohttp_session-0.8.0-py3-none-any.whl
Algorithm Hash digest
SHA256 23316f114ed3bfbe936c6afea987d20ec95d7da322643ce1ec99a33373dd129f
MD5 7ccebe4c5fdc3a4ff8a175bf58f66c4e
BLAKE2b-256 9cbbe54fcbd084baa42b26afb65f499aa7b623c2803b75b835d19891b0431e39

See more details on using hashes here.

Provenance

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page