A Requests auth module for HTTP Message Signatures
Project description
requests-http-signature is a Requests authentication plugin (requests.auth.AuthBase subclass) implementing the IETF HTTP Message Signatures draft RFC.
Installation
$ pip install requests-http-signature
Usage
import requests
from requests_http_signature import HTTPSignatureAuth, algorithms
preshared_key_id = 'squirrel'
preshared_secret = b'monorail_cat'
url = 'http://example.com/path'
auth = HTTPSignatureAuth(key=preshared_secret,
key_id=preshared_key_id,
signature_algorithm=algorithms.HMAC_SHA256)
requests.get(url, auth=auth)
By default, only the Date header and the @method, @authority, and @target-uri derived component identifiers are signed for body-less requests such as GET. The Date header is set if it is absent. In addition, for requests with bodies (such as POST), the Content-Digest header is set to the SHA256 of the request body using the format described in the IETF Digest Fields draft RFC and signed. To add other headers to the signature, pass an array of header names in the covered_component_ids keyword argument. See the API documentation for the full list of options and details.
Verifying responses
The class method HTTPSignatureAuth.verify() can be used to verify responses received back from the server:
class key_resolver:
def resolve_public_key(self, key_id):
assert key_id == 'squirrel'
return 'monorail_cat'
response = requests.get(url, auth=auth)
HTTPSignatureAuth.verify(response,
signature_algorithm=algorithms.HMAC_SHA256,
key_resolver=key_resolver)
More generally, you can reconstruct an arbitrary request using the Requests API and pass it to verify():
request = requests.Request(...) # Reconstruct the incoming request using the Requests API
prepared_request = request.prepare() # Generate a PreparedRequest
HTTPSignatureAuth.verify(prepared_request, ...)
To verify incoming requests and sign responses in the context of an HTTP server, see the flask-http-signature and http-message-signatures packages.
See the API documentation for full details.
Asymmetric key algorithms
To sign or verify messages with an asymmetric key algorithm, set the signature_algorithm keyword argument to algorithms.ED25519, algorithms.ECDSA_P256_SHA256, algorithms.RSA_V1_5_SHA256, or algorithms.RSA_PSS_SHA512. Note that signing with rsa-pss-sha512 is not currently supported due to a limitation of the cryptography library.
For asymmetric key algorithms, you can supply the private key as the key parameter to the HTTPSignatureAuth() constructor as bytes in the PEM format, or configure the key resolver as follows:
with open('key.pem', 'rb') as fh:
auth = HTTPSignatureAuth(algorithm=algorithms.RSA_V1_5_SHA256,
key=fh.read(),
key_id=preshared_key_id)
requests.get(url, auth=auth)
class MyKeyResolver:
def resolve_public_key(self, key_id: str):
return public_key_pem_bytes[key_id]
def resolve_private_key(self, key_id: str):
return private_key_pem_bytes[key_id]
auth = HTTPSignatureAuth(algorithm=algorithms.RSA_V1_5_SHA256,
key=fh.read(),
key_resolver=MyKeyResolver())
requests.get(url, auth=auth)
Digest algorithms
If you need to generate a Content-Digest header using SHA-512, you can do so via subclassing:
class MySigner(HTTPSignatureAuth): def add_digest(self, request): super().add_digest(request, algorithm="sha-512")
Links
http-message-signatures - a dependency of this library that handles much of the implementation
Bugs
Please report bugs, issues, feature requests, etc. on GitHub.
License
Licensed under the terms of the Apache License, Version 2.0.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file requests-http-signature-0.6.0.tar.gz
.
File metadata
- Download URL: requests-http-signature-0.6.0.tar.gz
- Upload date:
- Size: 18.5 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/3.4.1 importlib_metadata/4.6.0 pkginfo/1.7.0 requests/2.25.1 requests-toolbelt/0.9.1 tqdm/4.61.1 CPython/3.9.10
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 8205b8d1a31435f6af602fd5b1fec4886ef89b6731423c566a4756de684995af |
|
MD5 | 842efe0e741b2241f2c38165d3c88d45 |
|
BLAKE2b-256 | ab84b0d319c18bc80c766c498a3dbc849db88d4fce75d93edf8aec9914a5d641 |
File details
Details for the file requests_http_signature-0.6.0-py3-none-any.whl
.
File metadata
- Download URL: requests_http_signature-0.6.0-py3-none-any.whl
- Upload date:
- Size: 11.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/3.4.1 importlib_metadata/4.6.0 pkginfo/1.7.0 requests/2.25.1 requests-toolbelt/0.9.1 tqdm/4.61.1 CPython/3.9.10
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 8402bb76609b2444dd195c8c5b7f7d4233fc34807ea201a447f57fbaafa0ebf9 |
|
MD5 | ca888acf1d724cb82a460b89242fe299 |
|
BLAKE2b-256 | be0bf7b63b7ebeb98317c614981fdb9b8893817c406b5ba3133a10063bdb82bb |