@@ -119,3 +119,98 @@ You can also set the default CORS headers for all endpoints with Flask applicati
119119
120120 .. note ::
121121 These default configs will be overridden by the decorator *cors_options * for specific endpoints.
122+
123+
124+ FastAPI
125+ =======
126+
127+ Usage
128+ -----
129+
130+ To use iam-python-sdk on FastAPI frameworks, you have to init the iam-python-sdk when FastAPI app started:
131+
132+ .. code-block :: python
133+
134+ from fastapi import FastAPI
135+ from iam_python_sdk.fastapi import IAM , Settings
136+
137+ app = FastAPI()
138+
139+ @app.on_event (" startup" )
140+ async def startup_event ():
141+ config = Settings(
142+ iam_base_url = " <Base IAM URL>" ,
143+ iam_client_id = " <Client ID>" ,
144+ iam_client_secret = " <Client Secret>" ,
145+ )
146+ app.state.iam = IAM(app, config)
147+
148+ Then you can protect your endpoint with *permission_required * dependency from unauthorized access:
149+
150+ .. code-block :: python
151+
152+ from iam- python- sdk.fastapi import permission_required
153+
154+ @app.get (' /protected' , dependencies = [
155+ Depends(
156+ permission_required(
157+ {" resource" : " ADMIN:NAMESPACE:{namespace} :CLIENT" , " action" : 2 },
158+ {" {namespace} " : " sdktest" },
159+ csrf_protect = True
160+ )
161+ )
162+ ])
163+ def get_protected_endpoint ():
164+ return ' You have authorized access!'
165+
166+ By default, *permission_required * dependency will check the access token on the Authorization header with Bearer type.
167+ You can customize these default configurations according to your service/apps needs:
168+
169+ .. code-block :: python
170+
171+ settings.iam_base_url = " "
172+ settings.iam_client_id = " "
173+ settings.iam_client_secret = " "
174+ settings.iam_token_locations = [" headers" , " cookies" ]
175+ settings.iam_token_header_name = " Authorization"
176+ settings.iam_token_header_type = " Bearer"
177+ settings.iam_token_cookie_name = " access_token"
178+ settings.iam_token_cookie_path = " /"
179+ settings.iam_csrf_protection = True
180+ settings.iam_strict_referer = True
181+
182+ .. note ::
183+ This module has been tested with FastAPI default uvicorn server for development.
184+ For production use, this module has been tested with *Gunicorn *.
185+ You can use Gunicorn with ``uvicorn.workers.UvicornWorker `` class worker.
186+
187+ For more information about FastAPI deployment, please read more information `here <https://fastapi.tiangolo.com/deployment/server-workers/ >`_
188+
189+ CORS Middleware
190+ ---------------
191+
192+ This module support CORS middleware to set CORS header response. You can set the CORS headers with these settings.
193+
194+ .. code-block :: python
195+
196+ settings.iam_cors_enable = False
197+ settings.iam_cors_origin = " *"
198+ settings.iam_cors_headers = " *"
199+ settings.iam_cors_methods = " *"
200+ settings.iam_cors_credentials = True
201+
202+ The sample response of this endpoint would be like:
203+
204+ .. code-block :: console
205+
206+ HTTP/1.1 200 OK
207+ Date: Fri, 12 Nov 2021 01:15:39 GMT
208+ Server: Nginx
209+ Access-Control-Allow-Origin: *
210+ Access-Control-Allow-Methods: GET, POST, OPTIONS
211+ Access-Control-Allow-Headers: Device-Id, Device-Os, Device-Type
212+ Access-Control-Allow-Credentials: true
213+ .......
214+
215+ .. note ::
216+ You can read more about CORS specification `here <https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS >`_
0 commit comments