data:image/s3,"s3://crabby-images/2523c/2523ce4b8b64bade795ffc89574cfc29f35428d3" alt="Deno 2.2 Improves Dependency Management and Expands Node.js Compatibility"
Security News
Deno 2.2 Improves Dependency Management and Expands Node.js Compatibility
Deno 2.2 enhances Node.js compatibility, improves dependency management, adds OpenTelemetry support, and expands linting and task automation for developers.
This project provides a simple Python library for securing Flask APIs with JWT authentication.
Secure endpoints are accessed by passing a JSON Web Token (JWT).
The follow Python decorators are available for use on Flask API endpoints.
private
- Secures an API endpoint. Requests to the endpoint will return a 401 Unauthorized
response unless a valid JWT is attached to the HTTP request. The JWT must be sent as a bearer token in the standard authorization header: Authorization: Bearer <token>
.public
- This is a marker decorator to identify an endpoint as intentionally public.The following example shows how to secure a private endpoint for a simple API built with the Flask RESTful framework. In this example, requests to the resource will return a 401 Unauthorized
response unless a valid JWT token is attached to the HTTP request.
from flask_restful import Resource
from ibm_flask_jwt.decorators import private
class PrivateApi(Resource):
@private
def get(self):
return 'Success'
The following environment variables are loaded by the library:
JWT_PUBLIC_KEY
- (Required) RSA256 public key for JWT signature verification.Use Pipenv for managing dependencies. Install all dependencies with pipenv install --dev
.
Run the unit tests with code coverage with pipenv run pytest --cov lib test
.
Run the build.py
file to generate the setup.py
file. This allows us to read the required dependencies from Pipfile.lock
so they are available in the install_requires
configuration field of setup.py
.
FAQs
A simple library for securing Flask REST APIs with JWTs using decorators
We found that ibm-flask-jwt demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Deno 2.2 enhances Node.js compatibility, improves dependency management, adds OpenTelemetry support, and expands linting and task automation for developers.
Security News
React's CRA deprecation announcement sparked community criticism over framework recommendations, leading to quick updates acknowledging build tools like Vite as valid alternatives.
Security News
Ransomware payment rates hit an all-time low in 2024 as law enforcement crackdowns, stronger defenses, and shifting policies make attacks riskier and less profitable.