Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
The Onebusaway SDK Python library provides convenient access to the Onebusaway SDK REST API from any Python 3.8+
application. The library includes type definitions for all request params and response fields, and offers both synchronous and asynchronous clients powered by httpx.
It is generated with Stainless.
The REST API documentation can be found on developer.onebusaway.org. The full API of this library can be found in api.md.
# install from PyPI
pip install onebusaway
The full API of this library can be found in api.md.
import os
from onebusaway import OnebusawaySDK
client = OnebusawaySDK(
api_key=os.environ.get("ONEBUSAWAY_API_KEY"), # This is the default and can be omitted
)
current_time = client.current_time.retrieve()
While you can provide an api_key
keyword argument,
we recommend using python-dotenv
to add ONEBUSAWAY_API_KEY="My API Key"
to your .env
file
so that your API Key is not stored in source control.
Simply import AsyncOnebusawaySDK
instead of OnebusawaySDK
and use await
with each API call:
import os
import asyncio
from onebusaway import AsyncOnebusawaySDK
client = AsyncOnebusawaySDK(
api_key=os.environ.get("ONEBUSAWAY_API_KEY"), # This is the default and can be omitted
)
async def main() -> None:
current_time = await client.current_time.retrieve()
asyncio.run(main())
Functionality between the synchronous and asynchronous clients is otherwise identical.
Nested request parameters are TypedDicts. Responses are Pydantic models which also provide helper methods for things like:
model.to_json()
model.to_dict()
Typed requests and responses provide autocomplete and documentation within your editor. If you would like to see type errors in VS Code to help catch bugs earlier, set python.analysis.typeCheckingMode
to basic
.
When the library is unable to connect to the API (for example, due to network connection problems or a timeout), a subclass of onebusaway.APIConnectionError
is raised.
When the API returns a non-success status code (that is, 4xx or 5xx
response), a subclass of onebusaway.APIStatusError
is raised, containing status_code
and response
properties.
All errors inherit from onebusaway.APIError
.
import onebusaway
from onebusaway import OnebusawaySDK
client = OnebusawaySDK()
try:
client.current_time.retrieve()
except onebusaway.APIConnectionError as e:
print("The server could not be reached")
print(e.__cause__) # an underlying Exception, likely raised within httpx.
except onebusaway.RateLimitError as e:
print("A 429 status code was received; we should back off a bit.")
except onebusaway.APIStatusError as e:
print("Another non-200-range status code was received")
print(e.status_code)
print(e.response)
Error codes are as followed:
Status Code | Error Type |
---|---|
400 | BadRequestError |
401 | AuthenticationError |
403 | PermissionDeniedError |
404 | NotFoundError |
422 | UnprocessableEntityError |
429 | RateLimitError |
>=500 | InternalServerError |
N/A | APIConnectionError |
Certain errors are automatically retried 2 times by default, with a short exponential backoff. Connection errors (for example, due to a network connectivity problem), 408 Request Timeout, 409 Conflict, 429 Rate Limit, and >=500 Internal errors are all retried by default.
You can use the max_retries
option to configure or disable retry settings:
from onebusaway import OnebusawaySDK
# Configure the default for all requests:
client = OnebusawaySDK(
# default is 2
max_retries=0,
)
# Or, configure per-request:
client.with_options(max_retries=5).current_time.retrieve()
By default requests time out after 1 minute. You can configure this with a timeout
option,
which accepts a float or an httpx.Timeout
object:
from onebusaway import OnebusawaySDK
# Configure the default for all requests:
client = OnebusawaySDK(
# 20 seconds (default is 1 minute)
timeout=20.0,
)
# More granular control:
client = OnebusawaySDK(
timeout=httpx.Timeout(60.0, read=5.0, write=10.0, connect=2.0),
)
# Override per-request:
client.with_options(timeout=5.0).current_time.retrieve()
On timeout, an APITimeoutError
is thrown.
Note that requests that time out are retried twice by default.
We use the standard library logging
module.
You can enable logging by setting the environment variable ONEBUSAWAY_SDK_LOG
to info
.
$ export ONEBUSAWAY_SDK_LOG=info
Or to debug
for more verbose logging.
None
means null
or missingIn an API response, a field may be explicitly null
, or missing entirely; in either case, its value is None
in this library. You can differentiate the two cases with .model_fields_set
:
if response.my_field is None:
if 'my_field' not in response.model_fields_set:
print('Got json like {}, without a "my_field" key present at all.')
else:
print('Got json like {"my_field": null}.')
The "raw" Response object can be accessed by prefixing .with_raw_response.
to any HTTP method call, e.g.,
from onebusaway import OnebusawaySDK
client = OnebusawaySDK()
response = client.current_time.with_raw_response.retrieve()
print(response.headers.get('X-My-Header'))
current_time = response.parse() # get the object that `current_time.retrieve()` would have returned
print(current_time)
These methods return an APIResponse
object.
The async client returns an AsyncAPIResponse
with the same structure, the only difference being await
able methods for reading the response content.
.with_streaming_response
The above interface eagerly reads the full response body when you make the request, which may not always be what you want.
To stream the response body, use .with_streaming_response
instead, which requires a context manager and only reads the response body once you call .read()
, .text()
, .json()
, .iter_bytes()
, .iter_text()
, .iter_lines()
or .parse()
. In the async client, these are async methods.
with client.current_time.with_streaming_response.retrieve() as response:
print(response.headers.get("X-My-Header"))
for line in response.iter_lines():
print(line)
The context manager is required so that the response will reliably be closed.
This library is typed for convenient access to the documented API.
If you need to access undocumented endpoints, params, or response properties, the library can still be used.
To make requests to undocumented endpoints, you can make requests using client.get
, client.post
, and other
http verbs. Options on the client will be respected (such as retries) will be respected when making this
request.
import httpx
response = client.post(
"/foo",
cast_to=httpx.Response,
body={"my_param": True},
)
print(response.headers.get("x-foo"))
If you want to explicitly send an extra param, you can do so with the extra_query
, extra_body
, and extra_headers
request
options.
To access undocumented response properties, you can access the extra fields like response.unknown_prop
. You
can also get all the extra fields on the Pydantic model as a dict with
response.model_extra
.
You can directly override the httpx client to customize it for your use case, including:
import httpx
from onebusaway import OnebusawaySDK, DefaultHttpxClient
client = OnebusawaySDK(
# Or use the `ONEBUSAWAY_SDK_BASE_URL` env var
base_url="http://my.test.server.example.com:8083",
http_client=DefaultHttpxClient(
proxy="http://my.test.proxy.example.com",
transport=httpx.HTTPTransport(local_address="0.0.0.0"),
),
)
You can also customize the client on a per-request basis by using with_options()
:
client.with_options(http_client=DefaultHttpxClient(...))
By default the library closes underlying HTTP connections whenever the client is garbage collected. You can manually close the client using the .close()
method if desired, or with a context manager that closes when exiting.
This package generally follows SemVer conventions, though certain backwards-incompatible changes may be released as minor versions:
We take backwards-compatibility seriously and work hard to ensure you can rely on a smooth upgrade experience.
We are keen for your feedback; please open an issue with questions, bugs, or suggestions.
If you've upgraded to the latest version but aren't seeing any new features you were expecting then your python environment is likely still using an older version.
You can determine the version that is being used at runtime with:
import onebusaway
print(onebusaway.__version__)
Python 3.8 or higher.
FAQs
The official Python library for the onebusaway-sdk API
We found that onebusaway demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.