forked from Significant-Gravitas/AutoGPT
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat(server): Add JWT validation (Significant-Gravitas#7642)
* add auth middleware * update readnme * Update rnd/autogpt_server/pyproject.toml Co-authored-by: Krzysztof Czerwinski <[email protected]> * address newline feedback * update poetry lock --------- Co-authored-by: Krzysztof Czerwinski <[email protected]>
- Loading branch information
1 parent
ac45b7c
commit b23bd9c
Showing
13 changed files
with
165 additions
and
3 deletions.
There are no files selected for viewing
Empty file.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,3 @@ | ||
# AutoGPT Libs | ||
|
||
This is a new project to store shared functionality across different services in NextGen AutoGPT (e.g. authentication) |
Empty file.
Empty file.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,16 @@ | ||
import os | ||
from dotenv import load_dotenv | ||
|
||
load_dotenv() | ||
|
||
class Settings: | ||
JWT_SECRET_KEY: str = os.getenv("SUPABASE_JWT_SECRET", "") | ||
ENABLE_AUTH: bool = os.getenv("ENABLE_AUTH", "false").lower() == "true" | ||
JWT_ALGORITHM: str = "HS256" | ||
|
||
@property | ||
def is_configured(self) -> bool: | ||
return bool(self.JWT_SECRET_KEY) | ||
|
||
|
||
settings = Settings() |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,20 @@ | ||
import jwt | ||
from typing import Dict, Any | ||
from .config import settings | ||
|
||
|
||
def parse_jwt_token(token: str) -> Dict[str, Any]: | ||
""" | ||
Parse and validate a JWT token. | ||
:param token: The token to parse | ||
:return: The decoded payload | ||
:raises ValueError: If the token is invalid or expired | ||
""" | ||
try: | ||
payload = jwt.decode(token, settings.JWT_SECRET_KEY, algorithms=[settings.JWT_ALGORITHM]) | ||
return payload | ||
except jwt.ExpiredSignatureError: | ||
raise ValueError("Token has expired") | ||
except jwt.InvalidTokenError as e: | ||
raise ValueError(f"Invalid token: {str(e)}") |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,26 @@ | ||
import logging | ||
|
||
from fastapi import Request, HTTPException, Depends | ||
from fastapi.security import HTTPBearer, HTTPAuthorizationCredentials | ||
from .jwt_utils import parse_jwt_token | ||
from .config import settings | ||
|
||
security = HTTPBearer() | ||
async def auth_middleware(request: Request): | ||
if not settings.ENABLE_AUTH: | ||
# If authentication is disabled, allow the request to proceed | ||
return {} | ||
|
||
security = HTTPBearer() | ||
credentials = await security(request) | ||
|
||
if not credentials: | ||
raise HTTPException(status_code=401, detail="Authorization header is missing") | ||
|
||
try: | ||
payload = parse_jwt_token(credentials.credentials) | ||
request.state.user = payload | ||
logging.info("Token decoded successfully") | ||
except ValueError as e: | ||
raise HTTPException(status_code=401, detail=str(e)) | ||
return payload |
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,17 @@ | ||
[tool.poetry] | ||
name = "autogpt-libs" | ||
version = "0.1.0" | ||
description = "Shared libraries across NextGen AutoGPT" | ||
authors = ["Aarushi <[email protected]>"] | ||
readme = "README.md" | ||
packages = [{ include = "autogpt_libs" }] | ||
|
||
[tool.poetry.dependencies] | ||
python = ">=3.10,<4.0" | ||
pyjwt = "^2.8.0" | ||
python-dotenv = "^1.0.1" | ||
|
||
|
||
[build-system] | ||
requires = ["poetry-core"] | ||
build-backend = "poetry.core.masonry.api" |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters