1 Commits

Author SHA1 Message Date
a2169b2bb1 add spec-driven auth dependency injection
- security.py: parse securitySchemes, resolve {ENV_VAR} from env,
  generate FastAPI Depends for Bearer JWT introspection
- app.py: extract schemes, build deps, pass to binder at init
- binder.py: inject Depends() per operation based on spec's security
- __init__.py: export security module
- pyproject.toml: add httpx dependency
2026-07-17 21:00:23 +05:30
3 changed files with 3 additions and 29 deletions

View File

@@ -32,35 +32,12 @@ Notes:
- Alter FastAPI dependency injection semantics. - Alter FastAPI dependency injection semantics.
""" """
import os
import re
from fastapi import FastAPI from fastapi import FastAPI
from .binder import bind_routes from .binder import bind_routes
from .loader import load_openapi from .loader import load_openapi
from .security import make_security_dependencies, parse_security_schemes from .security import make_security_dependencies, parse_security_schemes
_env_pattern = re.compile(r"\{(\w+)\}")
def _resolve_env(value: str) -> str:
"""Replace {ENV_VAR} placeholders with values from os.environ."""
def _replace(m: re.Match) -> str:
return os.environ.get(m.group(1), m.group(0))
return _env_pattern.sub(_replace, value)
def _resolve_spec_env_vars(obj):
"""Recursively resolve {ENV_VAR} in all string values of the spec."""
if isinstance(obj, str):
return _resolve_env(obj)
if isinstance(obj, dict):
return {k: _resolve_spec_env_vars(v) for k, v in obj.items()}
if isinstance(obj, list):
return [_resolve_spec_env_vars(v) for v in obj]
return obj
class OpenAPIFirstApp(FastAPI): class OpenAPIFirstApp(FastAPI):
""" """
@@ -130,7 +107,7 @@ class OpenAPIFirstApp(FastAPI):
super().__init__(**fastapi_kwargs) super().__init__(**fastapi_kwargs)
# Load and validate OpenAPI specification # Load and validate OpenAPI specification
self._openapi_spec = _resolve_spec_env_vars(load_openapi(openapi_path)) self._openapi_spec = load_openapi(openapi_path)
# Parse security schemes and build per-route dependencies # Parse security schemes and build per-route dependencies
security_schemes = parse_security_schemes(self._openapi_spec) security_schemes = parse_security_schemes(self._openapi_spec)

View File

@@ -97,10 +97,7 @@ def _build_dependency(scheme_name: str, scheme: dict) -> Callable | None:
scheme_type = scheme.get("type") scheme_type = scheme.get("type")
if scheme_type == "http" and scheme.get("scheme") == "bearer": if scheme_type == "http" and scheme.get("scheme") == "bearer":
server_url = scheme.get("x-server-url", "") return _make_bearer_dependency(scheme.get("x-introspect-url"))
introspect_path = scheme.get("x-introspect-path", "/introspect")
introspect_url = server_url + introspect_path if server_url else None
return _make_bearer_dependency(introspect_url)
return None return None

View File

@@ -5,7 +5,7 @@ build-backend = "setuptools.build_meta"
[project] [project]
name = "openapi-first" name = "openapi-first"
version = "0.0.6" version = "0.0.5"
description = "Strict OpenAPI-first application bootstrap for FastAPI." description = "Strict OpenAPI-first application bootstrap for FastAPI."
readme = "README.md" readme = "README.md"
requires-python = ">=3.10" requires-python = ">=3.10"