mirror of
https://github.com/fastapi/fastapi.git
synced 2026-09-14 13:36:21 +08:00
05ca41cfd1
* ➕ Add mkdocstrings and griffe-typingdoc to dependencies * 🔧 Add mkdocstrings configs to MkDocs * 📝 Add first WIP reference page * ⬆️ Upgrade typing-extensions to the minimum version including Doc() * 📝 Add docs to FastAPI parameters * 📝 Add docstrings for OpenAPI docs utils * 📝 Add docstrings for security utils * 📝 Add docstrings for UploadFile * 📝 Update docstrings in FastAPI class * 📝 Add docstrings for path operation methods * 📝 Add docstring for jsonable_encoder * 📝 Add docstrings for exceptions * 📝 Add docstsrings for parameter functions * 📝 Add docstrings for responses * 📝 Add docstrings for APIRouter * ♻️ Sub-class BackgroundTasks to document it with docstrings * 📝 Update usage of background tasks in dependencies * ✅ Update tests with new deprecation warnings * 📝 Add new reference docs * 🔧 Update MkDocs with new reference docs * ✅ Update pytest fixture, deprecation is raised only once * 🎨 Update format for types in exceptions.py * ♻️ Update annotations in BackgroundTask, `Annotated` can't take ParamSpec's P.args or P.kwargs * ✏️ Fix typos caught by @pawamoy * 🔧 Update and fix MkDocstrings configs from @pawamoy tips * 📝 Update reference docs * ✏️ Fix typos found by @pawamoy * ➕ Add HTTPX as a dependency for docs, for the TestClient * 🔧 Update MkDocs config, rename websockets reference * 🔇 Add type-ignores for Doc as the stubs haven't been released for mypy * 🔥 Remove duplicated deprecated notice * 🔇 Remove typing error for unreleased stub in openapi/docs.py * ✅ Add tests for UploadFile for coverage * ⬆️ Upgrade griffe-typingdoc==0.2.2 * 📝 Refactor docs structure * 🔨 Update README generation with new index frontmatter and style * 🔨 Update generation of languages, remove from top menu, keep in lang menu * 📝 Add OpenAPI Pydantic models * 🔨 Update docs script to not translate Reference and Release Notes * 🔧 Add reference for OpenAPI models * 🔧 Update MkDocs config for mkdocstrings insiders * 👷 Install mkdocstring insiders in CI for docs * 🐛 Fix MkDocstrings insiders install URL * ➕ Move dependencies shared by docs and tests to its own requirements file * 👷 Update cache keys for test and docs dependencies * 📝 Remove no longer needed __init__ placeholder docstrings * 📝 Move docstring for APIRouter to the class level (not __init__ level) * 🔥 Remove no longer needed dummy placeholder __init__ docstring
302 lines
9.2 KiB
Python
302 lines
9.2 KiB
Python
from typing import Optional
|
|
|
|
from fastapi.openapi.models import APIKey, APIKeyIn
|
|
from fastapi.security.base import SecurityBase
|
|
from starlette.exceptions import HTTPException
|
|
from starlette.requests import Request
|
|
from starlette.status import HTTP_403_FORBIDDEN
|
|
from typing_extensions import Annotated, Doc # type: ignore [attr-defined]
|
|
|
|
|
|
class APIKeyBase(SecurityBase):
|
|
pass
|
|
|
|
|
|
class APIKeyQuery(APIKeyBase):
|
|
"""
|
|
API key authentication using a query parameter.
|
|
|
|
This defines the name of the query parameter that should be provided in the request
|
|
with the API key and integrates that into the OpenAPI documentation. It extracts
|
|
the key value sent in the query parameter automatically and provides it as the
|
|
dependency result. But it doesn't define how to send that API key to the client.
|
|
|
|
## Usage
|
|
|
|
Create an instance object and use that object as the dependency in `Depends()`.
|
|
|
|
The dependency result will be a string containing the key value.
|
|
|
|
## Example
|
|
|
|
```python
|
|
from fastapi import Depends, FastAPI
|
|
from fastapi.security import APIKeyQuery
|
|
|
|
app = FastAPI()
|
|
|
|
query_scheme = APIKeyQuery(name="api_key")
|
|
|
|
|
|
@app.get("/items/")
|
|
async def read_items(api_key: str = Depends(query_scheme)):
|
|
return {"api_key": api_key}
|
|
```
|
|
"""
|
|
|
|
def __init__(
|
|
self,
|
|
*,
|
|
name: Annotated[
|
|
str,
|
|
Doc("Query parameter name."),
|
|
],
|
|
scheme_name: Annotated[
|
|
Optional[str],
|
|
Doc(
|
|
"""
|
|
Security scheme name.
|
|
|
|
It will be included in the generated OpenAPI (e.g. visible at `/docs`).
|
|
"""
|
|
),
|
|
] = None,
|
|
description: Annotated[
|
|
Optional[str],
|
|
Doc(
|
|
"""
|
|
Security scheme description.
|
|
|
|
It will be included in the generated OpenAPI (e.g. visible at `/docs`).
|
|
"""
|
|
),
|
|
] = None,
|
|
auto_error: Annotated[
|
|
bool,
|
|
Doc(
|
|
"""
|
|
By default, if the query parameter is not provided, `APIKeyQuery` will
|
|
automatically cancel the request and sebd the client an error.
|
|
|
|
If `auto_error` is set to `False`, when the query parameter is not
|
|
available, instead of erroring out, the dependency result will be
|
|
`None`.
|
|
|
|
This is useful when you want to have optional authentication.
|
|
|
|
It is also useful when you want to have authentication that can be
|
|
provided in one of multiple optional ways (for example, in a query
|
|
parameter or in an HTTP Bearer token).
|
|
"""
|
|
),
|
|
] = True,
|
|
):
|
|
self.model: APIKey = APIKey(
|
|
**{"in": APIKeyIn.query}, # type: ignore[arg-type]
|
|
name=name,
|
|
description=description,
|
|
)
|
|
self.scheme_name = scheme_name or self.__class__.__name__
|
|
self.auto_error = auto_error
|
|
|
|
async def __call__(self, request: Request) -> Optional[str]:
|
|
api_key = request.query_params.get(self.model.name)
|
|
if not api_key:
|
|
if self.auto_error:
|
|
raise HTTPException(
|
|
status_code=HTTP_403_FORBIDDEN, detail="Not authenticated"
|
|
)
|
|
else:
|
|
return None
|
|
return api_key
|
|
|
|
|
|
class APIKeyHeader(APIKeyBase):
|
|
"""
|
|
API key authentication using a header.
|
|
|
|
This defines the name of the header that should be provided in the request with
|
|
the API key and integrates that into the OpenAPI documentation. It extracts
|
|
the key value sent in the header automatically and provides it as the dependency
|
|
result. But it doesn't define how to send that key to the client.
|
|
|
|
## Usage
|
|
|
|
Create an instance object and use that object as the dependency in `Depends()`.
|
|
|
|
The dependency result will be a string containing the key value.
|
|
|
|
## Example
|
|
|
|
```python
|
|
from fastapi import Depends, FastAPI
|
|
from fastapi.security import APIKeyHeader
|
|
|
|
app = FastAPI()
|
|
|
|
header_scheme = APIKeyHeader(name="x-key")
|
|
|
|
|
|
@app.get("/items/")
|
|
async def read_items(key: str = Depends(header_scheme)):
|
|
return {"key": key}
|
|
```
|
|
"""
|
|
|
|
def __init__(
|
|
self,
|
|
*,
|
|
name: Annotated[str, Doc("Header name.")],
|
|
scheme_name: Annotated[
|
|
Optional[str],
|
|
Doc(
|
|
"""
|
|
Security scheme name.
|
|
|
|
It will be included in the generated OpenAPI (e.g. visible at `/docs`).
|
|
"""
|
|
),
|
|
] = None,
|
|
description: Annotated[
|
|
Optional[str],
|
|
Doc(
|
|
"""
|
|
Security scheme description.
|
|
|
|
It will be included in the generated OpenAPI (e.g. visible at `/docs`).
|
|
"""
|
|
),
|
|
] = None,
|
|
auto_error: Annotated[
|
|
bool,
|
|
Doc(
|
|
"""
|
|
By default, if the header is not provided, `APIKeyHeader` will
|
|
automatically cancel the request and send the client an error.
|
|
|
|
If `auto_error` is set to `False`, when the header is not available,
|
|
instead of erroring out, the dependency result will be `None`.
|
|
|
|
This is useful when you want to have optional authentication.
|
|
|
|
It is also useful when you want to have authentication that can be
|
|
provided in one of multiple optional ways (for example, in a header or
|
|
in an HTTP Bearer token).
|
|
"""
|
|
),
|
|
] = True,
|
|
):
|
|
self.model: APIKey = APIKey(
|
|
**{"in": APIKeyIn.header}, # type: ignore[arg-type]
|
|
name=name,
|
|
description=description,
|
|
)
|
|
self.scheme_name = scheme_name or self.__class__.__name__
|
|
self.auto_error = auto_error
|
|
|
|
async def __call__(self, request: Request) -> Optional[str]:
|
|
api_key = request.headers.get(self.model.name)
|
|
if not api_key:
|
|
if self.auto_error:
|
|
raise HTTPException(
|
|
status_code=HTTP_403_FORBIDDEN, detail="Not authenticated"
|
|
)
|
|
else:
|
|
return None
|
|
return api_key
|
|
|
|
|
|
class APIKeyCookie(APIKeyBase):
|
|
"""
|
|
API key authentication using a cookie.
|
|
|
|
This defines the name of the cookie that should be provided in the request with
|
|
the API key and integrates that into the OpenAPI documentation. It extracts
|
|
the key value sent in the cookie automatically and provides it as the dependency
|
|
result. But it doesn't define how to set that cookie.
|
|
|
|
## Usage
|
|
|
|
Create an instance object and use that object as the dependency in `Depends()`.
|
|
|
|
The dependency result will be a string containing the key value.
|
|
|
|
## Example
|
|
|
|
```python
|
|
from fastapi import Depends, FastAPI
|
|
from fastapi.security import APIKeyCookie
|
|
|
|
app = FastAPI()
|
|
|
|
cookie_scheme = APIKeyCookie(name="session")
|
|
|
|
|
|
@app.get("/items/")
|
|
async def read_items(session: str = Depends(cookie_scheme)):
|
|
return {"session": session}
|
|
```
|
|
"""
|
|
|
|
def __init__(
|
|
self,
|
|
*,
|
|
name: Annotated[str, Doc("Cookie name.")],
|
|
scheme_name: Annotated[
|
|
Optional[str],
|
|
Doc(
|
|
"""
|
|
Security scheme name.
|
|
|
|
It will be included in the generated OpenAPI (e.g. visible at `/docs`).
|
|
"""
|
|
),
|
|
] = None,
|
|
description: Annotated[
|
|
Optional[str],
|
|
Doc(
|
|
"""
|
|
Security scheme description.
|
|
|
|
It will be included in the generated OpenAPI (e.g. visible at `/docs`).
|
|
"""
|
|
),
|
|
] = None,
|
|
auto_error: Annotated[
|
|
bool,
|
|
Doc(
|
|
"""
|
|
By default, if the cookie is not provided, `APIKeyCookie` will
|
|
automatically cancel the request and send the client an error.
|
|
|
|
If `auto_error` is set to `False`, when the cookie is not available,
|
|
instead of erroring out, the dependency result will be `None`.
|
|
|
|
This is useful when you want to have optional authentication.
|
|
|
|
It is also useful when you want to have authentication that can be
|
|
provided in one of multiple optional ways (for example, in a cookie or
|
|
in an HTTP Bearer token).
|
|
"""
|
|
),
|
|
] = True,
|
|
):
|
|
self.model: APIKey = APIKey(
|
|
**{"in": APIKeyIn.cookie}, # type: ignore[arg-type]
|
|
name=name,
|
|
description=description,
|
|
)
|
|
self.scheme_name = scheme_name or self.__class__.__name__
|
|
self.auto_error = auto_error
|
|
|
|
async def __call__(self, request: Request) -> Optional[str]:
|
|
api_key = request.cookies.get(self.model.name)
|
|
if not api_key:
|
|
if self.auto_error:
|
|
raise HTTPException(
|
|
status_code=HTTP_403_FORBIDDEN, detail="Not authenticated"
|
|
)
|
|
else:
|
|
return None
|
|
return api_key
|