Chuyển tới nội dung chính

Authentication

configure_authentication installs Keycloak/OpenID Connect routes, session middleware, CSRF protection, and a profile provider.

from fluvius.fastapi import configure_authentication, create_app

app = (
create_app(pkginfo)
| configure_authentication(
auth_profile_provider=ApplicationProfileProvider,
base_path="/auth",
)
)

Outside development mode, FLUVIUS_APPLICATION_SECRET_KEY is required. Configure the Keycloak base URL, realm, client ID, client secret, and callback URI with FLUVIUS_KEYCLOAK_* / FLUVIUS_DEFAULT_CALLBACK_URI.

Protect application routes with the decorator factory:

from fastapi import Request
from fluvius.fastapi import auth_required


@app.get("/me")
@auth_required()
async def me(request: Request):
auth = request.state.auth_context
return {"user": auth.user, "profile": auth.profile}

Domain mounts receive the same authorization context. Command roles_required checks profile roles, while API zones use IAM realm roles. Policy-enabled domains additionally evaluate their configured Casbin policy manager.

Keep HTTPS-only cookies and CSRF validation enabled in production. Session ID-token refresh uses a Redis single-flight lock when FLUVIUS_SESSION_REFRESH_REDIS_URL is configured.