Skip to content

Authentication

Base class for implementing the Authentication into SQLAdmin. You need to inherit this class and override the methods: login, logout and authenticate.

Source code in sqladmin/authentication.py
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
class AuthenticationBackend:
    """Base class for implementing the Authentication into SQLAdmin.
    You need to inherit this class and override the methods:
    `login`, `logout` and `authenticate`.
    """

    def __init__(self, secret_key: str, **session_kwargs: Any) -> None:
        from starlette.middleware.sessions import SessionMiddleware

        self.middlewares = [
            Middleware(SessionMiddleware, secret_key=secret_key, **session_kwargs),
        ]

    async def login(self, request: Request) -> Response | bool:
        """Implement login logic here.
        You can access the login form data `await request.form()`
        and validate the credentials.
        """
        raise NotImplementedError()

    async def logout(self, request: Request) -> Response | bool:
        """Implement logout logic here.
        This will usually clear the session with `request.session.clear()`.

        If a `Response` or `RedirectResponse` is returned,
        that response is returned to the user,
        otherwise the user will be redirected to the index page.
        """
        raise NotImplementedError()

    async def authenticate(self, request: Request) -> Response | bool:
        """Implement authenticate logic here.
        This method will be called for each incoming request
        to validate the authentication.

        If a `Response` or `RedirectResponse` is returned,
        that response is returned to the user,
        otherwise a True/False is expected.
        """
        raise NotImplementedError()

    async def get_user_id(self, request: Request) -> Any:
        """Return an identifier for the authenticated user, or `None`.

        Called once per request after `authenticate` succeeds. The result is
        stored on the request and read back by
        [`get_current_user_id`][sqladmin.authentication.get_current_user_id],
        so everything that needs to know *who* is acting -- the audit backend
        and the authorization backend among them -- shares one answer instead
        of each re-deriving it.

        The default reads ``user_id`` from the session, which suits the
        session-based login flow in the docs. Override it for anything else.
        """

        if "session" in request.scope:
            return request.session.get("user_id")
        return None

__init__(secret_key, **session_kwargs)

Source code in sqladmin/authentication.py
20
21
22
23
24
25
def __init__(self, secret_key: str, **session_kwargs: Any) -> None:
    from starlette.middleware.sessions import SessionMiddleware

    self.middlewares = [
        Middleware(SessionMiddleware, secret_key=secret_key, **session_kwargs),
    ]

authenticate(request) async

Implement authenticate logic here. This method will be called for each incoming request to validate the authentication.

If a Response or RedirectResponse is returned, that response is returned to the user, otherwise a True/False is expected.

Source code in sqladmin/authentication.py
44
45
46
47
48
49
50
51
52
53
async def authenticate(self, request: Request) -> Response | bool:
    """Implement authenticate logic here.
    This method will be called for each incoming request
    to validate the authentication.

    If a `Response` or `RedirectResponse` is returned,
    that response is returned to the user,
    otherwise a True/False is expected.
    """
    raise NotImplementedError()

login(request) async

Implement login logic here. You can access the login form data await request.form() and validate the credentials.

Source code in sqladmin/authentication.py
27
28
29
30
31
32
async def login(self, request: Request) -> Response | bool:
    """Implement login logic here.
    You can access the login form data `await request.form()`
    and validate the credentials.
    """
    raise NotImplementedError()

logout(request) async

Implement logout logic here. This will usually clear the session with request.session.clear().

If a Response or RedirectResponse is returned, that response is returned to the user, otherwise the user will be redirected to the index page.

Source code in sqladmin/authentication.py
34
35
36
37
38
39
40
41
42
async def logout(self, request: Request) -> Response | bool:
    """Implement logout logic here.
    This will usually clear the session with `request.session.clear()`.

    If a `Response` or `RedirectResponse` is returned,
    that response is returned to the user,
    otherwise the user will be redirected to the index page.
    """
    raise NotImplementedError()

get_user_id(request) async

Return an identifier for the authenticated user, or None.

Called once per request after authenticate succeeds. The result is stored on the request and read back by get_current_user_id, so everything that needs to know who is acting -- the audit backend and the authorization backend among them -- shares one answer instead of each re-deriving it.

The default reads user_id from the session, which suits the session-based login flow in the docs. Override it for anything else.

Source code in sqladmin/authentication.py
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
async def get_user_id(self, request: Request) -> Any:
    """Return an identifier for the authenticated user, or `None`.

    Called once per request after `authenticate` succeeds. The result is
    stored on the request and read back by
    [`get_current_user_id`][sqladmin.authentication.get_current_user_id],
    so everything that needs to know *who* is acting -- the audit backend
    and the authorization backend among them -- shares one answer instead
    of each re-deriving it.

    The default reads ``user_id`` from the session, which suits the
    session-based login flow in the docs. Override it for anything else.
    """

    if "session" in request.scope:
        return request.session.get("user_id")
    return None

Return the user id resolved for this request, or None.

Populated from AuthenticationBackend.get_user_id when the request enters an Admin route.

Source code in sqladmin/authentication.py
77
78
79
80
81
82
83
84
85
def get_current_user_id(request: Request) -> Any:
    """Return the user id resolved for this request, or `None`.

    Populated from
    [`AuthenticationBackend.get_user_id`][sqladmin.authentication.AuthenticationBackend.get_user_id]
    when the request enters an Admin route.
    """

    return getattr(request.state, _USER_ID_STATE_ATTR, None)