Skip to Content
FastAPI
book

FastAPI

by Bill Lubanovic
November 2023
Intermediate to advanced
277 pages
4h 55m
English
O'Reilly Media, Inc.
Content preview from FastAPI

Chapter 11. Authentication and Authorization

Respect mah authoritay!

Eric Cartman, South Park

Preview

Sometimes a website is wide open, and any visitor can visit any page. But if any of the site’s content may be modified, some endpoints will be restricted to certain people or groups. If anyone could alter pages on Amazon, imagine the odd items that would show up, and the amazing sales some people would suddenly get. Unfortunately, it’s human nature—for some humans—to take advantage of the rest, who pay a hidden tax for their activities.

Should we leave our cryptid site open for any users to access any endpoint? No! Almost any sizable web service eventually needs to deal with the following:

Authentication (authn)

Who are you?

Authorization (authz)

What do you want?

Should the authentication and authorization (auth) code have its own new layer, say between Web and Service? Or should everything be handled by the Web or Service layer itself? This chapter dips into auth techniques and where to put them.

Often descriptions of web security seem more confusing than they need to be. Attackers can be really, really sneaky, and countermeasures may not be simple.

Note

As I’ve mentioned more than once, the official FastAPI documentation is excellent. Try the Security section if this chapter doesn’t provide as many details as you’d like.

So, let’s take this walk-through in steps. I’ll start with simple techniques that are intended to only hook auth into a web endpoint for testing, ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Building Micro-Frontends

Building Micro-Frontends

Luca Mezzalira
Practical MLOps

Practical MLOps

Noah Gift, Alfredo Deza
Learning Go

Learning Go

Jon Bodner
FastAPI Cookbook

FastAPI Cookbook

Giunio De Luca

Publisher Resources

ISBN: 9781098135492Errata Page