AlexsanderHamir/Auth-Proxy

★ 0Forks 0PythonGitHub ↗Compare

README

Auth Proxy Server

A Python-based authentication proxy server that validates requests against a database and forwards them to a target URL.

Features

  • Validates X-Scope-OrgID and apikey headers against database
  • Stores credentials in a database (SQLite or PostgreSQL)
  • Management API for creating/deleting credentials
  • Forwards authenticated requests to a configurable target URL
  • Preserves all original request headers and body

Installation

  1. Install Poetry (if not already installed):
curl -sSL https://install.python-poetry.org | python3 -
  1. Install dependencies:
poetry install
  1. Create a .env file:
DATABASE_URL=sqlite:///auth_proxy.db
TARGET_URL=http://localhost:8080
PORT=3000

For PostgreSQL:

DATABASE_URL=postgresql://user:password@localhost:5432/auth_proxy

Usage

Start the server:

poetry run python app.py

Or activate the virtual environment first:

poetry shell
python app.py

Managing Credentials

Create a credential:

curl -X POST http://localhost:3000/credentials \
  -H "Content-Type: application/json" \
  -d '{
    "tenant_id": "tenant-123",
    "api_key": "secret-api-key-123"
  }'

List all credentials:

curl http://localhost:3000/credentials

Delete a credential:

curl -X DELETE http://localhost:3000/credentials \
  -H "Content-Type: application/json" \
  -d '{
    "tenant_id": "tenant-123"
  }'

Making Authenticated Requests

Once credentials are created, use them in requests:

curl -X GET http://localhost:3000/api/endpoint \
  -H "X-Scope-OrgID: tenant-123" \
  -H "apikey: secret-api-key-123"

Or using Python:

import requests

response = requests.get(
    'http://localhost:3000/api/endpoint',
    headers={
        'X-Scope-OrgID': 'tenant-123',
        'apikey': 'secret-api-key-123'
    }
)

Response Codes

  • 200: Successful proxy response from target server
  • 401 Unauthorized: Missing or invalid authentication headers/credentials
  • 500 Proxy Error: Error connecting to target server

Configuration

Edit .env to configure:

  • DATABASE_URL: Database connection string (SQLite or PostgreSQL)
  • TARGET_URL: URL of the server to proxy requests to
  • PORT: Port for the proxy server (default: 3000)

Database Schema

The credentials table has the following structure:

  • tenant_id (String, Primary Key): The tenant/organization ID
  • api_key (String): The API key for authentication
  • is_active (Boolean): Whether the credential is active

Contributors

AlexsanderHamir

Issues