auth
auth ¶
Authentication Provider System¶
This module provides a flexible, extensible authentication system with multiple provider strategies.
Key Components:
- AuthMethod: Enum of authentication strategies
- AuthResult: Dataclass tracking which method succeeded and metadata
- AuthProvider: Protocol for implementing custom providers
- Built-in providers: Environment, CodeEngine, OnePassword
- get_auth_with_providers: Main orchestration function
Usage:
Basic usage with default providers:
from crew_dcs.integrations.auth import get_auth_with_providers
# Try all available methods in order
result = await get_auth_with_providers(
target_instance="my-instance",
vault_id="op-vault-id" # Optional: enables OnePassword
)
print(f"Authenticated via {result.method.value}")
auth = result.auth # Use the DomoAuth instance
Custom provider chain:
from crew_dcs.integrations.auth import (
get_auth_with_providers,
EnvironmentAuthProvider,
OnePasswordAuthProvider
)
providers = [
OnePasswordAuthProvider(),
EnvironmentAuthProvider(),
]
result = await get_auth_with_providers(
providers=providers,
target_instance="my-instance",
vault_id="op-vault-id"
)
Custom provider implementation:
from crew_dcs.integrations.auth import AuthProvider, AuthMethod
import crew_dcs.auth as dmda
class VaultAuthProvider:
def __init__(self):
self.method = AuthMethod.CUSTOM
async def try_auth(self, **kwargs) -> dmda.DomoAuth | None:
# Your custom authentication logic
try:
token = retrieve_from_vault(kwargs.get('vault_key'))
return dmda.DomoTokenAuth(
domo_instance=kwargs['target_instance'],
domo_access_token=token
)
except Exception:
return None
OnePassword Utilities:
Direct access to OnePassword utilities:
from crew_dcs.integrations.auth.onepassword import (
generate_client,
get_item_by_title,
get_auth_from_onepass
)
# Create a 1Password client
client = await generate_client()
# Get an item by title
item = await get_item_by_title(client, vault_id="...", title="sdk_instance")
# Get auth directly (without provider system)
auth = await get_auth_from_onepass(
vault_id="...",
item_title="sdk_instance"
)
AuthMethod ¶
Bases: Enum
Enum identifying authentication methods.
AuthProvider ¶
Bases: Protocol
Protocol for implementing custom auth providers.
Any class implementing this protocol can be used as an auth provider.
Must have a method attribute and implement try_auth method.
Example
class CustomAuthProvider: def init(self): self.method = AuthMethod.CUSTOM
async def try_auth(self, **kwargs) -> dmda.DomoAuth | None:
# Your custom logic
return auth or None
try_auth
async
¶
try_auth(**kwargs) -> DomoAuth | None
Attempt authentication. Return None if this method unavailable or fails.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
**kwargs
|
Provider-specific arguments |
{}
|
Returns:
| Type | Description |
|---|---|
DomoAuth | None
|
DomoAuth instance if successful, None otherwise |
Source code in src/crew_dcs/integrations/auth/core.py
68 69 70 71 72 73 74 75 76 77 78 | |
AuthResult
dataclass
¶
AuthResult(
auth: DomoAuth,
method: AuthMethod,
details: dict[str, Any],
)
Result of authentication with metadata about how it was obtained.
Attributes:
| Name | Type | Description |
|---|---|---|
auth |
DomoAuth
|
The authenticated DomoAuth instance |
method |
AuthMethod
|
Which authentication method succeeded |
details |
dict[str, Any]
|
Additional metadata (e.g., instance, account name, provider name) |
CodeEngineAuthProvider ¶
CodeEngineAuthProvider()
Provider for CodeEngine sudo authentication.
Source code in src/crew_dcs/integrations/auth/providers.py
80 81 | |
try_auth
async
¶
try_auth(
sudo_function_instance_auth: DomoAuth | None = None,
target_instance: str | None = None,
account_name: str | None = None,
sudo_package_id: str | None = None,
sudo_package_version: str | None = None,
function_name: str = "get_account",
debug_api: bool = False,
**kwargs
) -> DomoAuth | None
Try to authenticate via CodeEngine sudo.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
sudo_function_instance_auth
|
DomoAuth | None
|
Authenticated auth for CodeEngine calls |
None
|
target_instance
|
str | None
|
Target Domo instance |
None
|
account_name
|
str | None
|
Account identifier (defaults to sdk_{target_instance}) |
None
|
sudo_package_id
|
str | None
|
CodeEngine package ID |
None
|
sudo_package_version
|
str | None
|
CodeEngine package version |
None
|
function_name
|
str
|
CodeEngine function name |
'get_account'
|
debug_api
|
bool
|
Enable debug output |
False
|
**kwargs
|
Additional arguments (ignored) |
{}
|
Returns:
| Type | Description |
|---|---|
DomoAuth | None
|
DomoAuth if successful, None if prerequisites missing or auth fails |
Source code in src/crew_dcs/integrations/auth/providers.py
83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 | |
EnvironmentAuthProvider ¶
EnvironmentAuthProvider()
Provider for environment variable authentication.
Source code in src/crew_dcs/integrations/auth/providers.py
23 24 | |
try_auth
async
¶
try_auth(
target_instance: str | None = None,
domo_instance_env_var: str = "DOMO_INSTANCE",
domo_token_env_var: str = "DOMO_ACCESS_TOKEN",
**kwargs
) -> DomoAuth | None
Try to authenticate from environment variables.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
target_instance
|
str | None
|
Override instance name (sets env var temporarily) |
None
|
domo_instance_env_var
|
str
|
Environment variable name for instance |
'DOMO_INSTANCE'
|
domo_token_env_var
|
str
|
Environment variable name for token |
'DOMO_ACCESS_TOKEN'
|
**kwargs
|
Additional arguments (ignored) |
{}
|
Returns:
| Type | Description |
|---|---|
DomoAuth | None
|
DomoAuth if successful, None if env vars not available |
Source code in src/crew_dcs/integrations/auth/providers.py
26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 | |
OnePasswordAuthProvider ¶
OnePasswordAuthProvider()
Provider for 1Password authentication.
Source code in src/crew_dcs/integrations/auth/providers.py
149 150 | |
try_auth
async
¶
try_auth(
vault_id: str | None = None,
item_title: str | None = None,
target_instance: str | None = None,
domo_instance: str | None = None,
client=None,
debug_api: bool = False,
**kwargs
) -> DomoAuth | None
Try to authenticate via 1Password.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
vault_id
|
str | None
|
1Password vault ID |
None
|
item_title
|
str | None
|
1Password item title (defaults to sdk_{target_instance}) |
None
|
target_instance
|
str | None
|
Target Domo instance name |
None
|
domo_instance
|
str | None
|
Override for final instance name |
None
|
client
|
Optional existing 1Password client |
None
|
|
debug_api
|
bool
|
Enable debug output |
False
|
**kwargs
|
Additional arguments (ignored) |
{}
|
Returns:
| Type | Description |
|---|---|
DomoAuth | None
|
DomoAuth if successful, None if prerequisites missing or auth fails |
Source code in src/crew_dcs/integrations/auth/providers.py
152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 | |
get_auth_with_providers
async
¶
get_auth_with_providers(
providers: list[AuthProvider] | None = None,
**auth_kwargs
) -> AuthResult
Try authentication providers in order until one succeeds.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
providers
|
list[AuthProvider] | None
|
Ordered list of auth providers to try. If None, uses default set. |
None
|
**auth_kwargs
|
Arguments passed to each provider's try_auth method |
{}
|
Returns:
| Type | Description |
|---|---|
AuthResult
|
AuthResult with successful auth and metadata |
Raises:
| Type | Description |
|---|---|
ValueError
|
If all providers fail |
Example
Use default providers¶
result = await get_auth_with_providers(target_instance="my-instance") print(f"Authenticated via {result.method.value}")
Custom provider order¶
from crew_dcs.integrations.auth import ( EnvironmentAuthProvider, OnePasswordAuthProvider )
providers = [MyCustomProvider(), EnvironmentAuthProvider()] result = await get_auth_with_providers( providers=providers, target_instance="my-instance" )
Source code in src/crew_dcs/integrations/auth/core.py
81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 | |