From 2344386f773bb943d3f667e1862bec2f6d4b4f18 Mon Sep 17 00:00:00 2001 From: mdipierro Date: Fri, 18 Dec 2015 19:19:43 -0600 Subject: [PATCH] better docstring for Auth.jwt --- gluon/tools.py | 22 ++++++++++++++-------- 1 file changed, 14 insertions(+), 8 deletions(-) diff --git a/gluon/tools.py b/gluon/tools.py index 62f52f6b..dde1e1fe 100644 --- a/gluon/tools.py +++ b/gluon/tools.py @@ -4044,35 +4044,41 @@ class Auth(object): def jwt(self): """ - To user JWT authentication, instantiate auth with + To use JWT authentication: + 1) instantiate auth with auth = Auth(db, jwt = {'secret_key':'secret'}) - where 'secret' is your own secret string. Then decorate functions that requires login - but will accept the JWT token as credential as: + where 'secret' is your own secret string. + + 2) Secorate functions that require login but should accept the JWT token credentials: @auth.allows_jwt() @auth.requires_login() def myapi(): return 'hello %s' % auth.user.email - (notice the jwt is allowed but not required. if user is logged in, myapi is accessible) + Notice jwt is allowed but not required. if user is logged in, myapi is accessible. + + 3) Use it! + Now API users can obtain a token with http://.../app/default/user/jwt?username=...&password=.... - They can refresh an existing token with + (returns json object with a token attribute) + API users can refresh an existing token with http://.../app/default/user/jwt?token=... - And they can authenticate themselves when calling the myapi by injecting a header + they can authenticate themselves when calling http:/.../myapi by injecting a header Authorization: Bearer - For additional arguments that can be passed to + Any additional attributes in the jwt argument of Auth() below: auth = Auth(db, jwt = {...}) - please see class AuthJWT.__init__(...) arguments. + are passed to the constructor of class AuthJWT. Look there for documentation. """ if not self.jwt_handler: raise HTTP(400, "Not authorized")