This package extends PyMongo's MongoClient to provide built-in smart authentication. It simplifies authentication by:
- automatically authenticating when creating the connection instead of having to manually call
authenticateon the authentication database - if an authenticated client was created without passing any credentials, it authenticates by:
- looking for a
MONGO_CREDENTIAL_FILEenvironment variable and associated kwargs in the constructor to format it, if applicable - looking for a
MONGO_AUTHENTICATED_URIenvironment variable - looking for credentials in the
MONGO_AUTHENTICATION_DATABASE,MONGO_USERNAMEandMONGO_PASSWORDenvironment variables - looking for a
.mongo_credentialsfile in the user's home - looking for a
mongo_credentialsfile in the/etcfolder
- looking for a
It also allows the user to specify the path to another credentials file or pass credentials directly.
pip install pymongo-smart-auth
The MongoClient class from the PyMongo-Smart-Auth package is a drop-in replacement for PyMongo's MongoClient that simplifies authentication management.
The constructor works in the same way as the MongoClient constructor with four additional parameters, all optional:
username: the username to authenticate withpassword: the password to authenticate withcredentials_file: a file where credentials can be foundauthenticate: a boolean indicating whether the client should authenticate (defaults toTrue)
When using a credentials file, it should either have:
a single line with a fully authenticated URI
the authentication database on the first line, the user on the second and the password on the third. Empty lines are ignored. Example file:
admin administrator P4ssw0rd
Upon initialisation with the default authenticate=True, the client looks for credentials in the following order:
- The
usernameandpasswordparameters - The passed
credentials_file - The
MONGO_CREDENTIAL_FILEenvironment variable formatted with the kwargs of the constructor, if applicable - The
MONGO_AUTHENTICATED_URIenvironment variable - The
MONGO_AUTHENTICATION_DATABASE,MONGO_USERNAMEandMONGO_PASSWORDenvironment variables - The
.mongo_credentialsfile in the user's home - The
mongo_credentialsfile in the/etcfolder
frompymongo_smart_authimportMongoClient# Explicit user and passwordmongo1=MongoClient(username='user', password='p4ssw0rd')
database1=mongo1['database1'] # Automatically authenticated# Explicit user and password with separate authentication databasemongo2=MongoClient(username='user', password='p4ssw0rd', authentication_database='mongo_users')
database2=mongo2['database2'] # Automatically authenticated# Will read /some/path/mongo_credentialsmongo3=MongoClient(credentials_file='/some/path/mongo_credentials')
database3=mongo3['database3'] # Automatically authenticated# Will read the file in the MONGO_CREDENTIAL_FILE environment variable if set,# then the file in MONGO_CREDENTIAL_FILE environment variable if set,# then the MONGO_AUTHENTICATION_DATABASE, MONGO_USERNAME and MONGO_PASSWORD environment variables if set,# then ~/.mongo_credentials if it exists,# otherwise /etc/mongo_credentialsmongo4=MongoClient()
database4=mongo4['database4'] # Automatically authenticated# Will authenticate with a file defined in the environment with a keyword argument# Assuming MONGO_CREDENTIAL_FILE=/etc/credentials_{group},# this will authenticate with the credentials in /etc/credentials_my_groupmongo5=MongoClient(group='my_group')
database5=mongo6['my_group_database'] # Automatically authenticated# Will not authenticatemongo6=MongoClient(authenticate=False)
database6=mongo5['database5'] # Not authenticatedThis project is licensed under the terms of the MIT license.