Simple user session protection for Flask applications.
- Python 85.9%
- HTML 14.1%
|
All checks were successful
build / tests-3.10 (push) Successful in 35s
build / tests-3.11 (push) Successful in 33s
build / lint (push) Successful in 59s
build / tests-3.12 (push) Successful in 45s
build / tests-3.13 (push) Successful in 47s
build / zizmor (push) Successful in 9s
build / tests-3.14 (push) Successful in 54s
build / tests-pypy-3.11 (push) Successful in 1m47s
|
||
|---|---|---|
| .forgejo/workflows | ||
| docs | ||
| example | ||
| src/flask_paranoid | ||
| tests | ||
| .gitignore | ||
| .readthedocs.yaml | ||
| .travis.yml | ||
| CHANGES.md | ||
| CODE_OF_CONDUCT.md | ||
| CONTRIBUTING.md | ||
| LICENSE | ||
| MANIFEST.in | ||
| pyproject.toml | ||
| README.md | ||
| SECURITY.md | ||
| setup.cfg | ||
| setup.py | ||
| tox.ini | ||
flask-paranoid
Simple user session protection.
Quick Start
Here is a simple application that uses Flask-Paranoid to protect the user session:
from flask import Flask
from flask_paranoid import Paranoid
app = Flask(__name__)
app.config['SECRET_KEY'] = 'top-secret!'
paranoid = Paranoid(app)
paranoid.redirect_view = '/'
@app.route('/')
def index():
return render_template('index.html')
When a client connects to this application, a "paranoid" token will be generated according to the IP address and user agent. In all subsequent requests, the token will be recalculated and checked against the one computed for the first request. If the session cookie is stolen and the attacker tries to use it from another location, the generated token will be different, and in that case the extension will clear the session and block the request.
Resources
Sponsor this project
This project relies on contributions from its users. If you benefit from it please consider making a single or ongoing monetary contribution in one of the following platforms:
Thank you!