Coverage for /usr/local/lib/python3.10/site-packages/opal_server-0.0.0-py3.10.egg/opal_server/security/jwks.py: 96%

21 statements  

« prev     ^ index     » next       coverage.py v7.15.2, created at 2026-10-10 11:54 +0000

1import json 

2from pathlib import Path 

3 

4from fastapi import FastAPI 

5from fastapi.staticfiles import StaticFiles 

6from opal_common.authentication.signer import JWTSigner 

7 

8 

9class JwksStaticEndpoint: 

10 """Configure a static files endpoint on a fastapi app, exposing JWKs.""" 

11 

12 def __init__( 

13 self, 

14 signer: JWTSigner, 

15 jwks_url: str, 

16 jwks_static_dir: str, 

17 ): 

18 self._signer = signer 

19 self._jwks_url = Path(jwks_url) 

20 self._jwks_static_dir = Path(jwks_static_dir) 

21 

22 def configure_app(self, app: FastAPI): 

23 # create the directory in which the jwks.json file should sit 

24 self._jwks_static_dir.mkdir(parents=True, exist_ok=True) 

25 

26 # get the jwks contents from the signer 

27 jwks_contents = {} 

28 if self._signer.enabled: 28 ↛ 33line 28 didn't jump to line 33 because the condition on line 28 was always true

29 jwk = json.loads(self._signer.get_jwk()) 

30 jwks_contents = {"keys": [jwk]} 

31 

32 # write the jwks.json file 

33 filename = self._jwks_static_dir / self._jwks_url.name 

34 with open(filename, "w") as f: 

35 f.write(json.dumps(jwks_contents)) 

36 

37 route_url = str(self._jwks_url.parent) 

38 app.mount( 

39 route_url, 

40 StaticFiles(directory=str(self._jwks_static_dir)), 

41 name="jwks_dir", 

42 )