django-suap-auth¶
Django OAuth2 authentication backend for SUAP (Unified Public Administration Management System), the academic management system of IFRN.
Introduction¶
django-suap-auth is a Python/Django library designed to simplify and standardize authentication and user profile data retrieval between Django applications and SUAP (Unified Public Administration Management System) — the academic and administrative management platform used by the Federal Institute of Rio Grande do Norte (IFRN).
The package abstracts the complexity of communicating via the OAuth2 Authorization Code Flow protocol with SUAP’s identity provider. It automatically handles exchanging authorization codes for access tokens, querying SUAP user data APIs, and mapping those attributes onto the Django User model.
Beyond basic login integration, the library provides:
Extensible Data Pipeline: A Chain of Responsibility architecture featuring customizable fetchers and mappers to retrieve data from various SUAP API endpoints and map attributes onto the user model.
Profile & Raw Data Submodule (``django_suap_auth.profile``): Ready-to-use Django models (
Perfil,DadosBrutos,Vinculo) to store academic/staff roles and persist full raw JSON responses from SUAP.Native JWT Authentication (``django_suap_auth.jwt``): Built-in endpoints for issuing and validating JWT tokens (without requiring heavy third-party REST frameworks).
User Impersonation (``django_suap_auth.impersonation`` / impersonate): Support for testing and support workflows requiring temporary user identity switching.
Table of Contents:
- What’s New
- Installation
- SUAP OAuth2 Configuration
- Built-in Profile Models (django_suap_auth.profile)
- User Impersonation
- Audit Trail and Admin Dashboard
- SUAP JWT Endpoints
- SUAP OAuth2 Scopes
- Mapping SUAP Attributes to the Django User Model
- User Info Fetching and Mapping Pipeline
- Fetchers (User Data Retrieval)
- Mappers (User Attribute Mapping)
- Authentication Flow
- Sandboxes
- Development
- Release Process
Features¶
OAuth2 Authorization Code Flow with SUAP
Optional JWT authentication endpoints (
/api/token/pair,/api/token/refresh,/api/token/verify)Submodule
django_suap_auth.profilewith built-in profile models (Perfil,DadosBrutos,Vinculo)Submodule
django_suap_auth.impersonationfor user impersonation workflowsConfigurable scopes (
identificacao,email,documentos_pessoais,dados_academicos,dados_pessoais,reitoria)Flexible attribute mapping from SUAP response to Django User model fields
Optional JSON field storage for complete SUAP responses
Configurable intermediate login page (
SUAP_AUTH['DIRECT_REDIRECT'])CSRF protection via state parameter validation