django-suap-auth

Django OAuth2 authentication backend for SUAP (Unified Public Administration Management System), the academic management system of IFRN.

Introduction

django-suap-auth is a Python/Django library designed to simplify and standardize authentication and user profile data retrieval between Django applications and SUAP (Unified Public Administration Management System) — the academic and administrative management platform used by the Federal Institute of Rio Grande do Norte (IFRN).

The package abstracts the complexity of communicating via the OAuth2 Authorization Code Flow protocol with SUAP’s identity provider. It automatically handles exchanging authorization codes for access tokens, querying SUAP user data APIs, and mapping those attributes onto the Django User model.

Beyond basic login integration, the library provides:

  • Extensible Data Pipeline: A Chain of Responsibility architecture featuring customizable fetchers and mappers to retrieve data from various SUAP API endpoints and map attributes onto the user model.

  • Profile & Raw Data Submodule (``django_suap_auth.profile``): Ready-to-use Django models (Perfil, DadosBrutos, Vinculo) to store academic/staff roles and persist full raw JSON responses from SUAP.

  • Native JWT Authentication (``django_suap_auth.jwt``): Built-in endpoints for issuing and validating JWT tokens (without requiring heavy third-party REST frameworks).

  • User Impersonation (``django_suap_auth.impersonation`` / impersonate): Support for testing and support workflows requiring temporary user identity switching.

Table of Contents:

Features

  • OAuth2 Authorization Code Flow with SUAP

  • Optional JWT authentication endpoints (/api/token/pair, /api/token/refresh, /api/token/verify)

  • Submodule django_suap_auth.profile with built-in profile models (Perfil, DadosBrutos, Vinculo)

  • Submodule django_suap_auth.impersonation for user impersonation workflows

  • Configurable scopes (identificacao, email, documentos_pessoais, dados_academicos, dados_pessoais, reitoria)

  • Flexible attribute mapping from SUAP response to Django User model fields

  • Optional JSON field storage for complete SUAP responses

  • Configurable intermediate login page (SUAP_AUTH['DIRECT_REDIRECT'])

  • CSRF protection via state parameter validation