Node.js Backend Development Bootcamp · レッスン

OAuth2パスワードフローの統合

FastAPIアプリケーションにOAuth2のパスワードフローを統合し、ユーザーログインとトークン取得に対応します。

レッスン 4/610 ステップ

「OAuth2パスワードフローの統合」はCoddyKit上の無料Node.js Backend Development Bootcampレッスンです。 これはレッスン4/6です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはNode.js Backend Development Bootcamp学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Node.js Backend Development Bootcampコースには全6レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

Intro to OAuth2 Password Flow

Welcome! This lesson focuses on integrating the OAuth2 Password Flow in FastAPI. It's a standard and secure way for users to log in to your application.

This flow allows users to provide their username and password directly to your API. If successful, your API issues an access token, which the user then uses to access protected resources.

Why Use Password Flow?

The OAuth2 Password Flow is particularly suitable for first-party applications, like your own mobile app or web frontend, where you fully trust the client.

  • Security: It's a widely adopted, well-understood security standard.
  • Simplicity: Provides a straightforward login experience for users.
  • Token-based: After login, users get a token, avoiding the need to send credentials with every request.

Key FastAPI Components

FastAPI provides specialized utilities to make implementing OAuth2 Password Flow easy:

  • OAuth2PasswordBearer: A dependency that extracts the access token from the Authorization: Bearer header of incoming requests.
  • OAuth2PasswordRequestForm: A dependency that automatically parses the username and password from the form data sent during a login request.

We'll combine these with FastAPI's powerful Dependency Injection system.

Setting up OAuth2PasswordBearer

First, we need to initialize OAuth2PasswordBearer. The tokenUrl parameter is crucial; it tells clients where to send their login credentials to obtain an access token.

This URL will be the path to our login endpoint.

from fastapi import FastAPI
from fastapi.security import OAuth2PasswordBearer

app = FastAPI()

# 'token' is the URL path where clients will log in
oauth2_scheme = OAuth2PasswordBearer(tokenUrl="token")

# We will create a @app.post("/token") endpoint next!

The Login Endpoint: /token

This is the core endpoint where users will send their username and password. It's typically a POST request.

We use OAuth2PasswordRequestForm as a dependency. FastAPI automatically parses the incoming form data and provides username and password attributes.

from fastapi import Depends, HTTPException, status
from fastapi.security import OAuth2PasswordRequestForm

@app.post("/token")
async def login_for_access_token(
    form_data: OAuth2PasswordRequestForm = Depends()
):
    # 1. Authenticate user (verify username/password)
    # 2. If valid, create an access token
    # 3. Return the token
    pass # Details coming in the next scene!

Full Code: Login & Protected Endpoint

Here's a complete FastAPI application demonstrating the OAuth2 Password Flow. It includes the /token endpoint for login and a /users/me/ endpoint protected by the access token.

Run this code: Save as main.py, then uvicorn main:app --reload. Access docs at http://127.0.0.1:8000/docs.

from fastapi import FastAPI, Depends, HTTPException, status
from fastapi.security import OAuth2PasswordBearer, OAuth2PasswordRequestForm
from pydantic import BaseModel
from typing import Optional

app = FastAPI()

oauth2_scheme = OAuth2PasswordBearer(tokenUrl="token")

# --- Mock User & Token Logic (Simplified for this lesson) ---
class UserInDB(BaseModel):
    username: str
    hashed_password: str
    disabled: Optional[bool] = None

class CurrentUser(BaseModel):
    username: str
    email: Optional[str] = None
    full_name: Optional[str] = None
    disabled: Optional[bool] = None

fake_users_db = {
    "testuser": UserInDB(username="testuser", hashed_password="password123", disabled=False),
    "disableduser": UserInDB(username="disableduser", hashed_password="securepass", disabled=True)
}

def get_user_from_db(username: str):
    user_data = fake_users_db.get(username)
    if user_data:
        return CurrentUser(username=user_data.username, full_name=f"{user_data.username} Full", email=f"{user_data.username}@example.com", disabled=user_data.disabled)
    return None

def authenticate_user(username: str, password: str):
    user_in_db = fake_users_db.get(username)
    if not user_in_db or user_in_db.hashed_password != password: # In real app, use password hashing
        return None
    return get_user_from_db(username)

def create_access_token(data: dict):
    # In a real app, use `jwt.encode` with a secret key (from Lesson 1)
    return f"mock_jwt_for_{data['sub']}"
# --- End Mock Logic ---

@app.post("/token")
async def login_for_access_token(
    form_data: OAuth2PasswordRequestForm = Depends()
):
    user = authenticate_user(form_data.username, form_data.password)
    if not user:
        raise HTTPException(
            status_code=status.HTTP_401_UNAUTHORIZED,
            detail="Incorrect username or password",
            headers={"WWW-Authenticate": "Bearer"},
        )
    if user.disabled:
        raise HTTPException(
            status_code=status.HTTP_400_BAD_REQUEST,
            detail="Inactive user"
        )
    access_token = create_access_token(data={"sub": user.username})
    return {"access_token": access_token, "token_type": "bearer"}

# Dependency to get the current user from the token
async def get_current_user(token: str = Depends(oauth2_scheme)):
    # In a real app, this would decode and validate the JWT (from Lesson 1)
    if not token.startswith("mock_jwt_for_"):
        raise HTTPException(
            status_code=status.HTTP_401_UNAUTHORIZED,
            detail="Invalid authentication credentials",
            headers={"WWW-Authenticate": "Bearer"},
        )
    username = token.replace("mock_jwt_for_", "")
    user = get_user_from_db(username)
    if user is None or user.disabled:
        raise HTTPException(
            status_code=status.HTTP_401_UNAUTHORIZED,
            detail="Invalid authentication credentials or inactive user",
            headers={"WWW-Authenticate": "Bearer"},
        )
    return user

# A Protected Endpoint
@app.get("/users/me/", response_model=CurrentUser)
async def read_users_me(current_user: CurrentUser = Depends(get_current_user)):
    return current_user

Understanding get_current_user

The get_current_user function is a crucial dependency. It performs two main tasks:

  1. Extract Token: Uses oauth2_scheme = Depends(OAuth2PasswordBearer(...)) to get the token from the Authorization header.
  2. Validate & Fetch User: Decodes and validates the token (using JWT logic from Lesson 1 in a real app). If valid, it fetches and returns the corresponding User object. If invalid or missing, it raises an HTTPException.

How Clients Interact

Here's a typical client interaction with the OAuth2 Password Flow:

  1. Client (e.g., mobile app) sends a POST request to /token with username and password in form data.
  2. If successful, the API returns an access_token (e.g., {"access_token": "abc.123.xyz", "token_type": "bearer"}).
  3. For subsequent protected requests, the client includes this token in the Authorization header: Authorization: Bearer abc.123.xyz.

Quick Check: OAuth2 Components

Which FastAPI component is primarily responsible for parsing the username and password from an incoming login request (form data)?

Recap: OAuth2 Password Flow

You've successfully integrated the OAuth2 Password Flow in FastAPI!

  • You initialized OAuth2PasswordBearer with a tokenUrl.
  • You created a /token endpoint using OAuth2PasswordRequestForm to handle user login.
  • You understood how to authenticate users and issue access tokens.
  • You secured endpoints by using a get_current_user dependency to extract and validate the access token.

Next, you can explore Role-Based Access Control (RBAC) to add more granular permissions based on user roles!

無料で開始

AI チューターと学ぶ JavaScript — 無料

ブラウザでリアルコードを書いて実行し、24/7 の AI チューターから瞬時にサポートを受け、ウェブまたはアプリで続きから学習できます。

コース
22
レッスン
92

よくある質問

「OAuth2パスワードフローの統合」レッスンは無料ですか?

はい。「OAuth2パスワードフローの統合」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Node.js Backend Development Bootcampコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Node.js Backend Development Bootcampコースには全6レッスンが含まれています。

「OAuth2パスワードフローの統合」で何を学びますか?

FastAPIアプリケーションにOAuth2のパスワードフローを統合し、ユーザーログインとトークン取得に対応します。 ブラウザで直接実行するハンズオンコードでNode.js Backend Development Bootcampを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

Node.js Backend Development Bootcampを始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのNode.js Backend Development Bootcampは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン4/6です。

「OAuth2パスワードフローの統合」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このNode.js Backend Development Bootcampレッスンでコードを書いて実行できますか?

はい。すべてのNode.js Backend Development Bootcampレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. ユーザー登録とログイン
  2. JWTトークンの生成と検証
  3. ステートレス認証のためのJWT
  4. OAuth2パスワードフローの統合
  5. ロールベースアクセス制御
  6. ロールベースアクセス制御(RBAC)
← Node.js Backend Development Bootcampに戻る