This message was deleted.
# ask-for-help
s
This message was deleted.
s
Hiya! Do you have code you could share for how you're mounting the middleware?
n
Yes, sure. One second
Copy code
from starlette.middleware.authentication import AuthenticationMiddleware
from starlette.responses import PlainTextResponse
Copy code
from starlette.middleware.authentication import AuthenticationMiddleware
from starlette.responses import PlainTextResponse

class TokenAuth (BaseTokenAuth):
    async def verify(self, token: str):
        print('here 1 11111111111111111111111111')
        if token != 'test123':
            return None
        return True

svc.add_asgi_middleware(AuthenticationMiddleware, backend=TokenAuth(), on_error=lambda _, exc: PlainTextResponse(str(exc), status_code=401))
I've tried with the basetokenauth backend
b
what if u you implemented
on_error
See if it throws anything
I assume this is done before the
Copy code
@svc.api(...)
n
Yes, it is done before the .api
Just tried to implement on_error but nothing is thrown

https://i.gyazo.com/f187432484bb81214fb2de6909deeaa5.png▾

Here's a ss with this part of the code
Also tried to add '@requires('authenticated')' after @svc.api but i get the following error:
No "request" or "websocket" argument on function "<function txt2img at 0x7ff87c9ce5e0>"
s
Ah, does the middleware require annotating the endpoints?
n
I think so, here's an example from their github

https://i.gyazo.com/eb6148714a1944e6485b0bf2587a46fa.png▾

But I can't find how to do that with bento (and I am also new to Python btw)
s
I'm not sure that's actually possible, let me look into this a bit.
n
Ok, thanks a lot for helping
I chose to use starlette-auth-toolkit by following bentoml's article on Securing Endpoints Access here: https://docs.bentoml.org/en/latest/guides/security.html
Also, if you know any other way to secure my endpoints pls let me know