• Get Review Board
  • What's New
  • Products
  • Review Board Code review, image review, and document review
  • Documentation
  • Release Notes
  • Power Pack Enterprise integrations, reports, and enhanced document review
  • Try for 60 Days
  • Purchase
  • RBCommons Review Board as a Service, hosted by us
  • Pricing
  • RBTools Command line tools and Python API for Review Board
  • Documentation
  • Release Notes
  • Review Bot Automated code review, connecting tools you already use
  • Documentation
  • Release Notes
  • RB Gateway Manage Git and Mercurial repositories in your network
  • Documentation
  • Release Notes
  • Learn and Explore
  • What is Code Review?
  • Documentation
  • Frequently Asked Questions
  • Support Options
  • Third-Party Integrations
  • Demo
  • Review Board RBTools Power Pack Review Bot Djblets RB Gateway
    1. Djblets 5.x
    2. Version 5.x
    3. Version 4.x
    4. Version 3.x
    5. Version 2.x
    6. Version 2.0
    7. Version 1.0
    8. Version 0.9
    9. Djblets Documentation
    10. Guides
    11. Web API Guides
    12. Adding OAuth2 Support
  • Home
  • Guides
  • Avatar Services Guides
  • Writing Avatar Services
  • Extension Guides
  • Writing Extensions
  • Testing Extensions
  • Feature Checks Guides
  • Introduction to Feature Checks
  • Writing Features
  • Writing Feature Checkers
  • Testing with Feature Checks
  • Integration Guides
  • Supporting Integrations
  • Writing Integrations
  • Privacy Compliance Guides
  • Getting and Checking Consent
  • Working with Personally Identifiable Information
  • Service Integrations
  • reCAPTCHA Guides
  • Using reCAPTCHA
  • Registries Guides
  • Writing Registries
  • Web API Guides
  • Writing Web API Resources
  • Adding OAuth2 Support
  • Module and Class References
  • djblets
  • djblets.deprecation
  • djblets.auth.forms
  • djblets.auth.ratelimit
  • djblets.auth.signals
  • djblets.auth.util
  • djblets.auth.views
  • djblets.avatars.errors
  • djblets.avatars.forms
  • djblets.avatars.registry
  • djblets.avatars.services
  • djblets.avatars.services.base
  • djblets.avatars.services.fallback
  • djblets.avatars.services.file_upload
  • djblets.avatars.services.gravatar
  • djblets.avatars.services.url
  • djblets.avatars.settings
  • djblets.cache.backend
  • djblets.cache.backend_compat
  • djblets.cache.context_processors
  • djblets.cache.errors
  • djblets.cache.forwarding_backend
  • djblets.cache.serials
  • djblets.cache.synchronizer
  • djblets.conditions
  • djblets.conditions.choices
  • djblets.conditions.conditions
  • djblets.conditions.errors
  • djblets.conditions.operators
  • djblets.conditions.values
  • djblets.configforms.forms
  • djblets.configforms.mixins
  • djblets.configforms.pages
  • djblets.configforms.registry
  • djblets.configforms.views
  • djblets.datagrid.grids
  • djblets.db.backends.mysql.base
  • djblets.db.fields
  • djblets.db.fields.base64_field
  • djblets.db.fields.comma_separated_values_field
  • djblets.db.fields.counter_field
  • djblets.db.fields.json_field
  • djblets.db.fields.modification_timestamp_field
  • djblets.db.fields.relation_counter_field
  • djblets.db.managers
  • djblets.db.query
  • djblets.db.query_catcher
  • djblets.db.query_comparator
  • djblets.db.validators
  • djblets.extensions.admin
  • djblets.extensions.errors
  • djblets.extensions.extension
  • djblets.extensions.forms
  • djblets.extensions.hooks
  • djblets.extensions.loaders
  • djblets.extensions.manager
  • djblets.extensions.middleware
  • djblets.extensions.models
  • djblets.extensions.packaging
  • djblets.extensions.resources
  • djblets.extensions.settings
  • djblets.extensions.signals
  • djblets.extensions.staticfiles
  • djblets.extensions.testing
  • djblets.extensions.testing.testcases
  • djblets.extensions.urls
  • djblets.extensions.views
  • djblets.extensions.templatetags.djblets_extensions
  • djblets.features
  • djblets.features.checkers
  • djblets.features.decorators
  • djblets.features.errors
  • djblets.features.feature
  • djblets.features.level
  • djblets.features.registry
  • djblets.features.testing
  • djblets.features.templatetags.features
  • djblets.forms.fields
  • djblets.forms.fieldsets
  • djblets.forms.forms
  • djblets.forms.forms.key_value_form
  • djblets.forms.widgets
  • djblets.gravatars
  • djblets.gravatars.templatetags.gravatars
  • djblets.http.middleware
  • djblets.http.responses
  • djblets.integrations.errors
  • djblets.integrations.forms
  • djblets.integrations.hooks
  • djblets.integrations.integration
  • djblets.integrations.manager
  • djblets.integrations.mixins
  • djblets.integrations.models
  • djblets.integrations.urls
  • djblets.integrations.views
  • djblets.log
  • djblets.log.middleware
  • djblets.log.siteconfig
  • djblets.log.urls
  • djblets.log.views
  • djblets.mail.dmarc
  • djblets.mail.message
  • djblets.mail.testing
  • djblets.mail.utils
  • djblets.markdown
  • djblets.markdown.extensions.escape_html
  • djblets.markdown.extensions.wysiwyg
  • djblets.markdown.extensions.wysiwyg_email
  • djblets.pipeline.compilers.es6
  • djblets.pipeline.compilers.less
  • djblets.pipeline.compilers.mixins
  • djblets.pipeline.compilers.rollup
  • djblets.pipeline.compilers.typescript
  • djblets.pipeline.settings
  • djblets.privacy.consent
  • djblets.privacy.consent.base
  • djblets.privacy.consent.common
  • djblets.privacy.consent.errors
  • djblets.privacy.consent.forms
  • djblets.privacy.consent.hooks
  • djblets.privacy.consent.registry
  • djblets.privacy.consent.tracker
  • djblets.privacy.models
  • djblets.privacy.pii
  • djblets.privacy.templatetags.djblets_privacy
  • djblets.recaptcha.mixins
  • djblets.recaptcha.siteconfig
  • djblets.recaptcha.templatetags.djblets_recaptcha
  • djblets.recaptcha.widgets
  • djblets.registries
  • djblets.registries.errors
  • djblets.registries.importer
  • djblets.registries.mixins
  • djblets.registries.registry
  • djblets.registries.signals
  • djblets.secrets
  • djblets.secrets.crypto
  • djblets.secrets.token_generators
  • djblets.secrets.token_generators.base
  • djblets.secrets.token_generators.legacy_sha1
  • djblets.secrets.token_generators.registry
  • djblets.secrets.token_generators.vendor_checksum
  • djblets.siteconfig
  • djblets.siteconfig.admin
  • djblets.siteconfig.context_processors
  • djblets.siteconfig.django_settings
  • djblets.siteconfig.forms
  • djblets.siteconfig.managers
  • djblets.siteconfig.middleware
  • djblets.siteconfig.models
  • djblets.siteconfig.signals
  • djblets.siteconfig.views
  • djblets.template.caches
  • djblets.template.context
  • djblets.template.loaders.conditional_cached
  • djblets.template.loaders.namespaced_app_dirs
  • djblets.testing.decorators
  • djblets.testing.testcases
  • djblets.testing.testrunners
  • djblets.urls.context_processors
  • djblets.urls.decorators
  • djblets.urls.patterns
  • djblets.urls.resolvers
  • djblets.urls.root
  • djblets.urls.staticfiles
  • djblets.util.compat.django.core.cache
  • djblets.util.compat.python.past
  • djblets.util.contextmanagers
  • djblets.util.dates
  • djblets.util.decorators
  • djblets.util.filesystem
  • djblets.util.functional
  • djblets.util.html
  • djblets.util.http
  • djblets.util.humanize
  • djblets.util.json_utils
  • djblets.util.properties
  • djblets.util.serializers
  • djblets.util.symbols
  • djblets.util.templatetags.djblets_deco
  • djblets.util.templatetags.djblets_email
  • djblets.util.templatetags.djblets_forms
  • djblets.util.templatetags.djblets_images
  • djblets.util.templatetags.djblets_js
  • djblets.util.templatetags.djblets_utils
  • djblets.util.typing
  • djblets.util.views
  • djblets.views.generic.base
  • djblets.views.generic.etag
  • djblets.webapi.auth
  • djblets.webapi.auth.backends
  • djblets.webapi.auth.backends.api_tokens
  • djblets.webapi.auth.backends.base
  • djblets.webapi.auth.backends.basic
  • djblets.webapi.auth.backends.oauth2_tokens
  • djblets.webapi.auth.views
  • djblets.webapi.decorators
  • djblets.webapi.encoders
  • djblets.webapi.errors
  • djblets.webapi.fields
  • djblets.webapi.managers
  • djblets.webapi.models
  • djblets.webapi.oauth2_scopes
  • djblets.webapi.resources
  • djblets.webapi.resources.base
  • djblets.webapi.resources.group
  • djblets.webapi.resources.registry
  • djblets.webapi.resources.root
  • djblets.webapi.resources.user
  • djblets.webapi.resources.mixins.api_tokens
  • djblets.webapi.resources.mixins.forms
  • djblets.webapi.resources.mixins.oauth2_tokens
  • djblets.webapi.resources.mixins.queries
  • djblets.webapi.responses
  • djblets.webapi.signals
  • djblets.webapi.testing
  • djblets.webapi.testing.decorators
  • djblets.webapi.testing.testcases
  • General Index
  • Python Module Index
  • Release Notes
  • Adding OAuth2 Support¶

    Overview¶

    The Web API utilities provided by Djblets can be augmented to add support for authentication via OAuth2. In order to do this, there are a few steps:

    Additional Requirements¶

    OAuth2 support requires the django-oauth-toolkit module to be installed. This module has only been tested with version 0.9.0.

    settings.py¶

    The following settings need to be updated in settings.py to take advantage of OAuth2 support.

    INSTALLED_APPS:

    Add 'oauth2_provider' to this list.

    WEB_API_AUTH_BACKENDS:

    Add ''djblets.webapi.auth.backends.oauth2_tokens.OAuth2TokenAuthBackend' to this list.

    settings.py¶
    WEB_API_AUTH_BACKENDS = (
        'djblets.webapi.auth.backends.basic.WebAPIBasicAuthBackend',
        'djblets.webapi.auth.backends.oauth2_tokens.OAuth2TokenAuthBackend',
    )
    
    AUTHENTICATION_BACKENDS:

    Create an authentication backend using OAuth2TokenBackendMixin and add it to this setting:

    my_app/auth_backends.py¶
    from djblets.webapi.auth.backends.oauth2_tokens import OAuth2TokenBackendMixin
    from django.contrib.auth.backends import ModelBackend
    
    class EnabledOAuth2TokenBackend(OAuth2TokenBackendMixin, ModelBackend):
        """An OAuth2 token auth backend using a custom Application model."""
    
        def verify_request(self, request, token, user):
            return token.application.some_custom_property
    
    settings.py¶
    AUTHENTICATION_BACKENDS = (
        'django.contrib.auth.backends.ModelBackend',
        # ...
        'myapp.auth_backends.EnabledOAuth2TokenBackend',
    )
    
    WEB_API_ROOT_RESOURCE:

    Define this to be the full import path of your root resource.

    settings.py¶
    WEB_API_ROOT_RESOURCE = 'myapp.webapi.resources.root.root_resource'
    
    WEB_API_SCOPE_DICT_CLASS:

    This setting determines what class defines the OAuth2 scopes for your web API. By default, each resource will require scope_name:method where scope_name is defined by ResourceOAuth2TokenMixin.scope_name and method is one of read (for HTTP GET, HEAD, and OPTIONS), write (for HTTP PUT and POST), or destroy (for HTTP DELETE).

    Djblets provides two possible scope dictionary classes for your web API:

    djblets.webapi.oauth2_scopes.ExtensionEnabledWebAPIScopeDictionary:

    For apps that use the djblets extensions framework.

    djblets.webapi.oauth2_scopes.WebAPIScopeDictionary:

    For apps that do not use the djblets extensions framework.

    settings.py¶
    # If using extensions:
    WEB_API_SCOPE_DICT_CLASS = \
        'djblets.webapi.oauth2_scopes.ExtensionEnabledWebAPIScopeDictionary'
    
    # Otherwise:
    WEB_API_SCOPE_DICT_CLASS = \
        'djblets.webapi.oauth2_scopes.WebAPIScopeDictionary'
    
    OAUTH_PROVIDER:

    This setting must, at a minimum, define the DEFAULT_SCOPES and SCOPES keys. The following example presumes that your root resource is named 'root' and you are using one of the provided scope dictionaries.

    The SCOPES key should be an empty dictionary. It will be replaced at runtime with the proper dictionary.

    settings.py¶
    OAUTH2_PROVIDER = {
         'DEFAULT_SCOPES': 'root:read',
         'SCOPES': {},
    }
    

    Resource Classes¶

    Resources should all inherit from a base class that includes the provided mixin for OAuth2 support.

    from djblets.webapi.resources.base import WebAPIResource as \
        BaseWebAPIResource
    from djblets.webapi.resources.mixins.oauth2_tokens import \
        ResourceOAuth2TokenMixin
    
    
    class WebAPIResource(ResourceOAuth2TokenMixin, BaseWebAPIResource):
        """The base resource class.
    
        All resources should inherit from this.
        """
    

    If you wish to disable access to a resource when using an OAuth2 token, you may set the oauth2_token_access_allowed attribute to False.

    Enabling Web API OAuth Scopes¶

    Finally, to enable the web API scope dictionary, you must run enable_webapi_scopes() at runtime. This should be run when your app is starting.

    If you are on Django 1.7+, you should call this function in your AppConfig.ready method:

    my_app/apps.py¶
    from django.apps import AppConfig
    
    
    class WebApiAppConfig(AppConfig):
        def ready(self):
            """Enable the WebAPI scopes dictionary."""
            from djblets.webapi.oauth2_scopes import enable_webapi_scopes
    
            enable_oauth2_scopes()
    

    Otherwise if you are on Django 1.6, you may call it in your root urls.py:

    urls.py¶
    from djblets.webapi.oauth2_scopes import enable_webapi_scopes
    
    
    urlpatterns = [
        # ...
    ]
    
    enable_oauth2_scopes()
    

    Keep up with the latest Review Board releases, security updates, and helpful information.

    About
    News
    Demo
    RBCommons Hosting
    Integrations
    Happy Users
    Support Options
    Documentation
    FAQ
    User Manual
    RBTools
    Administration Guide
    Power Pack
    Release Notes
    Downloads
    Review Board
    RBTools
    Djblets
    Power Pack
    Package Store
    PGP Signatures
    Contributing
    Bug Tracker
    Submit Patches
    Development Setup
    Wiki
    Follow Us
    Mailing Lists
    Reddit
    Twitter
    Mastodon
    Facebook
    YouTube

    Copyright © 2006-2025 Beanbag, Inc. All rights reserved.

    Terms of Service — Privacy Policy — AI Ethics Policy — Branding

    On this page

    • [Top]
    • Overview
    • Additional Requirements
    • settings.py
    • Resource Classes
    • Enabling Web API OAuth Scopes