from fune.auth.validate_registration import validate_registration # auth.validate-registration@^1
Suites · auth
User accounts and authentication
Sign-up and login forms, password policy and hashing, login lockout, and signed access tokens (JWT) read from the Authorization header.
34 capabilities (12 core, 22 optional) and 12 gaps, in build order. Put each line in the file that calls it, then fune build.
1. Sign-up and login forms
Check what people type into the account forms, the same way in the browser and the API.
from fune.auth.validate_login import validate_login # auth.validate-login@^1
from fune.auth.normalise_email import normalise_email # auth.normalise-email@^1
from fune.auth.validate_password_change import validate_password_change # auth.validate-password-change@^1
2. Passwords
Decide what passwords are acceptable and store them safely.
from fune.auth.password_policy import password_policy, check_password # auth.password-policy@^1
from fune.auth.password_hash import hash_password, verify_password, password_needs_rehash # auth.password-hash@^1
from fune.crypto.pbkdf2_sha256 import pbkdf2_sha256 # crypto.pbkdf2-sha256@^1
from fune.crypto.constant_time_equal import constant_time_equal # crypto.constant-time-equal@^1
- breached-passwords Checking passwords against a breach corpus (Have I Been Pwned's range API) is network work; the policy's common-password list is built in.
3. Login protection
Slow down password guessing.
from fune.auth.login_throttle import login_throttle # auth.login-throttle@^1
from fune.http.retry_after import retry_after_seconds # http.retry-after@^1
- ip-rate-limiting Rate limiting by IP address across accounts, with its shared counter store (Redis, a database).
4. Tokens
Issue and check signed tokens for an API or a single-page app.
from fune.auth.access_token import issue_access_token, read_access_token, confirm_access_token # auth.access-token@^1
from fune.auth.bearer_token import parse_bearer_token # auth.bearer-token@^1
from fune.auth.jwt import sign_jwt, verify_jwt, decode_jwt # auth.jwt@^1
from fune.crypto.hmac_sha256 import hmac_sha256 # crypto.hmac-sha256@^1
from fune.crypto.sha256 import sha256 # crypto.sha256@^1
from fune.encoding.base64 import base64_encode, base64_decode, base64_url_encode, base64_url_decode # encoding.base64@^1
from fune.time.countdown import countdown # time.countdown@^1
- sessions Server-side sessions and cookies: storing them, Secure/HttpOnly/SameSite flags, CSRF tokens and expiry are yours.
- asymmetric-jwt RS256/ES256 tokens and JWKS key sets (for third-party identity providers): auth.jwt is HS256 only.
5. Forms in React
Accessible account pages in a React front end (TypeScript only).
6. Contact details from validation-basics
Check and normalise a person's contact details before storing them.
from fune.validation.email import is_email # validation.email@^1
from fune.validation.phone_e164 import validate_phone_e164 # validation.phone-e164@^2
from fune.validation.uk_postcode import validate_uk_postcode # validation.uk-postcode@^2
from fune.text.normalise_name import normalise_name # text.normalise-name@^1
7. Bank details from validation-basics
Check payee and customer bank details before money moves.
from fune.validation.iban import is_iban # validation.iban@^1
from fune.validation.bic import validate_bic # validation.bic@^1
from fune.validation.uk_sort_code_account import validate_uk_sort_code_account # validation.uk-sort-code-account@^3
from fune.validation.uk_modulus_table import parse_uk_modulus_table # validation.uk-modulus-table@^1
8. Identifiers and check digits from validation-basics
Catch mistyped reference numbers by their check digits.
from fune.validation.luhn import is_luhn # validation.luhn@^1
from fune.validation.uk_company_number import validate_uk_company_number # validation.uk-company-number@^2
from fune.validation.lei import validate_lei # validation.lei@^1
from fune.validation.gtin import validate_gtin # validation.gtin@^1
9. Displaying sensitive values from validation-basics
Show stored identifiers without exposing them.
from fune.text.mask import mask # text.mask@^1
Gaps
What this kind of app usually needs that Functional Weave does not have yet: write these yourself, or use a service.
- email-verification Sending verification and password-reset emails, and storing their one-time tokens with expiry.
- oauth-social-login OAuth 2.0 / OpenID Connect sign-in with Google, Microsoft, GitHub and the like.
- mfa Second factors: TOTP authenticator codes, SMS codes, passkeys/WebAuthn and recovery codes.
- roles-permissions Roles, permissions and organisation membership: who may do what is yours to model.
- user-storage The users table, unique email index, migrations and account deletion.
- address-lookup Turning a postcode into a list of addresses (Royal Mail PAF or a lookup API) is network work and not in caps.
- email-deliverability Whether a mailbox exists (MX lookups, a confirmation email): validation.email checks the syntax only.
- vocalink-data The Vocalink modulus tables themselves: download them from Pay.UK under its terms; caps parses them but does not ship them.