FastAPI application for automated login security testing using Playwright. Supports REST API control, CLI execution, and Docker + nginx deployment.
auth-security-suite/
├── .env.example # Environment variable template
├── Dockerfile # Playwright-based app image
├── docker-compose.yml # App + nginx stack
├── nginx/nginx.conf # Reverse proxy config
├── pyproject.toml
├── requirements.txt
└── src/auth_security_suite/
├── main.py # FastAPI app (uvicorn entry)
├── cli.py # CLI runner
├── core/settings.py # .env config (pydantic-settings)
├── schemas/ # Request/response models
├── services/ # Login tester + password generator
├── worker/ # Background job runner
└── api/v1/endpoints/ # REST endpoints
- Python 3.11+
- Playwright Chromium browser
- Docker & Docker Compose (for containerised deployment)
Copy the example env file and edit values for your target site:
cd auth-security-suite
cp .env.example .envKey variables (all prefixed with AUTH_SECURITY_):
| Variable | Description | Example |
|---|---|---|
BASE_URL |
Target auth base URL | https://issuer-evrc.viitorcloud.in/auth |
LOGIN_EMAIL |
Email used in the login form | user@example.com |
START_LENGTH |
Initial password length | 8 |
START_FROM |
Resume from this password (empty = from beginning) | 000001*E |
HEADLESS |
Run browser without UI | true |
Start from the beginning:
AUTH_SECURITY_START_FROM=Resume from a previous run:
AUTH_SECURITY_START_FROM=000001*Ecd auth-security-suite
python -m venv .venv
# Windows
.venv\Scripts\activate
# Linux / macOS
source .venv/bin/activate
pip install -e .
playwright install chromiumuvicorn auth_security_suite.main:app --reload --host 0.0.0.0 --port 8000- API docs: http://localhost:8000/docs
- Health check: http://localhost:8000/health
Uses .env settings directly — no API server needed:
python -m auth_security_suite.cliOr, after install:
auth-security-suiteThe original script path still works if the package is installed:
python python_script/brute_force.pycurl -X POST http://localhost:8000/api/v1/brute-force/start \
-H "Content-Type: application/json" \
-d '{"start_length": 8, "start_from": null}'curl -X POST http://localhost:8000/api/v1/brute-force/start \
-H "Content-Type: application/json" \
-d '{"start_length": 8, "start_from": "000001*E"}'curl http://localhost:8000/api/v1/brute-force/statuscurl -X POST http://localhost:8000/api/v1/brute-force/stopcd auth-security-suite
cp .env.example .env
# Edit .env with your target site credentialsdocker compose up --build -d# Health check via nginx
curl http://localhost:8080/health
# API docs
# Open http://localhost:8080/docs in a browserdocker compose logs -f appdocker compose down| Service | Internal port | Exposed port | Description |
|---|---|---|---|
app |
8000 | — | FastAPI + Playwright |
nginx |
80 | 8080 | Reverse proxy |
- Password generation —
tiered_combinations()produces candidates of a given length that contain at least one special character. - Login attempt —
LoginTester.try_password()fills the form, clicks Sign In, and checks for a dashboard redirect. - reCAPTCHA handling — On "Invalid reCAPTCHA" the page reloads and the next password is tried.
- Length escalation — When all combinations for length N are exhausted, the runner moves to length N+1.
- Resume support — Set
START_FROMto skip already-tried passwords and continue from a saved point.
| Issue | Fix |
|---|---|
TimeoutError on dashboard wait |
Increase AUTH_SECURITY_NAV_TIMEOUT_MS in .env |
| reCAPTCHA blocks every attempt | Set AUTH_SECURITY_HEADLESS=false and solve manually, or add delays |
playwright install missing |
Run playwright install chromium after pip install |
| Port 8080 already in use | Change nginx port in docker-compose.yml |