ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

Hold the immutable authorization picture of a single request.

Effective authorization is the intersection of what the identity owns and what the presented credential is allowed to use:

effective = identity permissions ∩ credential abilities

A credential without abilities (None) never narrows the identity, and abilities alone can never grant a permission the identity lacks.

Concurrency

Instances are fully immutable once built, so they can be shared by every coroutine handling the same request without synchronisation.

Method __init__ Build a snapshot from the resolved authorization sources.
Method __repr__ Return a debugging representation of the snapshot.
Method can Report whether the effective authorization grants a permission.
Method hasRole Report whether the identity owns a role.
Class Variable __slots__ Undocumented
Instance Variable __abilities Undocumented
Instance Variable __permissions Undocumented
Instance Variable __roles Undocumented
Property abilities Return the abilities restricting the presented credential.
Property permissions Return the permissions owned by the identity.
Property roles Return the roles assigned to the identity.
def __init__(self, permissions: Iterable[str], roles: Iterable[str], abilities: Iterable[str] | None = None): (source)

Build a snapshot from the resolved authorization sources.

Parameters
permissions:Iterable[str]Permission names owned by the identity, direct ones and the ones inherited from its roles.
roles:Iterable[str]Role names assigned to the identity.
abilities:Iterable[str] | None, optionalAbilities restricting the presented credential.
Returns
NoneThe snapshot is initialised with immutable collections.
def __repr__(self) -> str: (source)

Return a debugging representation of the snapshot.

Returns
strCompact description with the collection sizes only.
def can(self, permission: str) -> bool: (source)

Report whether the effective authorization grants a permission.

Parameters
permission:strPermission name to evaluate.
Returns
boolTrue when the identity owns the permission and the presented credential is allowed to use it.
def hasRole(self, role: str) -> bool: (source)

Report whether the identity owns a role.

Parameters
role:strRole name to evaluate.
Returns
boolTrue when the role is assigned to the identity.
__abilities: frozenset[str] | None = (source)

Undocumented

__permissions: frozenset[str] = (source)

Undocumented

Undocumented

Return the abilities restricting the presented credential.

Returns
frozenset[str] | NoneAbilities of the credential, or None when unrestricted.

Return the permissions owned by the identity.

Returns
frozenset[str]Direct permissions plus the ones inherited from roles.

Return the roles assigned to the identity.

Returns
frozenset[str]Role names, without hierarchy or inheritance.