THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
Answer authorization questions for a given request context.
The authorizer never stores the current identity: every method takes the request context as its first argument. That keeps the service stateless and therefore safe as a container singleton shared by every concurrent request.
Concurrency
Only policy classes are cached. Each evaluation builds a fresh policy in the caller's container scope, so injected request dependencies and mutable policy state are never retained by this singleton.
| Method | __init__ |
Initialise the authorizer with the application container. |
| Async Method | allows |
Evaluate a policy ability against a concrete resource. |
| Async Method | can |
Report whether the context grants a permission. |
| Async Method | can |
Report whether the context grants every permission. |
| Async Method | can |
Report whether the context grants at least one permission. |
| Async Method | has |
Report whether the context owns a role. |
| Method | register |
Bind a policy class to a resource type. |
| Method | registry |
Return the policy registry backing this authorizer. |
| Class Variable | __slots__ |
Undocumented |
| Instance Variable | __app |
Undocumented |
| Instance Variable | __registry |
Undocumented |
Initialise the authorizer with the application container.
| Parameters | |
app:IApplication | Container used to build policy instances with their own dependencies injected. |
| Returns | |
None | The registry starts empty and is filled during boot. |
IAuthenticationContext, ability: str, resource: object) -> bool:
(source)
¶
Evaluate a policy ability against a concrete resource.
| Parameters | |
context:IAuthenticationContext | Authentication context of the current request. |
ability:str | Ability declared by the policy of the resource. |
resource:object | Resource instance, or the resource class when the ability does not need an instance. |
| Returns | |
bool | True only when the policy explicitly allows the operation and the credential permits the named ability. Hooks cannot override credential restrictions. |
| Raises | |
PolicyNotFoundException | When the resource type has no policy, or the policy does not declare the requested ability. |
orionis.auth.contracts.IAuthorizer.canReport whether the context grants a permission.
| Parameters | |
context:IAuthenticationContext | Authentication context of the current request. |
permission:str | Permission name to evaluate. |
| Returns | |
bool | True when the permission is granted. |
IAuthenticationContext, permissions: Iterable[ str]) -> bool:
(source)
¶
Report whether the context grants every permission.
| Parameters | |
context:IAuthenticationContext | Authentication context of the current request. |
permissions:Iterable[str] | Permission names to evaluate. |
| Returns | |
bool | True when every permission is granted. |
IAuthenticationContext, permissions: Iterable[ str]) -> bool:
(source)
¶
Report whether the context grants at least one permission.
| Parameters | |
context:IAuthenticationContext | Authentication context of the current request. |
permissions:Iterable[str] | Permission names to evaluate. |
| Returns | |
bool | True when at least one permission is granted. |
Report whether the context owns a role.
| Parameters | |
context:IAuthenticationContext | Authentication context of the current request. |
role:str | Role name to evaluate. |
| Returns | |
bool | True when the role is assigned to the identity. |
Return the policy registry backing this authorizer.
| Returns | |
PolicyRegistry | Registry holding the resource to policy bindings. |