ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

class Authorizer(IAuthorizer): (source)

Constructor: Authorizer(app)

View In Hierarchy

Answer authorization questions for a given request context.

The authorizer never stores the current identity: every method takes the request context as its first argument. That keeps the service stateless and therefore safe as a container singleton shared by every concurrent request.

Concurrency

Only policy classes are cached. Each evaluation builds a fresh policy in the caller's container scope, so injected request dependencies and mutable policy state are never retained by this singleton.

Method __init__ Initialise the authorizer with the application container.
Async Method allows Evaluate a policy ability against a concrete resource.
Async Method can Report whether the context grants a permission.
Async Method canAll Report whether the context grants every permission.
Async Method canAny Report whether the context grants at least one permission.
Async Method hasRole Report whether the context owns a role.
Method registerPolicy Bind a policy class to a resource type.
Method registry Return the policy registry backing this authorizer.
Class Variable __slots__ Undocumented
Instance Variable __app Undocumented
Instance Variable __registry Undocumented
def __init__(self, app: IApplication): (source)

Initialise the authorizer with the application container.

Parameters
app:IApplicationContainer used to build policy instances with their own dependencies injected.
Returns
NoneThe registry starts empty and is filled during boot.
async def allows(self, context: IAuthenticationContext, ability: str, resource: object) -> bool: (source)

Evaluate a policy ability against a concrete resource.

Parameters
context:IAuthenticationContextAuthentication context of the current request.
ability:strAbility declared by the policy of the resource.
resource:objectResource instance, or the resource class when the ability does not need an instance.
Returns
boolTrue only when the policy explicitly allows the operation and the credential permits the named ability. Hooks cannot override credential restrictions.
Raises
PolicyNotFoundExceptionWhen the resource type has no policy, or the policy does not declare the requested ability.
async def can(self, context: IAuthenticationContext, permission: str) -> bool: (source)

Report whether the context grants a permission.

Parameters
context:IAuthenticationContextAuthentication context of the current request.
permission:strPermission name to evaluate.
Returns
boolTrue when the permission is granted.
async def canAll(self, context: IAuthenticationContext, permissions: Iterable[str]) -> bool: (source)

Report whether the context grants every permission.

Parameters
context:IAuthenticationContextAuthentication context of the current request.
permissions:Iterable[str]Permission names to evaluate.
Returns
boolTrue when every permission is granted.
async def canAny(self, context: IAuthenticationContext, permissions: Iterable[str]) -> bool: (source)

Report whether the context grants at least one permission.

Parameters
context:IAuthenticationContextAuthentication context of the current request.
permissions:Iterable[str]Permission names to evaluate.
Returns
boolTrue when at least one permission is granted.
async def hasRole(self, context: IAuthenticationContext, role: str) -> bool: (source)

Report whether the context owns a role.

Parameters
context:IAuthenticationContextAuthentication context of the current request.
role:strRole name to evaluate.
Returns
boolTrue when the role is assigned to the identity.
def registerPolicy(self, resource: type, policy: type[IPolicy]): (source)

Bind a policy class to a resource type.

Parameters
resource:typeResource class protected by the policy.
policy:type[IPolicy]Policy class implementing the abilities.
Returns
NoneThe registry is updated as a side effect.
def registry(self) -> PolicyRegistry: (source)

Return the policy registry backing this authorizer.

Returns
PolicyRegistryRegistry holding the resource to policy bindings.

Undocumented

__registry = (source)

Undocumented