THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
Create permissions and roles, and attach them to identities.
Database unique constraints decide concurrent insertions. Duplicate recovery uses a transaction or savepoint and verifies that the desired row exists before treating the operation as idempotent.
Concurrency
The registrar is stateless and safe as a singleton. Duplicate inserts lose against the primary or unique key and are resolved by reading the row that won.
| Async Method | __attach |
Insert a pivot row, ignoring an already existing one. |
| Async Method | __find |
Return the identifier of a named permission or role. |
| Async Method | __first |
Return the identifier of a row, inserting it when missing. |
| Method | __init__ |
Initialise the registrar with the model-less query gateway. |
| Async Method | assign |
Attach roles to an identity. |
| Async Method | create |
Create a permission, or return the existing one. |
| Async Method | create |
Create a role, or return the existing one. |
| Async Method | give |
Attach direct permissions to an identity. |
| Async Method | grant |
Attach permissions to a role. |
| Async Method | remove |
Detach roles from an identity. |
| Async Method | revoke |
Detach permissions from a role. |
| Async Method | revoke |
Detach direct permissions from an identity. |
| Class Variable | __slots__ |
Undocumented |
| Instance Variable | __db |
Undocumented |
Insert a pivot row, ignoring an already existing one.
| Parameters | |
table:str | Pivot table receiving the row. |
values:dict[str, object] | Columns forming the composite primary key. |
| Returns | |
None | The row is inserted, or silently skipped when present. |
| Raises | |
QueryException | If insertion fails and no identical pivot row exists. |
Return the identifier of a row, inserting it when missing.
The unique key decides concurrent insertions. A nested transaction rolls back a losing insert before the winning row is read, without aborting the caller's transaction.
| Parameters | |
table:str | Table holding the named rows. |
name:str | Name of the row. |
| Returns | |
object | Identifier of the existing or freshly created row. |
| Raises | |
QueryException | When the insert fails for a reason other than a duplicate. |
AuthException | When the name is empty, padded or longer than the schema permits. |
Initialise the registrar with the model-less query gateway.
| Parameters | |
db:IQueryBuilder | Gateway used to build queries over the authorization tables. |
| Returns | |
None | The registrar keeps only the injected gateway. |
Attach roles to an identity.
| Parameters | |
authorizable:IAuthorizable | Identity receiving the roles. |
*roles:str | Role names. Missing roles are created. |
| Returns | |
None | The pivot table is updated as a side effect. |
Attach direct permissions to an identity.
| Parameters | |
authorizable:IAuthorizable | Identity receiving the permissions. |
*permissions:str | Permission names. Missing permissions are created. |
| Returns | |
None | The pivot table is updated as a side effect. |
Detach roles from an identity.
| Parameters | |
authorizable:IAuthorizable | Identity losing the roles. |
*roles:str | Role names. Unknown names are ignored. |
| Returns | |
None | The pivot table is updated as a side effect. |
Detach direct permissions from an identity.
| Parameters | |
authorizable:IAuthorizable | Identity losing the permissions. |
*permissions:str | Permission names. Unknown names are ignored. |
| Returns | |
None | The pivot table is updated as a side effect. |