ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

class IAuthorizationSnapshot(ABC): (source)

Known subclasses: orionis.auth.authorization.AuthorizationSnapshot

View In Hierarchy

Define the immutable authorization picture of a single request.

The snapshot is resolved at most once per request and answers every later can() call without touching the database again.

Method can Report whether the effective authorization grants a permission.
Method hasRole Report whether the identity owns a role.
Class Variable __slots__ Undocumented
Property abilities Return the abilities restricting the current credential.
Property permissions Return the permissions granted to the identity.
Property roles Return the role names assigned to the identity.
@abstractmethod
def can(self, permission: str) -> bool: (source)

Report whether the effective authorization grants a permission.

Parameters
permission:strPermission name to evaluate.
Returns
boolTrue when the identity owns the permission and the current credential is allowed to use it.
@abstractmethod
def hasRole(self, role: str) -> bool: (source)

Report whether the identity owns a role.

Parameters
role:strRole name to evaluate.
Returns
boolTrue when the role is assigned to the identity.
@property
@abstractmethod
abilities: frozenset[str] | None = (source)

Return the abilities restricting the current credential.

Returns
frozenset[str] | NoneAbilities carried by the access token, or None when the credential does not narrow the authorization of the identity.
@property
@abstractmethod
permissions: frozenset[str] = (source)

Return the permissions granted to the identity.

Returns
frozenset[str]Union of the direct permissions and the ones inherited from the roles of the identity.
@property
@abstractmethod
roles: frozenset[str] = (source)

Return the role names assigned to the identity.

Returns
frozenset[str]Role names, without any hierarchy or inheritance.