ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

Define the component answering authorization questions.

The authorizer never owns the current identity. It receives the request context on every call, which keeps it safe to register as a singleton.

Async Method allows Evaluate a policy ability against a concrete resource.
Async Method can Report whether the context grants a permission.
Async Method canAll Report whether the context grants every permission.
Async Method canAny Report whether the context grants at least one permission.
Async Method hasRole Report whether the context owns a role.
Method registerPolicy Bind a policy class to a resource type.
Class Variable __slots__ Undocumented
@abstractmethod
async def allows(self, context: IAuthenticationContext, ability: str, resource: object) -> bool: (source)

Evaluate a policy ability against a concrete resource.

Parameters
context:IAuthenticationContextAuthentication context of the current request.
ability:strAbility declared by the policy of the resource.
resource:objectResource instance, or the resource class when the ability does not need an instance.
Returns
boolTrue when the policy allows the operation.
Raises
PolicyNotFoundExceptionWhen no policy is registered for the resource type.
@abstractmethod
async def can(self, context: IAuthenticationContext, permission: str) -> bool: (source)

Report whether the context grants a permission.

Parameters
context:IAuthenticationContextAuthentication context of the current request.
permission:strPermission name to evaluate.
Returns
boolTrue when the permission is granted.
@abstractmethod
async def canAll(self, context: IAuthenticationContext, permissions: Iterable[str]) -> bool: (source)

Report whether the context grants every permission.

Parameters
context:IAuthenticationContextAuthentication context of the current request.
permissions:Iterable[str]Permission names to evaluate.
Returns
boolTrue when every permission is granted.
@abstractmethod
async def canAny(self, context: IAuthenticationContext, permissions: Iterable[str]) -> bool: (source)

Report whether the context grants at least one permission.

Parameters
context:IAuthenticationContextAuthentication context of the current request.
permissions:Iterable[str]Permission names to evaluate.
Returns
boolTrue when at least one permission is granted.
@abstractmethod
async def hasRole(self, context: IAuthenticationContext, role: str) -> bool: (source)

Report whether the context owns a role.

Parameters
context:IAuthenticationContextAuthentication context of the current request.
role:strRole name to evaluate.
Returns
boolTrue when the role is assigned to the identity.
@abstractmethod
def registerPolicy(self, resource: type, policy: type[IPolicy]): (source)

Bind a policy class to a resource type.

Parameters
resource:typeResource class protected by the policy.
policy:type[IPolicy]Policy class implementing the abilities.
Returns
NoneThe registry is updated as a side effect.