THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
class documentation
class IAuthorizer(ABC): (source)
Known subclasses: orionis.auth.authorization.authorizer.Authorizer
Define the component answering authorization questions.
The authorizer never owns the current identity. It receives the request context on every call, which keeps it safe to register as a singleton.
| Async Method | allows |
Evaluate a policy ability against a concrete resource. |
| Async Method | can |
Report whether the context grants a permission. |
| Async Method | can |
Report whether the context grants every permission. |
| Async Method | can |
Report whether the context grants at least one permission. |
| Async Method | has |
Report whether the context owns a role. |
| Method | register |
Bind a policy class to a resource type. |
| Class Variable | __slots__ |
Undocumented |
@abstractmethod
async def allows(self, context: IAuthenticationContext, ability: str, resource: object) -> bool:
(source)
¶
overridden in
orionis.auth.authorization.authorizer.AuthorizerEvaluate a policy ability against a concrete resource.
| Parameters | |
context:IAuthenticationContext | Authentication context of the current request. |
ability:str | Ability declared by the policy of the resource. |
resource:object | Resource instance, or the resource class when the ability does not need an instance. |
| Returns | |
bool | True when the policy allows the operation. |
| Raises | |
PolicyNotFoundException | When no policy is registered for the resource type. |
@abstractmethod
async def can(self, context: IAuthenticationContext, permission: str) -> bool:
(source)
¶
overridden in
orionis.auth.authorization.authorizer.AuthorizerReport whether the context grants a permission.
| Parameters | |
context:IAuthenticationContext | Authentication context of the current request. |
permission:str | Permission name to evaluate. |
| Returns | |
bool | True when the permission is granted. |
@abstractmethod
async def canAll(self, context: IAuthenticationContext, permissions: Iterable[ str]) -> bool:
(source)
¶
overridden in
orionis.auth.authorization.authorizer.AuthorizerReport whether the context grants every permission.
| Parameters | |
context:IAuthenticationContext | Authentication context of the current request. |
permissions:Iterable[str] | Permission names to evaluate. |
| Returns | |
bool | True when every permission is granted. |
@abstractmethod
async def canAny(self, context: IAuthenticationContext, permissions: Iterable[ str]) -> bool:
(source)
¶
overridden in
orionis.auth.authorization.authorizer.AuthorizerReport whether the context grants at least one permission.
| Parameters | |
context:IAuthenticationContext | Authentication context of the current request. |
permissions:Iterable[str] | Permission names to evaluate. |
| Returns | |
bool | True when at least one permission is granted. |
@abstractmethod
async def hasRole(self, context: IAuthenticationContext, role: str) -> bool:
(source)
¶
overridden in
orionis.auth.authorization.authorizer.AuthorizerReport whether the context owns a role.
| Parameters | |
context:IAuthenticationContext | Authentication context of the current request. |
role:str | Role name to evaluate. |
| Returns | |
bool | True when the role is assigned to the identity. |