ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

class RequirePermissionMiddleware(BaseMiddleware): (source)

Constructor: RequirePermissionMiddleware(authorizer)

View In Hierarchy

Require one or more permissions before reaching the controller.

The Orionis router attaches middleware classes, not parameterised instances, so the required permissions are declared by subclassing:

class CanManageUsers(RequirePermissionMiddleware):
    permissions = ("users.view", "users.update")

Route.get("/users", [UserController, "index"]).middleware(CanManageUsers)

Declaring the requirement as a real class keeps the compiled route cache valid, which a dynamically generated class could not do.

Method __init__ Initialise the middleware with the authorizer.
Async Method handle Evaluate the permissions and continue when they are granted.
Class Variable __slots__ Undocumented
Class Variable permissions Undocumented
Class Variable requires_all Undocumented
Instance Variable _authorizer Undocumented
def __init__(self, authorizer: IAuthorizer): (source)

Initialise the middleware with the authorizer.

Parameters
authorizer:IAuthorizerComponent evaluating the permissions of the request context.
Returns
NoneThe middleware keeps no per request state.
async def handle(self, request: Request, call_next: NextCallable) -> Response: (source)

Evaluate the permissions and continue when they are granted.

Parameters
request:RequestIncoming HTTP request, unused by this middleware.
call_next:NextCallableCallable advancing to the next layer.
Returns
ResponseResponse produced by the rest of the pipeline.
Raises
AuthConfigurationExceptionWhen the subclass declares no permission at all.
AuthenticationExceptionWhen the request carries no authenticated identity, which the handler turns into a 401 response.
AuthorizationExceptionWhen the identity is authenticated but not authorized, which the handler turns into a 403 response.
__slots__: tuple[str, ...] = (source)

Undocumented

permissions: ClassVar[tuple[str, ...]] = (source)

Undocumented

requires_all: ClassVar[bool] = (source)

Undocumented

_authorizer = (source)

Undocumented