ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

Gate a route behind a policy ability declared on a resource class.

The middleware evaluates the ability against the resource class, which covers the gates that do not need a loaded row, such as viewAny or create:

class CanCreatePosts(RequirePolicyMiddleware):
    ability = "create"
    resource = Post

Abilities that depend on a concrete row belong in the controller, where the instance already exists:

await Auth.authorizeResource("update", post)
Method __init__ Initialise the middleware with the authorizer.
Async Method handle Evaluate the policy and continue when it allows the operation.
Class Variable __slots__ Undocumented
Class Variable ability Undocumented
Class Variable resource Undocumented
Instance Variable _authorizer Undocumented
def __init__(self, authorizer: IAuthorizer): (source)

Initialise the middleware with the authorizer.

Parameters
authorizer:IAuthorizerComponent resolving and running the policy.
Returns
NoneThe middleware keeps no per request state.
async def handle(self, request: Request, call_next: NextCallable) -> Response: (source)

Evaluate the policy and continue when it allows the operation.

Parameters
request:RequestIncoming HTTP request, unused by this middleware.
call_next:NextCallableCallable advancing to the next layer.
Returns
ResponseResponse produced by the rest of the pipeline.
Raises
AuthConfigurationExceptionWhen the subclass declares no ability or no resource.
AuthenticationExceptionWhen the request carries no authenticated identity.
AuthorizationExceptionWhen the policy denies the operation.
__slots__: tuple[str, ...] = (source)

Undocumented

ability: ClassVar[str] = (source)

Undocumented

resource: ClassVar[type | None] = (source)

Undocumented

_authorizer = (source)

Undocumented