THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
class documentation
class RequirePolicyMiddleware(BaseMiddleware): (source)
Constructor: RequirePolicyMiddleware(authorizer)
Gate a route behind a policy ability declared on a resource class.
The middleware evaluates the ability against the resource class, which covers the gates that do not need a loaded row, such as viewAny or create:
class CanCreatePosts(RequirePolicyMiddleware):
ability = "create"
resource = Post
Abilities that depend on a concrete row belong in the controller, where the instance already exists:
await Auth.authorizeResource("update", post)
| Method | __init__ |
Initialise the middleware with the authorizer. |
| Async Method | handle |
Evaluate the policy and continue when it allows the operation. |
| Class Variable | __slots__ |
Undocumented |
| Class Variable | ability |
Undocumented |
| Class Variable | resource |
Undocumented |
| Instance Variable | _authorizer |
Undocumented |
Initialise the middleware with the authorizer.
| Parameters | |
authorizer:IAuthorizer | Component resolving and running the policy. |
| Returns | |
None | The middleware keeps no per request state. |
overrides
orionis.http.BaseMiddleware.handleEvaluate the policy and continue when it allows the operation.
| Parameters | |
request:Request | Incoming HTTP request, unused by this middleware. |
callNextCallable | Callable advancing to the next layer. |
| Returns | |
Response | Response produced by the rest of the pipeline. |
| Raises | |
AuthConfigurationException | When the subclass declares no ability or no resource. |
AuthenticationException | When the request carries no authenticated identity. |
AuthorizationException | When the policy denies the operation. |