ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

class ProxiesMiddleware: (source)

Constructor: ProxiesMiddleware(config)

View In Hierarchy

Normalize client IP and scheme using trusted proxy headers.

  • Supports multiple proxies (X-Forwarded-For chain)
  • Supports multiple headers (get_all)
  • Prevents spoofing via trusted proxy validation

The headers used to resolve the real client IP and the original scheme are an internal framework decision: the de-facto standard X-Forwarded-For and X-Forwarded-Proto headers are always used. Applications only declare which proxies are trusted via trusted_proxies.

Static Method __compile Compile proxy identifiers into network objects.
Static Method __parseIp Parse a string into an IP address object.
Method __init__ Initialize the middleware with the given proxy configuration.
Method __isTrustedAddress Determine whether a parsed address belongs to a trusted network.
Method __process Apply trusted-proxy normalization to the transport adapter.
Method __resolveForwardedChain Resolve the real client IP from the forwarded header chain.
Method __resolveScheme Determine the original request scheme from forwarded headers.
Method handle Process an ASGI/RSGI scope and normalize its client IP and scheme.
Constant _IP_HEADER Undocumented
Constant _PROTO_HEADER Undocumented
Class Variable __slots__ Undocumented
Instance Variable __enabled Undocumented
Instance Variable __trusted_networks Undocumented
def __compile(proxies: Iterable[str]) -> tuple[IPv4Network | IPv6Network, ...]: (source)

Compile proxy identifiers into network objects.

The special token 'private' expands into the standard RFC-1918 and loopback address ranges.

Parameters
proxies:Iterable[str]An iterable of CIDR strings or the keyword 'private'.
Returns
tuple[IPv4Network | IPv6Network, ...]Compiled network objects used for IP membership tests.

Parse a string into an IP address object.

Parameters
value:strThe string to parse.
Returns
IPv4Address | IPv6Address | NoneThe parsed address, or None when the string is not a well-formed IPv4 or IPv6 address.
def __init__(self, config: dict): (source)

Initialize the middleware with the given proxy configuration.

Parameters
config:dictA dictionary whose keys must match HTTPProxies fields.
Returns
NoneUndocumented
def __isTrustedAddress(self, addr: IPv4Address | IPv6Address) -> bool: (source)

Determine whether a parsed address belongs to a trusted network.

Parameters
addr:IPv4Address | IPv6AddressThe parsed IP address to evaluate.
Returns
boolTrue if the address is within a trusted network; False otherwise.
def __process(self, adapter: TransportAdapter): (source)

Apply trusted-proxy normalization to the transport adapter.

Parameters
adapter:TransportAdapterAbstraction over an RSGI or ASGI scope.
Returns
NoneMutates adapter in place; no value is returned.
def __resolveForwardedChain(self, adapter: TransportAdapter, fallback_ip: str) -> tuple[str, list[str], list[str]]: (source)

Resolve the real client IP from the forwarded header chain.

Walks the chain right-to-left to skip trusted intermediaries and find the first untrusted address.

Parameters
adapter:TransportAdapterTransport abstraction providing header access.
fallback_ip:strIP to return when no forwarded chain header is present.
Returns
tuple[str, list[str], list[str]]A three-element tuple of (real_ip, proxies, full_chain).
def __resolveScheme(self, adapter: TransportAdapter) -> str | None: (source)

Determine the original request scheme from forwarded headers.

Parameters
adapter:TransportAdapterTransport abstraction providing header access.
Returns
str or None'http' or 'https' when the header is valid; None otherwise.
def handle(self, adapter: TransportAdapter) -> TransportAdapter: (source)

Process an ASGI/RSGI scope and normalize its client IP and scheme.

Parameters
adapter:TransportAdapterThe transport adapter to process.
Returns
TransportAdapterThe same transport adapter with updated client and scheme fields.
_IP_HEADER: str = (source)

Undocumented

Value
'x-forwarded-for'
_PROTO_HEADER: str = (source)

Undocumented

Value
'x-forwarded-proto'
__slots__: tuple[str, ...] = (source)

Undocumented

__enabled = (source)

Undocumented

__trusted_networks = (source)

Undocumented