THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
Normalize client IP and scheme using trusted proxy headers.
- Supports multiple proxies (X-Forwarded-For chain)
- Supports multiple headers (get_all)
- Prevents spoofing via trusted proxy validation
The headers used to resolve the real client IP and the original scheme are an internal framework decision: the de-facto standard X-Forwarded-For and X-Forwarded-Proto headers are always used. Applications only declare which proxies are trusted via trusted_proxies.
| Static Method | __compile |
Compile proxy identifiers into network objects. |
| Static Method | __parse |
Parse a string into an IP address object. |
| Method | __init__ |
Initialize the middleware with the given proxy configuration. |
| Method | __is |
Determine whether a parsed address belongs to a trusted network. |
| Method | __process |
Apply trusted-proxy normalization to the transport adapter. |
| Method | __resolve |
Resolve the real client IP from the forwarded header chain. |
| Method | __resolve |
Determine the original request scheme from forwarded headers. |
| Method | handle |
Process an ASGI/RSGI scope and normalize its client IP and scheme. |
| Constant | _IP |
Undocumented |
| Constant | _PROTO |
Undocumented |
| Class Variable | __slots__ |
Undocumented |
| Instance Variable | __enabled |
Undocumented |
| Instance Variable | __trusted |
Undocumented |
Compile proxy identifiers into network objects.
The special token 'private' expands into the standard RFC-1918 and loopback address ranges.
| Parameters | |
proxies:Iterable[str] | An iterable of CIDR strings or the keyword 'private'. |
| Returns | |
tuple[IPv4Network | IPv6Network, ...] | Compiled network objects used for IP membership tests. |
Parse a string into an IP address object.
| Parameters | |
value:str | The string to parse. |
| Returns | |
IPv4Address | IPv6Address | None | The parsed address, or None when the string is not a well-formed IPv4 or IPv6 address. |
Determine whether a parsed address belongs to a trusted network.
| Parameters | |
addr:IPv4Address | IPv6Address | The parsed IP address to evaluate. |
| Returns | |
bool | True if the address is within a trusted network; False otherwise. |
Apply trusted-proxy normalization to the transport adapter.
| Parameters | |
adapter:TransportAdapter | Abstraction over an RSGI or ASGI scope. |
| Returns | |
None | Mutates adapter in place; no value is returned. |
TransportAdapter, fallback_ip: str) -> tuple[ str, list[ str], list[ str]]:
(source)
¶
Resolve the real client IP from the forwarded header chain.
Walks the chain right-to-left to skip trusted intermediaries and find the first untrusted address.
| Parameters | |
adapter:TransportAdapter | Transport abstraction providing header access. |
fallbackstr | IP to return when no forwarded chain header is present. |
| Returns | |
tuple[str, list[str], list[str]] | A three-element tuple of (real_ip, proxies, full_chain). |
Determine the original request scheme from forwarded headers.
| Parameters | |
adapter:TransportAdapter | Transport abstraction providing header access. |
| Returns | |
str or None | 'http' or 'https' when the header is valid; None otherwise. |
Process an ASGI/RSGI scope and normalize its client IP and scheme.
| Parameters | |
adapter:TransportAdapter | The transport adapter to process. |
| Returns | |
TransportAdapter | The same transport adapter with updated client and scheme fields. |