THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
class SecurityMiddleware: (source)
Constructor: SecurityMiddleware(config, default_responses)
Enforce baseline HTTP security policies on every request.
The following checks are always active and are not configurable:
- CRLF-injection detection in header names and values.
- Rejection of requests carrying more than one Host header.
Host allowlist validation runs only when allowed_hosts is configured with an explicit list of host names.
| Static Method | __extract |
Strip the optional port from a Host header value. |
| Method | __init__ |
Initialize the middleware with the given security configuration. |
| Method | __is |
Check a hostname against the configured allowlist. |
| Async Method | handle |
Inspect the incoming request and enforce all security policies. |
| Class Variable | __slots__ |
Undocumented |
| Instance Variable | __allowed |
Undocumented |
| Instance Variable | __allowed |
Undocumented |
| Instance Variable | __default |
Undocumented |
| Instance Variable | __enforce |
Undocumented |
Initialize the middleware with the given security configuration.
| Parameters | |
config:dict | A dictionary whose keys must match HTTPSecurity fields. |
defaultIDefaultResponses | Predefined default responses for common HTTP errors. |
| Returns | |
None | Undocumented |
Inspect the incoming request and enforce all security policies.
Runs three sequential checks in order: CRLF-injection detection, duplicate Host header guard, and host allowlist validation. Returns a Response on the first violation, or None when all checks pass.
| Parameters | |
adapter:TransportAdapter | Transport abstraction providing header access and client-preference detection. |
| Returns | |
Response | None | An HTTP error response when a check fails, or None when the request is considered safe to proceed. |