ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

Enforce baseline HTTP security policies on every request.

The following checks are always active and are not configurable:

  • CRLF-injection detection in header names and values.
  • Rejection of requests carrying more than one Host header.

Host allowlist validation runs only when allowed_hosts is configured with an explicit list of host names.

Static Method __extractHostname Strip the optional port from a Host header value.
Method __init__ Initialize the middleware with the given security configuration.
Method __isAllowedHost Check a hostname against the configured allowlist.
Async Method handle Inspect the incoming request and enforce all security policies.
Class Variable __slots__ Undocumented
Instance Variable __allowed_host_suffixes Undocumented
Instance Variable __allowed_hosts Undocumented
Instance Variable __default_responses Undocumented
Instance Variable __enforce_hosts Undocumented
def __extractHostname(raw_host: str) -> str: (source)

Strip the optional port from a Host header value.

Handles both host:port and IPv6 literals such as [::1]:8000.

Parameters
raw_host:strThe raw Host header value.
Returns
strThe lowercase hostname without the port component.
def __init__(self, config: dict, default_responses: IDefaultResponses): (source)

Initialize the middleware with the given security configuration.

Parameters
config:dictA dictionary whose keys must match HTTPSecurity fields.
default_responses:IDefaultResponsesPredefined default responses for common HTTP errors.
Returns
NoneUndocumented
def __isAllowedHost(self, host: str) -> bool: (source)

Check a hostname against the configured allowlist.

Parameters
host:strLowercase hostname without the port component.
Returns
boolTrue when the host matches an exact entry or a wildcard subdomain pattern; False otherwise.
async def handle(self, adapter: TransportAdapter) -> Response | None: (source)

Inspect the incoming request and enforce all security policies.

Runs three sequential checks in order: CRLF-injection detection, duplicate Host header guard, and host allowlist validation. Returns a Response on the first violation, or None when all checks pass.

Parameters
adapter:TransportAdapterTransport abstraction providing header access and client-preference detection.
Returns
Response | NoneAn HTTP error response when a check fails, or None when the request is considered safe to proceed.
__slots__: tuple[str, ...] = (source)

Undocumented

__allowed_host_suffixes: tuple[str, ...] = (source)

Undocumented

__allowed_hosts: frozenset[str] = (source)

Undocumented

__default_responses = (source)

Undocumented

__enforce_hosts: bool = (source)

Undocumented