aio-libs / aio-libs/aiohttp-security

Extend permission-checking methods to return additional information

Đang mở
#241 2 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Python
Star
240
Fork
70
Merge trung bình
10 phút
Pull request đã merge (30 ngày)
3

Mô tả

Extend `async def check_permission(request, permission, context=None) -> bool` to return back additional information.

Method `check_permission()` calls method `async def permits(...) -> bool` declared in `AuthPolicy` and defined in user-defined policies that inherit `AuthPolicy`. We need to have a general and unified way to return back information from `permits()` (and thus `check_permission()`).

**Use case**:
`check_permission` is called on a bunch of permissions and the calling code wants to know which exactly permission check was failed.

**Possible solutions**:
1. More narrow approach. In order to preserve backward compatibility, we could add method `check_permissions() -> PermissionCheckResult` (in addition to `permits() -> bool`) that returns a general dataclass (or json object) that will consolidate information on the permission check, for example:
```
T = TypeVar('T')

@dataclass
class PermissionCheckResult:
success: bool
missing: Set[T]

async def check_permissions(...) -> PermissionCheckResult:
...
```
2. More general and more pythonic approach. Keep `permits() -> bool`, but allow it to raise a pre-defined exception for providing additional information:
```
class PermissionDeniedException(Exception):
def __init__(self, missing_permissions):
pass
```

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.