aio-libs / aio-libs/aiohttp-security

Extend permission-checking methods to return additional information

未关闭
#241 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
240
派生
70
平均合并
10 分钟
30 天内合并 PR
3

描述

Extend `async def check_permission(request, permission, context=None) -> bool` to return back additional information.

Method `check_permission()` calls method `async def permits(...) -> bool` declared in `AuthPolicy` and defined in user-defined policies that inherit `AuthPolicy`. We need to have a general and unified way to return back information from `permits()` (and thus `check_permission()`).

**Use case**:
`check_permission` is called on a bunch of permissions and the calling code wants to know which exactly permission check was failed.

**Possible solutions**:
1. More narrow approach. In order to preserve backward compatibility, we could add method `check_permissions() -> PermissionCheckResult` (in addition to `permits() -> bool`) that returns a general dataclass (or json object) that will consolidate information on the permission check, for example:
```
T = TypeVar('T')

@dataclass
class PermissionCheckResult:
success: bool
missing: Set[T]

async def check_permissions(...) -> PermissionCheckResult:
...
```
2. More general and more pythonic approach. Keep `permits() -> bool`, but allow it to raise a pre-defined exception for providing additional information:
```
class PermissionDeniedException(Exception):
def __init__(self, missing_permissions):
pass
```

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。