Skip to main content

graphql-authz

Build Status Coverage Status Version PyPI - Wheel Pyversions Download Discord

GraphQL-Authz is a Python port of GraphQL-Authz, the Casbin authorization middleware implementation in Node.js.

This package should be used with GraphQL-core 3, providing the capability to limit access to each GraphQL resource with the authorization middleware.

Installation

Install the package using pip.

pip install casbin-graphql-authz

Get Started

Limit the access to each GraphQL resource with a policy. For example, given this policy for an RBAC model:

p, authorized_user, hello, query

Authorization can be enforced using:

import casbin
from authz.middleware import enforcer_middleware

from graphql import (
    graphql_sync,
    GraphQLSchema,
    GraphQLObjectType,
    GraphQLField,
    GraphQLString,
)


schema = GraphQLSchema(
    query=GraphQLObjectType(
        name="RootQueryType",
        fields={
            "hello": GraphQLField(
                GraphQLString,
                resolve=lambda obj, info: "world")
        }))

enforcer = casbin.Enforcer("model_file.conf", "policy_file.csv")
authorization_middleware = enforcer_middleware(enforcer)

query = """{ hello }"""

# Authorized user ("authorized_user") has access to data
response = graphql_sync(
    schema,
    query,
    middleware=[authorization_middleware],
    context_value={"role": "authorized_user"}
)
assert response.data == {"hello": "world"}

# Unauthorized users ("unauthorized_user") are rejected
response = graphql_sync(
    schema,
    query,
    middleware=[authorization_middleware],
    context_value={"role": "unauthorized_user"}
)
assert response.errors[0].message == "unauthorized_user can not query hello"

For more interesting scenarios see tests folder.

Credits

Implementation was heavily inspired by the Node.js middleware GraphQL-Authz.

Authorization enforcement is based on Casbin authorization library.

Metadata

Release files for casbin-graphql-authz 1.5.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for casbin-graphql-authz 1.5.0
File Size Uploaded
casbin_graphql_authz-1.5.0.tar.gz 8.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for casbin-graphql-authz 1.5.0
File Interpreter ABI Platform
casbin_graphql_authz-1.5.0-py3-none-any.whl Python 3 none any Details

Total release size: 18.3 kB

Release files / casbin_graphql_authz-1.5.0.tar.gz

Download URL casbin_graphql_authz-1.5.0.tar.gz
Size 8.7 kB
Tags Source
SHA-256 checksum
How to use checksums
5669241e786b3d7492f062fa9df56c44deefb90e0aad762cf2b22ba4a1f309ef
BLAKE2b-256 checksum
How to use checksums
3b00f72c64841dc6ed783e97da3072f9b0bffbb6ebbdd686d67cb20d8ca98766
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.12.11

Release files / casbin_graphql_authz-1.5.0-py3-none-any.whl

Download URL casbin_graphql_authz-1.5.0-py3-none-any.whl
Size 9.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9cf33134964c1854e3596736a9878aa1819775fc3158e67eeb0042daa32a4bed
BLAKE2b-256 checksum
How to use checksums
1279b5a5e5cee66d049c057618b7cf78c2d88b87f3b555bfda70454c394b22f7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.12.11

Release history Release notifications | RSS feed

This release

1.5.0 This release

2 release files

1.4.0

2 release files

1.3.0

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page