Skip to main content

Django Group Role

Linters/Tests PyPI versions PyPI pyversions Django version

django-group-role aims to simplify "role based access" in django-based projects and applications. This app is build on top on contrib.auth and guardian apps.

django-group-role aims to enhance existing Group and Permission models of contrib.auth app to configure global-level access rules.

Install

First add 'django_group_role' to INSTALLED_APPS after contrib.auth and guardian and then configure the "role-definition" module:

INSTALLED_APPS = [
    ...
    "django.contrib.auth",
    ...
    "guardian",
    "django_group_role",
    ...
]

# every used role must be registered in this module
ROLES_MODULE = "myproject.roles"

Basic Setup

"Roles" are classes derived from django_group_role.roles.Role and should declare the following two attributes:

  • name: the name of the group which will be bound to this role (mandatory)
  • permissions: specify which permissions are granted to this role, it may be indicated in one of the following form:
    • a list of available permission which will be bound to this role, they must be provided using the notation '<appname>.<codename>'
    • a dict which keys can be app-names or <appname.model> (see example below)
from django_group_role import Role


class BasicRole(Role):
    name = "Base"
    abstract = True
    permissions = ["auth.view_user", "auth.view_group"]


class ExpandedRole(BasicRole):
    name = "Expanded"
    permissions = ["auth.add_user", "auth.change_user"]


class DerivedRole(BasicRole):
    name = "Derived"
    permissions = {
        'auth': {
            'user': ['view_user', 'add_user', 'delete_user']
        },
        'auth.group': ['view_group'],
    }

NOTE: to do not have the command creating a "base" group set it as abstract = True

Role inheritance

Roles can derive one-another like normal python classes, when a roles extend an other one it is not required to provide the permissions list. When extending an existing role its permissions gets merged with those defined in the base class.

NOTE: ATM multi-role inheritance is not tested, it may work but it is not guaranteed.

Database alignment

Since Role classes are not bound to database Group they must be synchronized in order to work as expected. To perform this the management command populate_roles is available. This command takes every configured role defined in ROLES_MODULE and set-up its permissions on the database, also creating the appropriate group if it does not exists yet.

See command help for further information regarding its arguments.

Signals

Upon setup each role fires two signals:

  • pre_role_setup: before the setup process starts, providing role and clear kwargs
  • post_role_setup: after the setup process ends, providing role kwargs

Use in unittest (TestCase)

For django style TestCase based testing is it possible to use the RoleEnabledTestMixin. This overrides the setUpTestData to load and create role-related data before running tests.

NOTE: ATM it is not guaranteed that loading different roles in each test may not collide, it could be released in the future.


Credits

This work was in part inspired by django-role-permissions.

Metadata

Release files for django-group-role 0.7.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for django-group-role 0.7.4
File Size Uploaded
django_group_role-0.7.4.tar.gz 13.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for django-group-role 0.7.4
File Interpreter ABI Platform
django_group_role-0.7.4-py3-none-any.whl Python 3 none any Details

Total release size: 27.4 kB

Release files / django_group_role-0.7.4.tar.gz

Download URL django_group_role-0.7.4.tar.gz
Size 13.8 kB
Tags Source
SHA-256 checksum
How to use checksums
864b84b534a1405eb85ace72d4ca40d8f21cc668b8692cba966add5507aeab91
BLAKE2b-256 checksum
How to use checksums
2b2a8ac38bed34481e6cc835f67f5d411350e15e89c3bbef6ab599f505600d6b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.12.3

Release files / django_group_role-0.7.4-py3-none-any.whl

Download URL django_group_role-0.7.4-py3-none-any.whl
Size 13.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
301189011b80541c1b8c710dfb7cfb921a83f8e80a9278bf84e8ef4ad1ba3e03
BLAKE2b-256 checksum
How to use checksums
548d805a045c9933012c619410ae4f61a94c692b38937fda729cfc40b083cda5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

0.7.4 This release

2 release files

0.7.3

2 release files

0.7.2

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page