Skip to main content

PyPI CI Codecov Documentation Supported Python versions License

Overview

Library to help manage role based access controls for django services.

  • See the Getting started guide to setup your development environment.

  • See the How To Guide to learn about the fundamentals of edx-rbac and how to implement RBAC in your Django service.

License

The code in this repository is licensed under the AGPL 3.0 unless otherwise noted.

Please see LICENSE.txt for details.

How To Contribute

Contributions are very welcome.

Please read How To Contribute for details.

Even though they were written with edx-platform in mind, the guidelines should be followed for Open edX code in general.

PR description template should be automatically applied if you are sending PR from github interface; otherwise you can find it it at PULL_REQUEST_TEMPLATE.md

Issue report template should be automatically applied if you are sending it from github UI as well; otherwise you can find it at ISSUE_TEMPLATE.md

Reporting Security Issues

Please do not report security issues in public. Please email security@edx.org.

Getting Help

Have a question about this repository, or about Open edX in general? Please refer to this list of resources if you need any assistance.

Change Log

Unreleased

[1.3.3] - 2020-10-02

  • Removed python_2_unicode_compatible decorator.

[1.3.2] - 2020-07-28

  • PermissionRequiredForListingMixin.get_queryset() should allow falsey base_queryset properties, like an empty QuerySet object. Adds tests to verify that this is the case.

[1.3.1] - 2020-06-16

  • Update get_assignments() to guard against AnonymousUsers.

  • Update contexts_accessible_from_database() to use get_assignments() instead of building a “custom” QuerySet.

[1.3.0] - 2020-06-11

  • Adds a PermissionRequiredForListingMixin that can be used in DRF ModelViewSets and supports a list action. This should allow list actions to return all of the elements from a base_queryset that the requesting user has access to, either via their JWT or DB-assigned roles.

  • Adds/modifies utility functions that deal with permission-checking to support multiple roles and multiple contexts.

[1.2.1] - 2020-05-08

  • Exposes a new utils.feature_roles_from_jwt() function, which, given a decoded JWT, will provide a mapping of feature roles to contexts/identifiers.

  • Modifies utils.user_has_access_via_database() to check for multiple database role assignments for a given user and role name (i.e. uses a filter() instead of a get()).

[1.2.0] - 2020-04-30

  • Removed support for django 2.0 and 2.1

  • Added Support for Python 3.8

[1.1.3] - 2020-04-13

  • Added check for AnonymousUser in user_has_access_via_database to prevent 500 errors.

[1.1.2] - 2020-03-27

  • Added support for Django 2.0, 2.1, and 2.2.

[1.1.1] - 2020-03-02

  • Fix bug in implicit role check when the same role has multiple contexts available.

[1.1.0] - 2020-02-18

  • Update PermissionRequiredMixin to pass through an object to rule predicates, if self.get_permision_required exists and is callable

[1.0.5] - 2019-12-18

  • Updated requirements.

[1.0.4] - 2019-12-17

  • Updated utils for user with multiple contexts.

[1.0.3] - 2019-09-12

  • Use functools.wraps to prevent the decorator from swallowing the view name

[1.0.2] - 2019-07-12

  • store current request on thread local storage using crum.

[1.0.1] - 2019-05-27

  • edx-drf-extensions version upgrade.

[1.0.0] - 2019-05-20

  • Removed get_request_or_stub and get_decoded_jwt_from_request from utils.py

[0.2.1] - 2019-05-08

  • edx-drf-extensions version upgrade.

[0.2.0] - 2019-04-30

  • Check for JWT presence in implicit permission.

  • Refactor role retrieval to remove the dependency on django models for assigning roles.

[0.1.11] - 2019-04-08

  • Get JWT token from request.auth if it is not set on the cookie. This supports client credentials oauth2 flow.

[0.1.10] - 2019-04-01

  • Update context checks for implicit and explicit access for all resources access.

[0.1.9] - 2019-04-01

  • Adding support for checking context for implicit and explicit access.

[0.1.8] - 2019-03-22

  • Adding an additional argument for the permission_required decorator

[0.1.7] - 2019-03-20

  • Adding a mixin for authz permissions support.

[0.1.6] - 2019-03-19

  • Adding a decorator for authz permissions support.

[0.1.5] - 2019-03-18

  • Adding django admin support for models extending UserRoleAssignment.

[0.1.4] - 2019-03-07

  • Adding a number of utils for roles in JWTs and the database

[0.1.3] - 2019-03-07

  • Adding get_context to the UserRoleAssignment class.

[0.1.2] - 2019-03-06

  • Quality fixes

[0.1.1] - 2019-03-06

  • Bumping version so we get pip updated with new models we added

[0.1.0] - 2019-02-28

Added

  • First release on PyPI.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

edx-rbac-1.3.4.tar.gz (29.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

edx_rbac-1.3.4-py2.py3-none-any.whl (38.5 kB view details)

Uploaded Python 2Python 3

File details

Details for the file edx-rbac-1.3.4.tar.gz.

File metadata

  • Download URL: edx-rbac-1.3.4.tar.gz
  • Upload date:
  • Size: 29.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.3.0 pkginfo/1.6.1 requests/2.25.1 setuptools/51.1.0 requests-toolbelt/0.9.1 tqdm/4.55.1 CPython/3.8.7

File hashes

Hashes for edx-rbac-1.3.4.tar.gz
Algorithm Hash digest
SHA256 5dafdbb277e8e8a602a16318de0b018c694fd455fc3b08f1f991d6d29edcdb0c
MD5 aff5fe9a9d0e65b7f3eae3618bfe79e9
BLAKE2b-256 2246f4d1ebbaeb3d3bd9f8f0d27b391a8ac74684abe030dbc9764119c606c945

See more details on using hashes here.

File details

Details for the file edx_rbac-1.3.4-py2.py3-none-any.whl.

File metadata

  • Download URL: edx_rbac-1.3.4-py2.py3-none-any.whl
  • Upload date:
  • Size: 38.5 kB
  • Tags: Python 2, Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.3.0 pkginfo/1.6.1 requests/2.25.1 setuptools/51.1.0 requests-toolbelt/0.9.1 tqdm/4.55.1 CPython/3.8.7

File hashes

Hashes for edx_rbac-1.3.4-py2.py3-none-any.whl
Algorithm Hash digest
SHA256 1a3ed4f9e83ba31487a1ae1c597782621b2b69e1447f9b4497a50f7dfd415fe2
MD5 9b74179a79c447185deab4964e8c8251
BLAKE2b-256 b3abdc2fa57be7e6772fe8439b1405b9bff51042962b5b8d51eb601d3979de15

See more details on using hashes here.

Release history Release notifications | RSS feed

3.0.0

2 files

2.1.0

2 files

2.0.0

2 files

1.10.0

2 files

1.9.0

2 files

1.8.0

2 files

1.7.0

2 files

1.6.0

2 files

1.5.1

2 files

1.5.0

2 files

1.4.2

2 files

1.4.1

2 files

This release

1.3.4 This release

2 files

1.3.3

2 files

1.3.2

2 files

1.3.1

2 files

1.3.0

2 files

1.2.1

2 files

1.2.0

2 files

1.1.3

2 files

1.1.2

2 files

1.1.1

2 files

1.1.0

2 files

1.0.5

2 files

1.0.4

2 files

1.0.3

2 files

1.0.2

2 files

1.0.1

2 files

1.0.0

2 files

0.2.1

2 files

0.2.0

2 files

0.1.11

2 files

0.1.10

2 files

0.1.9

2 files

0.1.8

2 files

0.1.7

2 files

0.1.6

2 files

0.1.5

2 files

0.1.4

2 files

0.1.3

2 files

0.1.2

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page