Skip to main content

Building blocks for zanzibar style ReBAC

Project description

zanzipy ✨

Zanzibar‑style authorization for Python, with a tiny DSL to declare your schema and a simple client to write and check permissions. Friendly, lightweight, and practical.

Install 📦

pip install zanzipy

Quick start 🚀

from zanzipy.dsl.builder import SchemaBuilder
from zanzipy.client import ZanzibarClient
from zanzipy.storage.repos.concrete.memory.relations import InMemoryRelationRepository

# Define schema with the fluent DSL
registry = (
    SchemaBuilder()
        .namespace("user").done()
        .namespace("document")
            .relation("owner", subjects=["user"])  # direct
            .permission("can_view", union=["owner"])  # computed
            .done()
        .build()
)

# Use the in‑memory repo for a zero‑dependency start
client = ZanzibarClient(schema=registry, relations_repository=InMemoryRelationRepository())

client.write("document:readme", "owner", "user:alice")
assert client.check("document:readme", "can_view", "user:alice")

That’s it. Add more relations/permissions with the DSL, and swap the repository when you’re ready to plug in your storage.

See the examples/ folder 📁 for more patterns (tuple‑to‑userset, groups, nested folders). A good starting point is examples/document_drive.py.

Quick start with mixins 🧩

Zanzipy also provides convenient mixins for Pythonic integration with your domain models.

from dataclasses import dataclass

from zanzipy.client import ZanzibarClient
from zanzipy.dsl.builder import SchemaBuilder
from zanzipy.engine_integration import ZanzibarEngine, configure_authorization
from zanzipy.integration.mixins import AuthorizableResource, AuthorizableSubject
from zanzipy.storage.repos.concrete.memory.relations import InMemoryRelationRepository

# Define a minimal schema (user + document)
registry = (
    SchemaBuilder()
        .namespace("user").done()
        .namespace("document")
            .relation("owner", subjects=["user"])  # direct relation
            .permission("can_view", union=["owner"])  # computed permission
            .done()
        .build()
)

# Wire up the engine used by the mixins
client = ZanzibarClient(schema=registry, relations_repository=InMemoryRelationRepository())
configure_authorization(ZanzibarEngine(client))

# Domain models using mixins
@dataclass
class User(AuthorizableSubject):
    id: str

    def get_subject_dict(self) -> dict:
        return {"namespace": "user", "id": self.id}


@dataclass
class Document(AuthorizableResource):
    id: str

    def get_resource_dict(self) -> dict:
        return {"namespace": "document", "id": self.id}


# Use high‑level helpers
alice = User(id="alice")
readme = Document(id="readme")

readme.grant(alice, "owner")  # writes a tuple: document:readme#owner@user:alice
assert readme.check(alice, "can_view")  # True via the computed permission

For a fuller mixins setup with groups, SQLAlchemy models, and caching, see examples/document_drive_sqlalchemy_and_mixins.py.

Key features 🧰

  • ✨ DSL‑first schema authoring (SchemaBuilder, NamespaceBuilder).
  • 🔗 Zanzibar semantics: relations, permissions, union/intersection/exclusion, tuple‑to‑userset.
  • ✅ Correctness‑first evaluation: cycle detection, max‑depth limits, and subject expansion.
  • 🧩 Simple client API: write, delete, check, list_objects, expand.
  • 🗄️ Storage‑agnostic: implement RelationRepository; start with in‑memory.
  • ⚡ Optional caching: tuple cache and compiled rule cache for hot paths.

When should you use zanzipy? 🤔

  • You want ReBAC embedded in your Python app without running another service.
  • You prefer a human‑readable, declarative schema (via a tiny DSL).
  • Your app has shared resources (e.g., docs, folders, teams) and needs roles, groups, or nested access patterns.
  • You need cross‑resource edges (tuple‑to‑userset) and clear, testable authorization logic.

License

Apache‑2.0

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

zanzipy-0.2.0.tar.gz (43.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

zanzipy-0.2.0-py3-none-any.whl (67.9 kB view details)

Uploaded Python 3

File details

Details for the file zanzipy-0.2.0.tar.gz.

File metadata

  • Download URL: zanzipy-0.2.0.tar.gz
  • Upload date:
  • Size: 43.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for zanzipy-0.2.0.tar.gz
Algorithm Hash digest
SHA256 5d7c35ca0b63c8d05b5ba92a17166d754e1974d46a00f5c7d6faa8d4e8066d7e
MD5 a06e9f08a3de25614fbdc93ec3fac9ab
BLAKE2b-256 faed65b6fc8940c3246bb12ed0b4d23e162bf5bc0134d2572286c83a5779aad4

See more details on using hashes here.

Provenance

The following attestation bundles were made for zanzipy-0.2.0.tar.gz:

Publisher: publish.yml on tylerchambers/zanzipy

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file zanzipy-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: zanzipy-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 67.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for zanzipy-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 e648af2913555b3db2c6e0674395604973898ef96ab6a411160c7d67341e2be1
MD5 149c8159088be6a6677a229e6499dba7
BLAKE2b-256 cd410bf154a15909725c363d2a19cefc8d5646898afe7e7560c1d97bc69e7e95

See more details on using hashes here.

Provenance

The following attestation bundles were made for zanzipy-0.2.0-py3-none-any.whl:

Publisher: publish.yml on tylerchambers/zanzipy

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page