Skip to content

Latest commit

 

History

History

Folders and files

README.md

simple_module_permissions

Role-based access control (RBAC) for simple_module apps. Users get roles, roles carry permissions, and route handlers declare required permissions at the decorator or dependency layer.

Pre-wired into any app scaffolded with smpy new.

Install

pip install simple_module_permissions

What it provides

  • Role and Permission SQLModel tables, seeded from module-registered defaults.
  • Direct user-level grants feed the framework's permission resolution through a grant source, so simple_module_hosting.permissions.RequiresPermission (re-exported as permissions.deps.RequiresPermission) and auth.deps.require_permission(...) both honour them.
  • Admin UI for assigning roles/permissions to users, reached through the users admin area at /users/admin; role and user editors live at /permissions/roles/{id}/edit and /permissions/users/{id}/edit.
  • register_permissions(self, registry) hook — every module declares its permission strings at boot via registry.add_group(...); the registry dedupes and persists them.

Usage

Declare permissions at module boot:

# modules/orders/orders/module.py
from simple_module_core.permissions import PermissionRegistry


class OrdersModule(ModuleBase):
    meta = ModuleMeta(name="orders")

    def register_permissions(self, registry: PermissionRegistry) -> None:
        registry.add_group("Orders", ["orders.read", "orders.write"])

Guard a route:

from fastapi import APIRouter, Depends
from permissions.deps import RequiresPermission  # type: ignore[import-not-found]

router = APIRouter()


@router.get("/orders", dependencies=[Depends(RequiresPermission("orders.read"))])
async def list_orders(): ...

Admin flow: navigate to /users/admin, create a role, assign permissions, assign the role to users.

Depends on

  • simple_module_core, simple_module_db, simple_module_hosting, simple_module_users

License

MIT — see LICENSE.