dogwood.enforcement#
SDK-level enforcement modes for Dogwood authorization decisions.
The Rust Dogwood core evaluates policy and returns a policy decision. This module adds Python SDK rollout behavior around that decision: enforce denials, or run in log-only mode and report what would have happened.
Behavior matrix:
Dogwood decision |
SDK mode |
Enforcement result |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
- class dogwood.enforcement.EnforcementResult[source]#
Effective SDK decision for an evaluated Dogwood event or request.
decisionis the raw Dogwood policy result, usually"Allow"or"Deny".allowedis the effective SDK outcome after applyingmode. Inlog_onlymode, a Dogwood denial producesallowed=Trueandwould_have_denied=True.- decision: str | None#
- mode: Literal['enforce', 'log_only']#
- allowed: bool#
- policy_allowed: bool | None#
- would_have_denied: bool#
- response: Any = None#
- class dogwood.enforcement.PolicyEnforcer[source]#
Apply
enforceorlog_onlybehavior to Dogwood decisions.Wrap either the Python fallback
Authorizeror native authorizer-like objects. The wrapped authorizer still performs the Dogwood policy evaluation; this class only decides how that result affects the caller.- authorize(event)[source]#
Authorize an SDK
Eventusingauthorizer.is_authorized.- Parameters:
event (Any)
- Return type:
- is_authorized(event)[source]#
Alias for
authorize()forAuthorizer-like usage.- Parameters:
event (Any)
- Return type:
- dogwood.enforcement.apply_enforcement(response, mode='enforce')[source]#
Return the effective SDK outcome for a raw Dogwood response.
- Parameters:
response (Any)
mode (str)
- Return type:
- dogwood.enforcement.decision_text(response)[source]#
Extract
AlloworDenytext from common Dogwood response shapes.- Parameters:
response (Any)
- Return type:
str | None
- dogwood.enforcement.is_allowed_decision(response)[source]#
Return true when a raw Dogwood response or decision is
Allow.- Parameters:
response (Any)
- Return type:
bool