dogwood.native#

Native PyO3 wrappers around the Rust dogwood_language API.

The functions in this module are the closest Python surface to the reference Rust implementation described in Dogwood’s API and workflow guide.

Mapping to Rust:

  • NativeAuthorizer wraps dogwood_language::Authorizer::new(LoweredPolicySet) and feeds request events through Authorizer::is_authorized.

  • lower_to_cedar() maps to LoweredPolicySet::from_str(...).as_cedar().

  • cedar_schema() maps to LoweredPolicySet::cedar_schema_str().

  • validate_policy() maps to Validator::new().validate(&policies).

  • replay() maps to dogwood_language::replay_log.

All schema-backed operations require the maturin-built extension module dogwood._dogwood_native.

dogwood.native.available()[source]#

Return whether the Rust dogwood_language extension is importable.

Return type:

bool

dogwood.native.require_available()[source]#

Raise RuntimeError if the native Rust extension is unavailable.

Return type:

None

class dogwood.native.NativeAuthorizer[source]#

Persistent native Dogwood authorizer.

Rust mapping:

  • Builds ServiceSchema from event_schema_source or ServiceSchema::defaults().

  • Builds PolicySchema::from_cedarschema_str(policy_schema_source).

  • Lowers with LoweredPolicySet::from_str.

  • Stores dogwood_language::Authorizer and calls Authorizer::is_authorized for each request.

The object is stateful: every authorization call records the event in the underlying Rust authorizer history, so temporal policies can observe prior events.

authorize_request(action, principal, resource, input)[source]#

Authorize one request event and return "Allow" or "Deny".

Rust mapping: builds a dogwood_language::Event with kind "request" from the supplied action, principal, resource, and input, then calls Authorizer::is_authorized.

Parameters:
  • action (str)

  • principal (str)

  • resource (str)

  • input (dict[str, Any])

Return type:

str

dogwood.native.lower_to_cedar(policy_source, policy_schema_source, event_schema_source=None)[source]#

Lower Dogwood policy source to Cedar policy text.

Rust mapping: LoweredPolicySet::from_str followed by LoweredPolicySet::as_cedar rendering.

Parameters:
  • policy_source (str)

  • policy_schema_source (str)

  • event_schema_source (str | None)

Return type:

str

dogwood.native.cedar_schema(policy_source, policy_schema_source, event_schema_source=None)[source]#

Return the augmented Cedar schema emitted by Dogwood lowering.

Rust mapping: LoweredPolicySet::cedar_schema_str.

Parameters:
  • policy_source (str)

  • policy_schema_source (str)

  • event_schema_source (str | None)

Return type:

str

dogwood.native.validate_policy(policy_source, policy_schema_source, event_schema_source=None)[source]#

Validate policy source against the supplied schemas.

Rust mapping: LoweredPolicySet::from_str then Validator::new().validate(&policies).

Parameters:
  • policy_source (str)

  • policy_schema_source (str)

  • event_schema_source (str | None)

Return type:

dict[str, Any]

dogwood.native.replay(policy_source, policy_schema_source, trace_source, event_schema_source=None)[source]#

Replay a Dogwood trace and return CLI-style verdict lines.

Rust mapping: dogwood_language::replay_log after lowering the policy set against the provided action and optional event schemas.

Parameters:
  • policy_source (str)

  • policy_schema_source (str)

  • trace_source (str)

  • event_schema_source (str | None)

Return type:

str

dogwood.native.authorize_request(policy_source, policy_schema_source, action, principal, resource, input, event_schema_source=None)[source]#

One-shot native authorization.

Rust mapping: lower policy source into a fresh LoweredPolicySet, create a fresh Authorizer, build one request event, and call Authorizer::is_authorized. Prefer NativeAuthorizer for repeated decisions so parse/lower work happens once.

Parameters:
  • policy_source (str)

  • policy_schema_source (str)

  • action (str)

  • principal (str)

  • resource (str)

  • input (dict[str, Any])

  • event_schema_source (str | None)

Return type:

str