dogwood.native#
Native PyO3 wrappers around the Rust dogwood_language API.
The functions in this module are the closest Python surface to the reference Rust implementation described in Dogwood’s API and workflow guide.
Mapping to Rust:
NativeAuthorizerwrapsdogwood_language::Authorizer::new(LoweredPolicySet)and feeds request events throughAuthorizer::is_authorized.lower_to_cedar()maps toLoweredPolicySet::from_str(...).as_cedar().cedar_schema()maps toLoweredPolicySet::cedar_schema_str().validate_policy()maps toValidator::new().validate(&policies).replay()maps todogwood_language::replay_log.
All schema-backed operations require the maturin-built extension module
dogwood._dogwood_native.
- dogwood.native.available()[source]#
Return whether the Rust
dogwood_languageextension is importable.- Return type:
bool
- dogwood.native.require_available()[source]#
Raise
RuntimeErrorif the native Rust extension is unavailable.- Return type:
None
- class dogwood.native.NativeAuthorizer[source]#
Persistent native Dogwood authorizer.
Rust mapping:
Builds
ServiceSchemafromevent_schema_sourceorServiceSchema::defaults().Builds
PolicySchema::from_cedarschema_str(policy_schema_source).Lowers with
LoweredPolicySet::from_str.Stores
dogwood_language::Authorizerand callsAuthorizer::is_authorizedfor each request.
The object is stateful: every authorization call records the event in the underlying Rust authorizer history, so temporal policies can observe prior events.
- authorize_request(action, principal, resource, input)[source]#
Authorize one request event and return
"Allow"or"Deny".Rust mapping: builds a
dogwood_language::Eventwith kind"request"from the supplied action, principal, resource, and input, then callsAuthorizer::is_authorized.- Parameters:
action (str)
principal (str)
resource (str)
input (dict[str, Any])
- Return type:
str
- dogwood.native.lower_to_cedar(policy_source, policy_schema_source, event_schema_source=None)[source]#
Lower Dogwood policy source to Cedar policy text.
Rust mapping:
LoweredPolicySet::from_strfollowed byLoweredPolicySet::as_cedarrendering.- Parameters:
policy_source (str)
policy_schema_source (str)
event_schema_source (str | None)
- Return type:
str
- dogwood.native.cedar_schema(policy_source, policy_schema_source, event_schema_source=None)[source]#
Return the augmented Cedar schema emitted by Dogwood lowering.
Rust mapping:
LoweredPolicySet::cedar_schema_str.- Parameters:
policy_source (str)
policy_schema_source (str)
event_schema_source (str | None)
- Return type:
str
- dogwood.native.validate_policy(policy_source, policy_schema_source, event_schema_source=None)[source]#
Validate policy source against the supplied schemas.
Rust mapping:
LoweredPolicySet::from_strthenValidator::new().validate(&policies).- Parameters:
policy_source (str)
policy_schema_source (str)
event_schema_source (str | None)
- Return type:
dict[str, Any]
- dogwood.native.replay(policy_source, policy_schema_source, trace_source, event_schema_source=None)[source]#
Replay a Dogwood trace and return CLI-style verdict lines.
Rust mapping:
dogwood_language::replay_logafter lowering the policy set against the provided action and optional event schemas.- Parameters:
policy_source (str)
policy_schema_source (str)
trace_source (str)
event_schema_source (str | None)
- Return type:
str
- dogwood.native.authorize_request(policy_source, policy_schema_source, action, principal, resource, input, event_schema_source=None)[source]#
One-shot native authorization.
Rust mapping: lower policy source into a fresh
LoweredPolicySet, create a freshAuthorizer, build onerequestevent, and callAuthorizer::is_authorized. PreferNativeAuthorizerfor repeated decisions so parse/lower work happens once.- Parameters:
policy_source (str)
policy_schema_source (str)
action (str)
principal (str)
resource (str)
input (dict[str, Any])
event_schema_source (str | None)
- Return type:
str