dogwood.values#
Python value, event, response, and fallback authorizer types.
These classes mirror the names in dogwood_language so code written against
dogwood-py follows the Rust API shape. Schema-backed production behavior should
use dogwood.native; the classes here also power the temporary
schema-less fallback path.
- class dogwood.values.Decision[source]#
Authorization decision.
Rust mapping:
dogwood_language::Decision.- ALLOW = 'Allow'#
- DENY = 'Deny'#
- __new__(value)#
- class dogwood.values.Entity[source]#
Cedar entity uid wrapper.
Rust mapping: Dogwood events ultimately carry Cedar entity UIDs for principal/resource scope.
- ty: str#
- id: str#
- class dogwood.values.DogwoodRuleRef[source]#
Reference to an originating Dogwood rule.
Rust mapping:
dogwood_language::DogwoodRuleRef.- rule_index: int#
- cedar_policy_id: str#
- class dogwood.values.Diagnostics[source]#
Decision diagnostics.
Rust mapping:
dogwood_language::Diagnostics. Native diagnostics are not fully exposed through PyO3 yet; the fallback stores determining rule refs and errors.- reason: tuple[DogwoodRuleRef, ...] = ()#
- errors: tuple[str, ...] = ()#
- class dogwood.values.Response[source]#
Authorization response.
Rust mapping:
dogwood_language::Responsereturned byAuthorizer::is_authorizedfor decision-kind events.- diagnostics: Diagnostics#
- class dogwood.values.Event[source]#
Dogwood event.
Rust mapping:
dogwood_language::Event. An event generalizes a Cedar request with a first-classkindsuch asrequestorresponse. Decision kinds are defined by the Dogwood event schema; the default schema makesrequesta decision kind andresponsehistory-only.- action_name: str#
- kind_name: str#
- ts: int = 0#
- logged: dict[str, Any]#
- request_ctx: dict[str, Any]#
- entities: dict[str, dict[str, Any]]#
- classmethod builder(action, kind)[source]#
Start building an event.
Rust mapping:
Event::builder(action, kind).- Parameters:
action (str)
kind (str)
- Return type:
- property action: str#
- property kind: str#
- principal()[source]#
Return the request principal, if this event carries request scope.
Rust mapping:
Event::principal().- Return type:
str | None
- resource()[source]#
Return the request resource, if this event carries request scope.
Rust mapping:
Event::resource().- Return type:
str | None
- field(group, name)[source]#
Read one logged event field.
Rust mapping:
Event::field(group, name).- Parameters:
group (str)
name (str)
- Return type:
Any | None
- class dogwood.values.EventBuilder[source]#
Builder for
Event.Rust mapping:
dogwood_language::EventBuilder.- timestamp(ts)[source]#
Set the event timestamp.
Rust mapping:
EventBuilder::timestamp.- Parameters:
ts (int)
- Return type:
- principal(uid)[source]#
Set request principal scope.
Rust mapping:
EventBuilder::principal.- Parameters:
uid (str)
- Return type:
- resource(uid)[source]#
Set request resource scope.
Rust mapping:
EventBuilder::resource.- Parameters:
uid (str)
- Return type:
- field(group, name, value)[source]#
Add one logged event field.
Rust mapping:
EventBuilder::field.- Parameters:
group (str)
name (str)
value (Any)
- Return type:
- logged_group(group, value)[source]#
Add a full logged event field group.
- Parameters:
group (str)
value (dict[str, Any])
- Return type:
- request_context(group, name, value)[source]#
Add one Cedar request context field.
- Parameters:
group (str)
name (str)
value (Any)
- Return type:
- class dogwood.values.Authorizer[source]#
Stateful fallback authorizer.
Rust mapping:
dogwood_language::Authorizer. The native equivalent isdogwood.native.NativeAuthorizer; this class is the temporary schema-less Python fallback.