feat: add OEP-66 queryset-scoping building blocks for DRF list endpoints - #569
Open
Abdul-Muqadim-Arbisoft wants to merge 1 commit into
Open
Conversation
Add a `scoping` module providing the reusable record-visibility layer from
OEP-66 ("Separating Authorization Concerns in List Endpoints") so DRF list
endpoints across the platform and its plugins can share it:
* ScopingPolicy — a typing.Protocol (structural interface, not an ABC).
Implementers need not import or inherit anything; type checkers verify
conformance statically. The single method is `scope(queryset, subject)`
(subject, not user, to match the openedx-authz subject-based model).
* ScopedQuerysetMixin — applies a view's `scoping_policy` on top of
`get_queryset()`. It duck-type-checks that the policy exposes a callable
`scope` and raises ImproperlyConfigured otherwise.
Using a Protocol + duck-typed runtime check (rather than an ABC) avoids
inheritance coupling across repos, keeps interface changes resilient, and
lets consumers implement the policy without a hard dependency on this base.
Bumps version to 10.7.0 and adds unit tests.
Abdul-Muqadim-Arbisoft
requested review from
Faraz32123,
feanil and
taimoor-ahmed-1
July 30, 2026 18:03
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add a
scopingmodule providing the reusable record-visibility layer from OEP-66 ("Separating Authorization Concerns in List Endpoints") so DRF list endpoints across the platform and its plugins can share it:scope(queryset, subject)(subject, not user, to match the openedx-authz subject-based model).scoping_policyon top ofget_queryset(). It duck-type-checks that the policy exposes a callablescopeand raises ImproperlyConfigured otherwise.Using a Protocol + duck-typed runtime check (rather than an ABC) avoids inheritance coupling across repos, keeps interface changes resilient, and lets consumers implement the policy without a hard dependency on this base.
Bumps version to 10.7.0 and adds unit tests.