Access policy SDK and provider support
Choose an integration#
Python SDK 0.2.3 supports caller-bound check_resources, filter_allowed, and
get_allowed_actions. Start with Python SDK setup, then
use the runtime-check guide
for response and failure behavior.
Although the Python signatures contain optional principal arguments, an explicit principal payload is rejected by the public backend. Use only the authenticated caller.
The JavaScript SDK's policy calls, Policy.checkResource and
Policy.getAllowedActions, send the same caller-bound check; see the
JavaScript SDK reference. The Refine
accessControlProvider (1.3.7 and later) sends Refine's list and show as
read, edit as update, and clone as create. It takes the policy kind,
such as datatable:orders, from params.entityType, then the resource's
meta.entityType, then the provider's entityType option. Without any of
those it sends the Refine resource name, which matches no policy, so the check
is denied. See Refine integration.
Registering a Refine provider doesn't protect routes; CanAccess and useCan
only decide what to show, and TaruviBase always enforces policies on the server.