BaseRequestHandler

DIRAC server has various passive components listening to incoming client requests and reacting accordingly by serving requested information, such as services or APIs.

This module is basic for each of these components and describes the basic concept of access to them.

class DIRAC.Core.Tornado.Server.private.BaseRequestHandler.BaseRequestHandler(application, request, **kwargs)

Bases: RequestHandler

This class primarily describes the process of processing an incoming request and the methods of authentication and authorization.

Each HTTP request is served by a new instance of this class.

For the sequence of method called, please refer to the tornado documentation.

In order to pass information around and keep some states, we use instance attributes. These are initialized in the initialize() method.

This class is basic for TornadoService and TornadoREST. Check them out, this is a good example of writing a new child class if needed.

digraph structure {
node [shape=plaintext]
RequestHandler [label="tornado.web.RequestHandler"];

{TornadoService, TornadoREST} -> BaseRequestHandler;
BaseRequestHandler -> RequestHandler [label="  inherit", fontsize=8];
}

In order to create a class that inherits from BaseRequestHandler, first you need to determine what HTTP methods need to be supported. Override the class variable SUPPORTED_METHODS by writing down the necessary methods there. Note that by default all HTTP methods are supported.

This class also defines some variables for writing your handler’s methods:

  • DEFAULT_AUTHORIZATION describes the general authorization rules for the entire handler

  • auth_<method name> describes authorization rules for a single method and has higher priority than DEFAULT_AUTHORIZATION

  • METHOD_PREFIX helps in finding the target method, see the _getMethod() methods, where described how exactly.

It is worth noting that DIRAC supports several ways to authorize the request and they are all descriptive in DEFAULT_AUTHENTICATION. Authorization schema is associated with _authz<SHEMA SHORT NAME> method and will be applied alternately as they are defined in the variable until one of them is successfully executed. If no authorization method completes successfully, access will be denied. The following authorization schemas are supported by default:

  • SSL (_authzSSL()) - reads the X509 certificate sent with the request

  • JWT (_authzJWT()) - reads the Bearer Access Token sent with the request

  • VISITOR (_authzVISITOR()) - authentication as visitor

Also, if necessary, you can create a new type of authorization by simply creating the appropriate method:

def _authzMYAUTH(self):
    '''Another authorization algorithm.'''
    # Do somthing
    return S_OK(credentials)  # return user credentials as a dictionary

The name of the component to monitor the developer can specify in the MONITORING_COMPONENT class variable, see MonitoringClient class for more details.

Review the class variables, explanatory comments. You are free to overwrite class variables to suit your needs.

The class contains methods that require implementation:

  • _pre_initialize()

  • _getCSAuthorizationSection()

  • _getMethod()

  • _getMethodArgs()

Some methods have basic behavior, but developers can rewrite them:

  • _getComponentInfoDict()

  • _monitorRequest()

Designed for overwriting in the final handler if necessary:

Warning

Do not change methods derived from tornado.web.RequestHandler, e.g.: initialize, prepare, get, post, etc.

Let’s analyze the incoming request processing algorithm.

https://dirac.readthedocs.io/en/integration/_images/BaseRequestHandler.png (source https://github.com/TaykYoku/DIRACIMGS/raw/main/BaseRequestHandler.svg)

But before the handler can accept requests, you need to start TornadoServer. At startup, HandlerManager call __pre_initialize() handler method that inspects the handler and its methods to generate tornados URLs of access to it:

  • specifies the full name of the component, including the name of the system to which it belongs as <System>/<Component>.

  • initialization of the main authorization class, see AuthManager for more details.

  • call __pre_initialize() that should explore the handler, prepare all the necessary attributes and most importantly - return the list of URL tornadoes

The first request starts the process of initializing the handler, see the initialize() method:

  • load all registered identity providers for authentication with access token, see __loadIdPs().

  • create a cls.log logger that should be used in the children classes instead of directly gLogger (this allows to carry the tornadoComponent information, crutial for centralized logging)

  • initialization of the monitoring specific to this handler, see _initMonitoring().

  • initialization of the target handler that inherit this one, see initializeHandler().

Next, first of all the tornados prepare method is called which does the following:

  • determines the name of the target method and checks its presence, see _getMethod().

  • request monitoring, see _monitorRequest().

  • authentication request using one of the available algorithms called DEFAULT_AUTHENTICATION, see _gatherPeerCredentials() for more details.

  • and finally authorizing the request to access the component, see authQuery for more details.

If all goes well, then a method is executed, the name of which coincides with the name of the request method (e.g.: get()) which does:

  • execute the target method in an executor a separate thread.

  • defines the arguments of the target method, see _getMethodArgs().

  • initialization of each request, see initializeRequest().

  • the result of the target method is processed in the main thread and returned to the client, see __execute().

BASE_URL = None
DEFAULT_AUTHENTICATION = ['SSL', 'JWT']
DEFAULT_AUTHORIZATION = None
DEFAULT_LOCATION = '/'
METHOD_PREFIX = 'export_'
SUPPORTED_METHODS = ('GET', 'HEAD', 'POST', 'DELETE', 'PATCH', 'PUT', 'OPTIONS')
__init__(application, request, **kwargs)
activityMonitoringReporter = None
add_header(name: str, value: bytes | str | Integral | datetime) None

Adds the given response header and value.

Unlike set_header, add_header may be called multiple times to return multiple values for the same header.

check_etag_header()

Checks the Etag header against requests’s If-None-Match.

Returns True if the request’s Etag matches and a 304 should be returned. For example:

self.set_etag_header()
if self.check_etag_header():
    self.set_status(304)
    return

This method is called automatically when the request is finished, but may be called earlier for applications that override compute_etag and want to do an early check for If-None-Match before completing the request. The Etag header should be set (perhaps with set_etag_header) before calling this method.

Verifies that the _xsrf cookie matches the _xsrf argument.

To prevent cross-site request forgery, we set an _xsrf cookie and include the same value as a non-cookie field with all POST requests. If the two do not match, we reject the form submission as a potential forgery.

The _xsrf value may be set as either a form field named _xsrf or in a custom HTTP header named X-XSRFToken or X-CSRFToken (the latter is accepted for compatibility with Django).

See http://en.wikipedia.org/wiki/Cross-site_request_forgery

Prior to release 1.1.1, this check was ignored if the HTTP header X-Requested-With: XMLHTTPRequest was present. This exception has been shown to be insecure and has been removed. For more information please see http://www.djangoproject.com/weblog/2011/feb/08/security/ http://weblog.rubyonrails.org/2011/2/8/csrf-protection-bypass-in-ruby-on-rails

Changed in version 3.2.2: Added support for cookie version 2. Both versions 1 and 2 are supported.

clear()

Resets all headers and content for this response.

clear_all_cookies(path='/', domain=None)

Deletes all the cookies the user sent with this request.

See clear_cookie for more information on the path and domain parameters.

Similar to set_cookie, the effect of this method will not be seen until the following request.

Changed in version 3.2: Added the path and domain parameters.

Deletes the cookie with the given name.

Due to limitations of the cookie protocol, you must pass the same path and domain to clear a cookie as were used when that cookie was set (but there is no way to find out on the server side which values were used for a given cookie).

Similar to set_cookie, the effect of this method will not be seen until the following request.

clear_header(name)

Clears an outgoing header, undoing a previous set_header call.

Note that this method does not apply to multi-valued headers set by add_header.

compute_etag()

Computes the etag header to be used for this request.

By default uses a hash of the content written so far.

May be overridden to provide custom etag implementations, or may return None to disable tornado’s default etag support.

property cookies

An alias for self.request.cookies <.httputil.HTTPServerRequest.cookies>.

create_signed_value(name, value, version=None)

Signs and timestamps a string so it cannot be forged.

Normally used via set_secure_cookie, but provided as a separate method for non-cookie uses. To decode a value not stored as a cookie use the optional value argument to get_secure_cookie.

Changed in version 3.2.1: Added the version argument. Introduced cookie version 2 and made it the default.

create_template_loader(template_path)

Returns a new template loader for the given path.

May be overridden by subclasses. By default returns a directory-based loader on the given path, using the autoescape and template_whitespace application settings. If a template_loader application setting is supplied, uses that instead.

property current_user

The authenticated user for this request.

This is set in one of two ways:

  • A subclass may override get_current_user(), which will be called automatically the first time self.current_user is accessed. get_current_user() will only be called once per request, and is cached for future access:

    def get_current_user(self):
        user_cookie = self.get_secure_cookie("user")
        if user_cookie:
            return json.loads(user_cookie)
        return None
    
  • It may be set as a normal variable, typically from an overridden prepare():

    @gen.coroutine
    def prepare(self):
        user_id_cookie = self.get_secure_cookie("user_id")
        if user_id_cookie:
            self.current_user = yield load_user(user_id_cookie)
    

Note that prepare() may be a coroutine while get_current_user() may not, so the latter form is necessary if loading the user requires asynchronous operations.

The user object may be any type of the application’s choosing.

data_received(chunk)

Implement this method to handle streamed request data.

Requires the .stream_request_body decorator.

static decode(encodedData)

Decode the json encoded string

Parameters:

encodedData – json encoded string

Returns:

the decoded objects, encoded object length

Arguably, the length of the encodedData is useless, but it is for compatibility

decode_argument(value, name=None)

Decodes an argument from the request.

The argument has been percent-decoded and is now a byte string. By default, this method decodes the argument as utf-8 and returns a unicode string, but this may be overridden in subclasses.

This method is used as a filter for both get_argument() and for values extracted from the url and passed to get()/post()/etc.

The name of the argument is provided if known, but may be None (e.g. for unnamed groups in the url regex).

async delete(*args, **kwargs)

Method to handle incoming DELETE requests.

detach()

Take control of the underlying stream.

Returns the underlying .IOStream object and stops all further HTTP processing. Intended for implementing protocols like websockets that tunnel over an HTTP handshake.

This method is only supported when HTTP/1.1 is used.

Added in version 5.1.

static encode(inData)

Encode the input data into a JSON string

Parameters:

inData – anything that can be serialized. Namely, anything that can be serialized by standard json package, datetime object, tuples, and any class that inherits from JSerializable

Returns:

a json string

finish(chunk=None)

Finishes this response, ending the HTTP request.

Passing a chunk to finish() is equivalent to passing that chunk to write() and then calling finish() with no arguments.

Returns a .Future which may optionally be awaited to track the sending of the response to the client. This .Future resolves when all the response data has been sent, and raises an error if the connection is closed before all data can be sent.

Changed in version 5.1: Now returns a .Future instead of None.

flush(include_footers=False, callback=None)

Flushes the current output buffer to the network.

The callback argument, if given, can be used for flow control: it will be run when all flushed data has been written to the socket. Note that only one flush callback can be outstanding at a time; if another flush occurs before the previous flush’s callback has been run, the previous callback will be discarded.

Changed in version 4.0: Now returns a .Future if no callback is given.

Deprecated since version 5.1: The callback argument is deprecated and will be removed in Tornado 6.0.

async get(*args, **kwargs)

Method to handle incoming GET requests. .. note:: all the arguments are already prepared in the prepare() method.

getCSOption(optionName, defaultValue=False)

Just for keeping same public interface

getProperties()
getRemoteAddress()

Just for keeping same public interface

getRemoteCredentials()

Get the credentials of the remote peer.

Returns:

Credentials dictionary of remote peer.

getUserDN()
getUserGroup()
getUserName()
get_argument(name, default=<object object>, strip=True)

Returns the value of the argument with the given name.

If default is not provided, the argument is considered to be required, and we raise a MissingArgumentError if it is missing.

If the argument appears in the url more than once, we return the last value.

The returned value is always unicode.

get_arguments(name, strip=True)

Returns a list of the arguments with the given name.

If the argument is not present, returns an empty list.

The returned values are always unicode.

get_body_argument(name, default=<object object>, strip=True)

Returns the value of the argument with the given name from the request body.

If default is not provided, the argument is considered to be required, and we raise a MissingArgumentError if it is missing.

If the argument appears in the url more than once, we return the last value.

The returned value is always unicode.

Added in version 3.2.

get_body_arguments(name, strip=True)

Returns a list of the body arguments with the given name.

If the argument is not present, returns an empty list.

The returned values are always unicode.

Added in version 3.2.

get_browser_locale(default='en_US')

Determines the user’s locale from Accept-Language header.

See http://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html#sec14.4

Returns the value of the request cookie with the given name.

If the named cookie is not present, returns default.

This method only returns cookies that were present in the request. It does not see the outgoing cookies set by set_cookie in this handler.

get_current_user()

Override to determine the current user from, e.g., a cookie.

This method may not be a coroutine.

get_login_url()

Override to customize the login URL based on the request.

By default, we use the login_url application setting.

get_query_argument(name, default=<object object>, strip=True)

Returns the value of the argument with the given name from the request query string.

If default is not provided, the argument is considered to be required, and we raise a MissingArgumentError if it is missing.

If the argument appears in the url more than once, we return the last value.

The returned value is always unicode.

Added in version 3.2.

get_query_arguments(name, strip=True)

Returns a list of the query arguments with the given name.

If the argument is not present, returns an empty list.

The returned values are always unicode.

Added in version 3.2.

Returns the given signed cookie if it validates, or None.

The decoded cookie value is returned as a byte string (unlike get_cookie).

Similar to get_cookie, this method only returns cookies that were present in the request. It does not see outgoing cookies set by set_secure_cookie in this handler.

Changed in version 3.2.1: Added the min_version argument. Introduced cookie version 2; both versions 1 and 2 are accepted by default.

Returns the signing key version of the secure cookie.

The version is returned as int.

get_status()

Returns the status code for our response.

get_template_namespace()

Returns a dictionary to be used as the default template namespace.

May be overridden by subclasses to add or modify values.

The results of this method will be combined with additional defaults in the tornado.template module and keyword arguments to render or render_string.

get_template_path()

Override to customize template path for each handler.

By default, we use the template_path application setting. Return None to load templates relative to the calling file.

get_user_locale()

Override to determine the locale from the authenticated user.

If None is returned, we fall back to get_browser_locale().

This method should return a tornado.locale.Locale object, most likely obtained via a call like tornado.locale.get("en")

async head(*args, **kwargs)

Method to handle incoming HEAD requests.

initialize(**kwargs)

Initialize the handler, called at every request.

It just calls __initialize()

If anything goes wrong, the client will get Connection aborted error. See details inside the method.

..warning::

DO NOT REWRITE THIS FUNCTION IN YOUR HANDLER ==> initialize in DISET became initializeRequest in HTTPS !

classmethod initializeHandler(componentInfo: dict)

This method for handler initializaion. This method is called only one time, at the first request. CAN be implemented by developer.

Parameters:

componentInfo – infos about component, see _getComponentInfoDict().

initializeRequest()

Called at every request, may be overwritten in your handler. CAN be implemented by developer.

isRegisteredUser()
property locale

The locale for the current session.

Determined by either get_user_locale, which you can override to set the locale based on, e.g., a user preference stored in a database, or get_browser_locale, which uses the Accept-Language header.

log = <DIRAC.FrameworkSystem.private.standardLogging.Logging.Logging object>
log_exception(typ, value, tb)

Override to customize logging of uncaught exceptions.

By default logs instances of HTTPError as warnings without stack traces (on the tornado.general logger), and all other exceptions as errors with stack traces (on the tornado.application logger).

Added in version 3.1.

on_connection_close()

Called in async handlers if the client closed the connection.

Override this to clean up resources associated with long-lived connections. Note that this method is called only if the connection was closed during asynchronous processing; if you need to do cleanup after every request override on_finish instead.

Proxies may keep a connection open for a time (perhaps indefinitely) after the client has gone away, so this method may not be called promptly after the end user closes their connection.

on_finish()

Called after the end of HTTP request. Log the request duration

async options(*args, **kwargs)

Method to handle incoming OPTIONS requests.

async patch(*args, **kwargs)

Method to handle incoming PATCH requests.

async post(*args, **kwargs)

Method to handle incoming POST requests.

async prepare()

Tornados prepare method that called before request

async put(*args, **kwargs)

Method to handle incoming PUT requests.

redirect(url, permanent=False, status=None)

Sends a redirect to the given (optionally relative) URL.

If the status argument is specified, that value is used as the HTTP status code; otherwise either 301 (permanent) or 302 (temporary) is chosen based on the permanent argument. The default is 302 (temporary).

render(template_name, **kwargs)

Renders the template with the given arguments as the response.

render() calls finish(), so no other output methods can be called after it.

Returns a .Future with the same semantics as the one returned by finish. Awaiting this .Future is optional.

Changed in version 5.1: Now returns a .Future instead of None.

render_embed_css(css_embed)

Default method used to render the final embedded css for the rendered webpage.

Override this method in a sub-classed controller to change the output.

render_embed_js(js_embed)

Default method used to render the final embedded js for the rendered webpage.

Override this method in a sub-classed controller to change the output.

render_linked_css(css_files)

Default method used to render the final css links for the rendered webpage.

Override this method in a sub-classed controller to change the output.

render_linked_js(js_files)

Default method used to render the final js links for the rendered webpage.

Override this method in a sub-classed controller to change the output.

render_string(template_name, **kwargs)

Generate the given template with the given arguments.

We return the generated byte string (in utf8). To generate and write a template as a response, use render() above.

require_setting(name, feature='this feature')

Raises an exception if the given app setting is not defined.

reverse_url(name, *args)

Alias for Application.reverse_url.

send_error(status_code=500, **kwargs)

Sends the given HTTP error code to the browser.

If flush() has already been called, it is not possible to send an error, so this method will simply terminate the response. If output has been written but not yet flushed, it will be discarded and replaced with the error page.

Override write_error() to customize the error page that is returned. Additional keyword arguments are passed through to write_error.

Sets an outgoing cookie name/value with the given options.

Newly-set cookies are not immediately visible via get_cookie; they are not present until the next request.

expires may be a numeric timestamp as returned by time.time, a time tuple as returned by time.gmtime, or a datetime.datetime object.

Additional keyword arguments are set on the cookies.Morsel directly. See https://docs.python.org/3/library/http.cookies.html#http.cookies.Morsel for available attributes.

set_default_headers()

Override this to set HTTP headers at the beginning of the request.

For example, this is the place to set a custom Server header. Note that setting such headers in the normal flow of request processing may not do what you want, since headers may be reset during error handling.

set_etag_header()

Sets the response’s Etag header using self.compute_etag().

Note: no header will be set if compute_etag() returns None.

This method is called automatically when the request is finished.

set_header(name: str, value: bytes | str | Integral | datetime) None

Sets the given response header name and value.

If a datetime is given, we automatically format it according to the HTTP specification. If the value is not a string, we convert it to a string. All header values are then encoded as UTF-8.

Signs and timestamps a cookie so it cannot be forged.

You must specify the cookie_secret setting in your Application to use this method. It should be a long, random sequence of bytes to be used as the HMAC secret for the signature.

To read a cookie set with this method, use get_secure_cookie().

Note that the expires_days parameter sets the lifetime of the cookie in the browser, but is independent of the max_age_days parameter to get_secure_cookie.

Secure cookies may contain arbitrary byte values, not just unicode strings (unlike regular cookies)

Similar to set_cookie, the effect of this method will not be seen until the following request.

Changed in version 3.2.1: Added the version argument. Introduced cookie version 2 and made it the default.

set_status(status_code, reason=None)

Sets the status code for our response.

Parameters:
  • status_code (int) – Response status code.

  • reason (str) – Human-readable reason phrase describing the status code. If None, it will be filled in from http.client.responses or “Unknown”.

Changed in version 5.0: No longer validates that the response code is in http.client.responses.

property settings

An alias for self.application.settings <Application.settings>.

classmethod srv_getCSOption(optionName, defaultValue=False)

Get an option from the CS section of the services

Returns:

Value for serviceSection/optionName in the CS being defaultValue the default

srv_getFormattedRemoteCredentials()

Return the DN of user

Mostly copy paste from DIRAC.Core.DISET.private.Transports.BaseTransport.BaseTransport.getFormattedCredentials()

Note that the information will be complete only once the AuthManager was called

srv_getRemoteAddress()

Get the address of the remote peer.

Returns:

Address of remote peer.

srv_getRemoteCredentials()

Get the credentials of the remote peer.

Returns:

Credentials dictionary of remote peer.

static_url(path, include_host=None, **kwargs)

Returns a static URL for the given relative static file path.

This method requires you set the static_path setting in your application (which specifies the root directory of your static files).

This method returns a versioned url (by default appending ?v=<signature>), which allows the static files to be cached indefinitely. This can be disabled by passing include_version=False (in the default implementation; other static file implementations are not required to support this, but they may support other options).

By default this method returns URLs relative to the current host, but if include_host is true the URL returned will be absolute. If this handler has an include_host attribute, that value will be used as the default for all static_url calls that do not pass include_host as a keyword argument.

write(chunk)

Writes the given chunk to the output buffer.

To write the output to the network, use the flush() method below.

If the given chunk is a dictionary, we write it as JSON and set the Content-Type of the response to be application/json. (if you want to send JSON as a different Content-Type, call set_header after calling write()).

Note that lists are not converted to JSON because of a potential cross-site security vulnerability. All JSON output should be wrapped in a dictionary. More details at http://haacked.com/archive/2009/06/25/json-hijacking.aspx/ and https://github.com/facebook/tornado/issues/1009

write_error(status_code, **kwargs)

Override to implement custom error pages.

write_error may call write, render, set_header, etc to produce output as usual.

If this error was caused by an uncaught exception (including HTTPError), an exc_info triple will be available as kwargs["exc_info"]. Note that this exception may not be the “current” exception for purposes of methods like sys.exc_info() or traceback.format_exc.

xsrf_form_html()

An HTML <input/> element to be included with all POST forms.

It defines the _xsrf input value, which we check on all POST requests to prevent cross-site request forgery. If you have set the xsrf_cookies application setting, you must include this HTML within all of your HTML forms.

In a template, this method should be called with {% module xsrf_form_html() %}

See check_xsrf_cookie() above for more information.

property xsrf_token

The XSRF-prevention token for the current user/session.

To prevent cross-site request forgery, we set an ‘_xsrf’ cookie and include the same ‘_xsrf’ value as an argument with all POST requests. If the two do not match, we reject the form submission as a potential forgery.

See http://en.wikipedia.org/wiki/Cross-site_request_forgery

This property is of type bytes, but it contains only ASCII characters. If a character string is required, there is no need to base64-encode it; just decode the byte string as UTF-8.

Changed in version 3.2.2: The xsrf token will now be have a random mask applied in every request, which makes it safe to include the token in pages that are compressed. See http://breachattack.com for more information on the issue fixed by this change. Old (version 1) cookies will be converted to version 2 when this method is called unless the xsrf_cookie_version Application setting is set to 1.

Changed in version 4.3: The xsrf_cookie_kwargs Application setting may be used to supply additional cookie options (which will be passed directly to set_cookie). For example, xsrf_cookie_kwargs=dict(httponly=True, secure=True) will set the secure and httponly flags on the _xsrf cookie.

class DIRAC.Core.Tornado.Server.private.BaseRequestHandler.TornadoResponse(payload=None, status_code=None)

Bases: object

BaseRequestHandler uses multithreading to process requests, so the logic you describe in the target method in the handler that inherit BaseRequestHandler will be called in a non-main thread.

Tornado warns that “methods on RequestHandler and elsewhere in Tornado are not thread-safe” https://www.tornadoweb.org/en/stable/web.html#thread-safety-notes.

This class registers tornado methods with arguments in the same order they are called from TornadoResponse instance to call them later in the main thread and can be useful if you are afraid to use Tornado methods in a non-main thread due to a warning from Tornado.

This is used in exceptional cases, in most cases it is not required, just use return S_OK(data) instead.

Usage example:

class MyHandler(BaseRequestHandlerChildHandler):

    def export_myTargetMethod(self):
        # Here we want to use the tornado method, but we want to do it in the main thread.
        # Let's create an TornadoResponse instance and
        # call the tornado methods we need in the order in which we want them to run in the main thread.
        resp = TornadoResponse('data')
        resp.set_header("Content-Type", "application/x-tar")
        # And finally, for example, redirect to another place
        return resp.redirect('https://my_another_server/redirect_endpoint')
__init__(payload=None, status_code=None)

C’or

Parameters:
  • payload – response body

  • status_code (int) – response status code

DIRAC.Core.Tornado.Server.private.BaseRequestHandler.authentication(val)

Decorator to determine authentication types

Usage:

@authentication(["SSL", "VISITOR"])
def export_myMethod(self):
    pass
DIRAC.Core.Tornado.Server.private.BaseRequestHandler.authorization(val)

Decorator to determine authorization requirements

Usage:

@authorization(["authenticated"])
def export_myMethod(self):
    pass
DIRAC.Core.Tornado.Server.private.BaseRequestHandler.set_attribute(attr, val)

Decorator to determine target method settings. Set method attribute.

Usage:

@set_attribute('my attribure', 'value')
def export_myMethod(self):
    pass