THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
class AuthenticationContext(IAuthenticationContext): (source)
Constructor: AuthenticationContext(identity, guard, abilities, repository, ...)
Hold the authenticated state of one request.
A context is created by the authentication middleware and stored in the container scope opened by the HTTP kernel. It is never attached to a singleton, so two requests running concurrently on the same event loop can never observe each other's identity.
Concurrency
The identity, the guard name and the abilities are fixed at construction time. The authorization snapshot is resolved lazily under an asyncio.Lock owned by this context, so several coroutines of the same request share a single database round trip.
| Method | __init__ |
Build the authentication context of a request. |
| Method | __is |
Report whether this context still belongs to a live request. |
| Method | __repr__ |
Return a debugging representation of the context. |
| Method | _bind |
Associate this context with one scope for its remaining lifetime. |
| Method | _fork |
Copy the current identity into a fresh, independently scoped context. |
| Async Method | authorization |
Return the effective authorization snapshot of the request. |
| Method | identifier |
Return the unique identifier of the authenticated identity. |
| Class Variable | __slots__ |
Undocumented |
| Instance Variable | __abilities |
Undocumented |
| Instance Variable | __credential |
Undocumented |
| Instance Variable | __guard |
Undocumented |
| Instance Variable | __identity |
Undocumented |
| Instance Variable | __lock |
Undocumented |
| Instance Variable | __repository |
Undocumented |
| Instance Variable | __scope |
Undocumented |
| Instance Variable | __snapshot |
Undocumented |
| Property | abilities |
Return the abilities carried by the presented credential. |
| Property | credential |
Return the identifier of the credential that authenticated. |
| Property | guard |
Return the name of the guard that resolved the identity. |
| Property | identity |
Return the authenticated identity of the request. |
| Property | is |
Report whether the request carries an authenticated identity. |
| Property | is |
Report whether the request is anonymous. |
IAuthenticatable | None = None, guard: str | None = None, abilities: Iterable[ str] | None = None, repository: IPermissionRepository | None = None, credential_id: object | None = None):
(source)
¶
Build the authentication context of a request.
| Parameters | |
identity:IAuthenticatable | None, optional | Identity resolved by a guard, or None for a guest. |
guard:str | None, optional | Name of the guard that resolved the identity. |
abilities:Iterable[str] | None, optional | Abilities restricting the presented credential. |
repository:IPermissionRepository | None, optional | Source used to resolve the authorization snapshot. It is only required for authenticated contexts. |
credentialobject | None, optional | Identifier of the revocable credential that authenticated the request, such as a personal access token. |
| Returns | |
None | The context starts without a resolved snapshot. |
Report whether this context still belongs to a live request.
| Returns | |
bool | False once replaced or once its owning scope has closed. |
Return a debugging representation of the context.
| Returns | |
str | Description exposing the guard and the identifier only, never any credential material. |
Associate this context with one scope for its remaining lifetime.
| Parameters | |
scope:ScopeManager | Active request scope publishing this context. |
| Returns | |
None | Later reads verify that the context is still current in this scope. |
| Raises | |
AuthException | If a context is shared between different request scopes. |
Copy the current identity into a fresh, independently scoped context.
Framework lifecycles call this while the owning scope is current, then bind the returned context inside their new scope. Authorization remains lazy and is resolved independently; neither a cached permission snapshot nor the source scope or lock is retained. A stale context yields a guest.
| Returns | |
AuthenticationContext | Unbound context carrying the current identity and credential limits. |
Return the effective authorization snapshot of the request.
| Returns | |
IAuthorizationSnapshot | Snapshot resolved at most once per request. Guests and contexts without a permission repository resolve to the shared empty snapshot. |
Return the unique identifier of the authenticated identity.
| Returns | |
object | None | Identifier of the identity, or None for a guest request. |
Return the identifier of the credential that authenticated.
| Returns | |
object | None | Identifier of the revocable credential, or None when the guard uses none. |
Return the name of the guard that resolved the identity.
| Returns | |
str | None | Guard name, or None when the request is anonymous. |
Return the authenticated identity of the request.
| Returns | |
IAuthenticatable | None | Resolved identity, or None for a guest request. |
Report whether the request carries an authenticated identity.
| Returns | |
bool | True when an identity was resolved by a guard. |