ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

Hold the authenticated state of one request.

A context is created by the authentication middleware and stored in the container scope opened by the HTTP kernel. It is never attached to a singleton, so two requests running concurrently on the same event loop can never observe each other's identity.

Concurrency

The identity, the guard name and the abilities are fixed at construction time. The authorization snapshot is resolved lazily under an asyncio.Lock owned by this context, so several coroutines of the same request share a single database round trip.

Method __init__ Build the authentication context of a request.
Method __isCurrent Report whether this context still belongs to a live request.
Method __repr__ Return a debugging representation of the context.
Method _bindToScope Associate this context with one scope for its remaining lifetime.
Method _fork Copy the current identity into a fresh, independently scoped context.
Async Method authorization Return the effective authorization snapshot of the request.
Method identifier Return the unique identifier of the authenticated identity.
Class Variable __slots__ Undocumented
Instance Variable __abilities Undocumented
Instance Variable __credential_id Undocumented
Instance Variable __guard Undocumented
Instance Variable __identity Undocumented
Instance Variable __lock Undocumented
Instance Variable __repository Undocumented
Instance Variable __scope Undocumented
Instance Variable __snapshot Undocumented
Property abilities Return the abilities carried by the presented credential.
Property credentialId Return the identifier of the credential that authenticated.
Property guard Return the name of the guard that resolved the identity.
Property identity Return the authenticated identity of the request.
Property isAuthenticated Report whether the request carries an authenticated identity.
Property isGuest Report whether the request is anonymous.
def __init__(self, identity: IAuthenticatable | None = None, guard: str | None = None, abilities: Iterable[str] | None = None, repository: IPermissionRepository | None = None, credential_id: object | None = None): (source)

Build the authentication context of a request.

Parameters
identity:IAuthenticatable | None, optionalIdentity resolved by a guard, or None for a guest.
guard:str | None, optionalName of the guard that resolved the identity.
abilities:Iterable[str] | None, optionalAbilities restricting the presented credential.
repository:IPermissionRepository | None, optionalSource used to resolve the authorization snapshot. It is only required for authenticated contexts.
credential_id:object | None, optionalIdentifier of the revocable credential that authenticated the request, such as a personal access token.
Returns
NoneThe context starts without a resolved snapshot.
def __isCurrent(self) -> bool: (source)

Report whether this context still belongs to a live request.

Returns
boolFalse once replaced or once its owning scope has closed.
def __repr__(self) -> str: (source)

Return a debugging representation of the context.

Returns
strDescription exposing the guard and the identifier only, never any credential material.
def _bindToScope(self, scope: ScopeManager): (source)

Associate this context with one scope for its remaining lifetime.

Parameters
scope:ScopeManagerActive request scope publishing this context.
Returns
NoneLater reads verify that the context is still current in this scope.
Raises
AuthExceptionIf a context is shared between different request scopes.

Copy the current identity into a fresh, independently scoped context.

Framework lifecycles call this while the owning scope is current, then bind the returned context inside their new scope. Authorization remains lazy and is resolved independently; neither a cached permission snapshot nor the source scope or lock is retained. A stale context yields a guest.

Returns
AuthenticationContextUnbound context carrying the current identity and credential limits.
async def authorization(self) -> IAuthorizationSnapshot: (source)

Return the effective authorization snapshot of the request.

Returns
IAuthorizationSnapshotSnapshot resolved at most once per request. Guests and contexts without a permission repository resolve to the shared empty snapshot.
def identifier(self) -> object | None: (source)

Return the unique identifier of the authenticated identity.

Returns
object | NoneIdentifier of the identity, or None for a guest request.
__abilities: frozenset[str] | None = (source)

Undocumented

__credential_id = (source)

Undocumented

Undocumented

__identity = (source)

Undocumented

Undocumented

__repository = (source)

Undocumented

__scope: ScopeManager | None = (source)

Undocumented

__snapshot: IAuthorizationSnapshot | None = (source)

Undocumented

Return the abilities carried by the presented credential.

Returns
frozenset[str] | NoneAbilities of the credential, or None when unrestricted.

Return the identifier of the credential that authenticated.

Returns
object | NoneIdentifier of the revocable credential, or None when the guard uses none.

Return the name of the guard that resolved the identity.

Returns
str | NoneGuard name, or None when the request is anonymous.
identity: IAuthenticatable | None = (source)

Return the authenticated identity of the request.

Returns
IAuthenticatable | NoneResolved identity, or None for a guest request.
isAuthenticated: bool = (source)

Report whether the request carries an authenticated identity.

Returns
boolTrue when an identity was resolved by a guard.

Report whether the request is anonymous.

Returns
boolTrue when no identity was resolved by any guard.