ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

class IAccessTokenRepository(ABC): (source)

View In Hierarchy

Define the persistence operations of personal access tokens.

Only a hash of the secret is stored, so a leaked database row never reveals a usable credential.

Async Method create Issue a new personal access token for an identity.
Async Method findByPlainText Resolve a token from the value presented by the client.
Async Method purgeExpired Delete tokens that expired or were revoked.
Async Method revoke Revoke a single token.
Async Method revokeAll Revoke every active token of an identity.
Async Method touch Confirm token validity and record its use atomically.
Class Variable __slots__ Undocumented
@abstractmethod
async def create(self, tokenable: IAuthorizable, name: str, *, abilities: Iterable[str] | None = None, expires_at: datetime | None = None) -> NewAccessToken: (source)

Issue a new personal access token for an identity.

Parameters
tokenable:IAuthorizableIdentity the token belongs to.
name:strHuman readable label describing the token.
abilities:Iterable[str] | None, optionalAbilities the token may use. None keeps the full authorization of the identity.
expires_at:datetime | None, optionalMoment the token stops being accepted. None falls back to the configured default expiration.
Returns
NewAccessTokenStored token metadata plus the plain text value, which is the only moment the secret is available.
@abstractmethod
async def findByPlainText(self, plain_text: str) -> AccessToken | None: (source)

Resolve a token from the value presented by the client.

Expired and revoked tokens are treated as absent.

Parameters
plain_text:strValue received in the Authorization header.
Returns
AccessToken | NoneMatching token, or None when the value is unusable.
@abstractmethod
async def purgeExpired(self) -> int: (source)

Delete tokens that expired or were revoked.

Returns
intNumber of rows removed from the store.
@abstractmethod
async def revoke(self, token_id: object) -> bool: (source)

Revoke a single token.

Parameters
token_id:objectIdentifier of the token to revoke.
Returns
boolTrue when a token was revoked by this call.
@abstractmethod
async def revokeAll(self, tokenable: IAuthorizable) -> int: (source)

Revoke every active token of an identity.

Parameters
tokenable:IAuthorizableIdentity whose tokens must be revoked.
Returns
intNumber of tokens revoked by this call.
@abstractmethod
async def touch(self, token_id: object) -> bool: (source)

Confirm token validity and record its use atomically.

Parameters
token_id:objectIdentifier of the token to update.
Returns
boolTrue only when a non-revoked, unexpired token was updated.
__slots__: tuple = (source)

Undocumented