THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
class documentation
class IAccessTokenRepository(ABC): (source)
Define the persistence operations of personal access tokens.
Only a hash of the secret is stored, so a leaked database row never reveals a usable credential.
| Async Method | create |
Issue a new personal access token for an identity. |
| Async Method | find |
Resolve a token from the value presented by the client. |
| Async Method | purge |
Delete tokens that expired or were revoked. |
| Async Method | revoke |
Revoke a single token. |
| Async Method | revoke |
Revoke every active token of an identity. |
| Async Method | touch |
Confirm token validity and record its use atomically. |
| Class Variable | __slots__ |
Undocumented |
@abstractmethod
async def create(self, tokenable: IAuthorizable, name: str, *, abilities: Iterable[ str] | None = None, expires_at: datetime | None = None) -> NewAccessToken:
(source)
¶
Issue a new personal access token for an identity.
| Parameters | |
tokenable:IAuthorizable | Identity the token belongs to. |
name:str | Human readable label describing the token. |
abilities:Iterable[str] | None, optional | Abilities the token may use. None keeps the full authorization of the identity. |
expiresdatetime | None, optional | Moment the token stops being accepted. None falls back to the configured default expiration. |
| Returns | |
NewAccessToken | Stored token metadata plus the plain text value, which is the only moment the secret is available. |
Resolve a token from the value presented by the client.
Expired and revoked tokens are treated as absent.
| Parameters | |
plainstr | Value received in the Authorization header. |
| Returns | |
AccessToken | None | Matching token, or None when the value is unusable. |
Revoke every active token of an identity.
| Parameters | |
tokenable:IAuthorizable | Identity whose tokens must be revoked. |
| Returns | |
int | Number of tokens revoked by this call. |