THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
class IAuthManager(ABC): (source)
Define the public entry point of the authentication module.
The manager holds no per request state. Every call reads the authentication context from the container scope opened for the request, so a singleton registration is safe under concurrency.
| Async Method | allows |
Evaluate a policy ability against a resource. |
| Async Method | attempt |
Authenticate the current request from submitted credentials. |
| Async Method | authorization |
Return the effective authorization snapshot of the request. |
| Async Method | authorize |
Require a permission or abort the current operation. |
| Async Method | authorize |
Require a policy ability or abort the current operation. |
| Async Method | can |
Report whether the current request grants a permission. |
| Async Method | can |
Report whether every permission is granted. |
| Async Method | can |
Report whether at least one permission is granted. |
| Async Method | cannot |
Report whether the current request lacks a permission. |
| Method | check |
Report whether the current request is authenticated. |
| Method | context |
Return the authentication context of the current request. |
| Async Method | create |
Issue a personal access token. |
| Async Method | denies |
Report whether a policy ability is denied for a resource. |
| Method | guard |
Return a configured guard by name. |
| Method | guest |
Report whether the current request is anonymous. |
| Async Method | has |
Report whether the identity owns a role. |
| Method | identifier |
Return the identifier of the authenticated identity. |
| Async Method | login |
Authenticate an identity without verifying credentials. |
| Async Method | logout |
Drop the authenticated state of the current request. |
| Method | register |
Bind a policy class to a resource type. |
| Async Method | revoke |
Revoke the presented token and clear this request's identity. |
| Method | user |
Return the identity authenticated for the current request. |
| Class Variable | __slots__ |
Undocumented |
Mapping[ str, object], *, remember: bool = False) -> bool:
(source)
¶
Authenticate the current request from submitted credentials.
| Parameters | |
credentials:Mapping[str, object] | Submitted credentials, typically username and password. |
remember:bool, optional | Keep the browser signed in using a revocable persistent credential. |
| Returns | |
bool | True when the credentials matched and the session was started. |
Return the effective authorization snapshot of the request.
| Returns | |
IAuthorizationSnapshot | Immutable view of permissions, roles and token abilities. |
Require a permission or abort the current operation.
| Parameters | |
permission:str | Permission name to require. |
| Returns | |
None | Nothing is returned when the permission is granted. |
| Raises | |
AuthenticationException | When the request carries no authenticated identity. |
AuthorizationException | When the identity is authenticated but lacks the permission. |
Require a policy ability or abort the current operation.
| Parameters | |
ability:str | Ability declared by the policy of the resource. |
resource:object | Resource instance, or the resource class. |
| Returns | |
None | Nothing is returned when the policy allows the operation. |
| Raises | |
AuthenticationException | When the request carries no authenticated identity. |
AuthorizationException | When the policy denies the operation. |
Report whether the current request is authenticated.
| Returns | |
bool | True when an identity was resolved by a guard. |
Return the authentication context of the current request.
| Returns | |
IAuthenticationContext | Context bound to the active scope, or a shared guest context when the code runs outside an authenticated request. |
str, *, tokenable: IAuthorizable | None = None, abilities: Iterable[ str] | None = None, expires_at: datetime | None = None) -> NewAccessToken:
(source)
¶
Issue a personal access token.
| Parameters | |
name:str | Human readable label describing the token. |
tokenable:IAuthorizable | None, optional | Identity owning the token. None uses the identity authenticated for the current request. |
abilities:Iterable[str] | None, optional | Abilities the token may use. None keeps the full authorization of the identity. |
expiresdatetime | None, optional | Moment the token stops being accepted. |
| Returns | |
NewAccessToken | Stored token metadata plus its plain text value. |
| Raises | |
AuthenticationException | When no identity is available to own the token. |
AuthorizationException | When a token-authenticated request tries to issue another token. |
Return a configured guard by name.
| Parameters | |
name:str | None, optional | Guard name. None selects the configured default guard. |
| Returns | |
IGuard | Guard registered under the requested name. |
| Raises | |
GuardNotFoundException | When no guard is registered under the given name. |
Return the identifier of the authenticated identity.
| Returns | |
object | None | Identifier of the identity, or None for a guest request. |
Authenticate an identity without verifying credentials.
| Parameters | |
identity:IAuthenticatable | Identity to remember for subsequent requests. |
| Returns | |
None | The session and the request context are updated. |
Drop the authenticated state of the current request.
| Returns | |
None | The session and the request context are cleared. |
Revoke the presented token and clear this request's identity.
| Returns | |
bool | True when a token was revoked by this call. Requests authenticated through the session always answer False. |