THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
class SessionGuard(ISessionGuard): (source)
Constructor: SessionGuard(app, identities)
Resolve the identity of web requests from the HTTP session.
The guard never implements its own session storage: it reads and writes the session started by StartSessionMiddleware and reachable through request.state.session.
Concurrency
The guard is stateless and safe as a singleton. All per request state lives in the session object owned by the request itself.
| Static Method | __session |
Return the session attached to a request, when present. |
| Method | __init__ |
Initialise the guard from the authentication configuration. |
| Async Method | __restore |
Restore an identity from a persistent credential. |
| Async Method | attempt |
Validate credentials and start an authenticated session. |
| Method | login |
Persist an identity in the session of the current request. |
| Async Method | logout |
Drop the authenticated state from the session. |
| Async Method | resolve |
Resolve the identity remembered in the session. |
| Class Variable | __slots__ |
Undocumented |
| Instance Variable | __csrf |
Undocumented |
| Instance Variable | __csrf |
Undocumented |
| Instance Variable | __identities |
Undocumented |
| Instance Variable | __password |
Undocumented |
| Instance Variable | __remember |
Undocumented |
| Instance Variable | __session |
Undocumented |
| Property | name |
Return the configuration name of this guard. |
Return the session attached to a request, when present.
| Parameters | |
request:Request | Incoming HTTP request. |
| Returns | |
ISession | None | Session started by the web pipeline, or None for routes that do not start one. |
Initialise the guard from the authentication configuration.
| Parameters | |
app:IApplication | Application exposing the auth.session configuration. |
identities:IIdentityProvider | Provider turning a stored identifier into an identity. |
| Returns | |
None | Only the session key and the provider are retained. |
Restore an identity from a persistent credential.
| Parameters | |
request:Request | Incoming request carrying the remember-me credential. |
| Returns | |
GuardResult | None | Authenticated session result, or None if restoration fails. |
Request, credentials: Mapping[ str, object], *, remember: bool = False) -> IAuthenticatable | None:
(source)
¶
Validate credentials and start an authenticated session.
| Parameters | |
request:Request | Incoming HTTP request owning the session. |
credentials:Mapping[str, object] | Submitted credentials. |
remember:bool, optional | Persist a revocable login credential after password verification. |
| Returns | |
IAuthenticatable | None | Authenticated identity, or None when the credentials do not match. The answer never reveals whether the account exists or the password was wrong. |
Persist an identity in the session of the current request.
| Parameters | |
request:Request | Incoming HTTP request owning the session. |
identity:IAuthenticatable | Identity to remember for subsequent requests. |
| Returns | |
None | The session is mutated as a side effect. |
| Raises | |
AuthException | When the request has no session, which means the route is not part of the web pipeline, or the identity has no persisted key. |
Resolve the identity remembered in the session.
A session pointing at an identity that no longer exists is cleaned up so the next request starts as a guest.
| Parameters | |
request:Request | Incoming HTTP request. |
| Returns | |
GuardResult | None | Resolved identity, or None when the request is anonymous. |