ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

class ModelIdentityProvider(IIdentityProvider): (source)

Constructor: ModelIdentityProvider(app, hasher)

View In Hierarchy

Resolve identities from an Orionis model declared in configuration.

The model class is never imported at module load time. Its dotted path travels through config/auth.py, which keeps the framework free of any dependency on application code and allows any model to play the role of the authenticatable identity.

Concurrency

The provider is stateless apart from the memoised model class, which is a pure function of the configuration. A concurrent first import may resolve the same class twice with no observable difference.

Method __init__ Initialise the provider from the authentication configuration.
Method __normalizeIdentifier Restore a stored scalar key to the model column's native type.
Method model Return the model class backing the authenticated identity.
Async Method retrieveByCredentials Retrieve an identity matching the public credential.
Async Method retrieveById Retrieve an identity by its primary key.
Async Method updateRememberToken Compare and replace an identity's remember token atomically.
Async Method validateCredentials Verify the submitted password against the stored hash.
Class Variable __slots__ Undocumented
Instance Variable __hasher Undocumented
Instance Variable __model Undocumented
Instance Variable __model_path Undocumented
Instance Variable __username_field Undocumented
def __init__(self, app: IApplication, hasher: IHashManager): (source)

Initialise the provider from the authentication configuration.

Parameters
app:IApplicationApplication exposing the auth.identity configuration.
hasher:IHashManagerHashing service used to verify submitted passwords.
Returns
NoneThe model class stays unresolved until the first lookup.
def __normalizeIdentifier(self, identifier: object) -> object | None: (source)

Restore a stored scalar key to the model column's native type.

Parameters
identifier:objectValue obtained from a session or a token owner column.
Returns
object | NoneNative integer, UUID or string, or None for an invalid key.
def model(self) -> type[Model]: (source)

Return the model class backing the authenticated identity.

Returns
type[Model]Model class resolved from the configured dotted path.
Raises
IdentityProviderExceptionWhen the path cannot be imported or the resolved class does not implement IAuthenticatable.
async def retrieveByCredentials(self, credentials: Mapping[str, object]) -> IAuthenticatable | None: (source)

Retrieve an identity matching the public credential.

Parameters
credentials:Mapping[str, object]Submitted credentials. Only the configured username field is read; the secret is deliberately ignored here.
Returns
IAuthenticatable | NoneMatching identity, or None when no identity matches.
async def retrieveById(self, identifier: object) -> IAuthenticatable | None: (source)

Retrieve an identity by its primary key.

Parameters
identifier:objectValue previously returned by getAuthIdentifier().
Returns
IAuthenticatable | NoneMatching identity, or None when it no longer exists.
async def updateRememberToken(self, identity: IAuthenticatable, expected: str | None, token: str | None) -> bool: (source)

Compare and replace an identity's remember token atomically.

Parameters
identity:IAuthenticatableIdentity whose remember token should be updated.
expected:str | NoneCurrent token expected in storage, or None if it is absent.
token:str | NoneReplacement token, or None to revoke the current token.
Returns
boolTrue if exactly one eligible identity row was updated; otherwise, False.
async def validateCredentials(self, identity: IAuthenticatable | None, credentials: Mapping[str, object]) -> bool: (source)

Verify the submitted password against the stored hash.

The hashing module burns its cost on a worker thread, so the event loop stays free. Unknown identities still perform password hashing work. This reduces account enumeration signals without promising exact timing equality across hash algorithms or historical cost settings. Backend input errors are treated as invalid credentials.

Parameters
identity:IAuthenticatable | NoneIdentity returned by retrieveByCredentials().
credentials:Mapping[str, object]Submitted credentials.
Returns
boolTrue only when the password matches the stored hash.
__slots__: tuple[str, ...] = (source)

Undocumented

__hasher = (source)

Undocumented

__model: type[Model] | None = (source)

Undocumented

__model_path: str = (source)

Undocumented

__username_field: str = (source)

Undocumented