THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
class ModelIdentityProvider(IIdentityProvider): (source)
Constructor: ModelIdentityProvider(app, hasher)
Resolve identities from an Orionis model declared in configuration.
The model class is never imported at module load time. Its dotted path travels through config/auth.py, which keeps the framework free of any dependency on application code and allows any model to play the role of the authenticatable identity.
Concurrency
The provider is stateless apart from the memoised model class, which is a pure function of the configuration. A concurrent first import may resolve the same class twice with no observable difference.
| Method | __init__ |
Initialise the provider from the authentication configuration. |
| Method | __normalize |
Restore a stored scalar key to the model column's native type. |
| Method | model |
Return the model class backing the authenticated identity. |
| Async Method | retrieve |
Retrieve an identity matching the public credential. |
| Async Method | retrieve |
Retrieve an identity by its primary key. |
| Async Method | update |
Compare and replace an identity's remember token atomically. |
| Async Method | validate |
Verify the submitted password against the stored hash. |
| Class Variable | __slots__ |
Undocumented |
| Instance Variable | __hasher |
Undocumented |
| Instance Variable | __model |
Undocumented |
| Instance Variable | __model |
Undocumented |
| Instance Variable | __username |
Undocumented |
Initialise the provider from the authentication configuration.
| Parameters | |
app:IApplication | Application exposing the auth.identity configuration. |
hasher:IHashManager | Hashing service used to verify submitted passwords. |
| Returns | |
None | The model class stays unresolved until the first lookup. |
Restore a stored scalar key to the model column's native type.
| Parameters | |
identifier:object | Value obtained from a session or a token owner column. |
| Returns | |
object | None | Native integer, UUID or string, or None for an invalid key. |
Return the model class backing the authenticated identity.
| Returns | |
type[Model] | Model class resolved from the configured dotted path. |
| Raises | |
IdentityProviderException | When the path cannot be imported or the resolved class does
not implement IAuthenticatable. |
Retrieve an identity by its primary key.
| Parameters | |
identifier:object | Value previously returned by getAuthIdentifier(). |
| Returns | |
IAuthenticatable | None | Matching identity, or None when it no longer exists. |
IAuthenticatable, expected: str | None, token: str | None) -> bool:
(source)
¶
Compare and replace an identity's remember token atomically.
| Parameters | |
identity:IAuthenticatable | Identity whose remember token should be updated. |
expected:str | None | Current token expected in storage, or None if it is absent. |
token:str | None | Replacement token, or None to revoke the current token. |
| Returns | |
bool | True if exactly one eligible identity row was updated; otherwise, False. |
IAuthenticatable | None, credentials: Mapping[ str, object]) -> bool:
(source)
¶
Verify the submitted password against the stored hash.
The hashing module burns its cost on a worker thread, so the event loop stays free. Unknown identities still perform password hashing work. This reduces account enumeration signals without promising exact timing equality across hash algorithms or historical cost settings. Backend input errors are treated as invalid credentials.
| Parameters | |
identity:IAuthenticatable | None | Identity returned by retrieveByCredentials(). |
credentials:Mapping[str, object] | Submitted credentials. |
| Returns | |
bool | True only when the password matches the stored hash. |