THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
class AuthenticateMiddleware(ResolveIdentityMiddleware): (source)
Known subclasses: orionis.auth.middleware.AuthenticateSessionMiddleware, orionis.auth.middleware.AuthenticateTokenMiddleware
Constructor: AuthenticateMiddleware(app, manager, permissions)
Require an authenticated identity before reaching the controller.
Guests never reach the route handler. Browsers are redirected to the page declared in auth.session.redirect_to when one is configured, and every other client receives a 401 response produced by the standard exception handler.
With no explicit guard, reuse the identity established by the kernel. Outside that pipeline, fall back to the configured default guard.
Responses of protected routes are marked as non-cacheable. Subclasses opt out by setting cache_control to None.
| Method | __init__ |
Initialise the middleware with its collaborators. |
| Method | _unauthenticated |
Build the answer given to an anonymous request. |
| Async Method | handle |
Reject anonymous requests and continue authenticated ones. |
| Class Variable | __slots__ |
Undocumented |
| Class Variable | cache |
Undocumented |
| Instance Variable | _redirect |
Undocumented |
Inherited from ResolveIdentityMiddleware:
| Async Method | _establish |
Resolve the identity and bind the resulting context. |
| Class Variable | guard |
Undocumented |
| Instance Variable | _manager |
Undocumented |
| Instance Variable | _permissions |
Undocumented |
IApplication, manager: IAuthManager, permissions: IPermissionRepository):
(source)
¶
Initialise the middleware with its collaborators.
| Parameters | |
app:IApplication | Application exposing the auth.session configuration. |
manager:IAuthManager | Manager exposing the configured guards. |
permissions:IPermissionRepository | Source the authorization snapshot is built from. |
| Returns | |
None | The redirect target is resolved once, at boot time. |
Build the answer given to an anonymous request.
| Parameters | |
request:Request | Incoming HTTP request. |
| Returns | |
Response | Redirect to the configured login page. |
| Raises | |
AuthenticationException | When the client expects a machine readable answer, or no redirect target is configured. The exception is translated into a 401 response by the framework exception handler. |
Reject anonymous requests and continue authenticated ones.
| Parameters | |
request:Request | Incoming HTTP request. |
callNextCallable | Callable advancing to the next layer. |
| Returns | |
Response | Response produced by the rest of the pipeline, or a redirect to the login page for anonymous browser requests. |
| Raises | |
AuthenticationException | When no identity backs the request and no redirect target is configured for browsers. |