ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

Store expiring token digests and rotate them on persistent login.

Static Method _generate Create a cookie value containing an identity, expiry, and secret.
Static Method _stored Bind a credential to its identity, expiry, and password hash.
Method __init__ Initialize persistent-login settings and dependencies.
Method _queue Queue a cookie change on the current request.
Method clearCookie Queue expiration of the current browser's persistent credential.
Async Method forget Forget an identity's persistent credential.
Async Method issue Issue a persistent credential after password verification.
Async Method restore Restore an identity by validating and rotating its cookie.
Async Method revoke Revoke a remembered credential and clear the browser cookie.
Instance Variable identities Undocumented
Instance Variable settings Undocumented
def _generate(identity: IAuthenticatable, expiry: int) -> str: (source)

Create a cookie value containing an identity, expiry, and secret.

Parameters
identity:IAuthenticatableIdentity that owns the persistent credential.
expiry:intUnix timestamp when the credential expires.
Returns
strCookie value containing the identity selector and random secret.
def _stored(cookie: str, identity: IAuthenticatable, expiry: int) -> str: (source)

Bind a credential to its identity, expiry, and password hash.

Parameters
cookie:strPublic remember-cookie value.
identity:IAuthenticatableIdentity that owns the credential.
expiry:intUnix timestamp when the credential expires.
Returns
strVersioned digest bound to the cookie and identity password hash.
def __init__(self, app: IApplication, identities: IIdentityProvider): (source)

Initialize persistent-login settings and dependencies.

Parameters
app:IApplicationApplication exposing the remember-me and session configuration.
identities:IIdentityProviderProvider used to retrieve identities and update remember tokens.
Returns
NoneSettings and the identity provider are retained on the instance.
Raises
ValueErrorIf the remember cookie name matches the session cookie name.
def _queue(self, request: Request, value: str, max_age: int): (source)

Queue a cookie change on the current request.

Parameters
request:RequestRequest that owns the pending response state.
value:strCookie value to issue, or an empty string to clear it.
max_age:intCookie lifetime in seconds; zero expires the cookie immediately.
Returns
NoneCookie attributes are stored on the request state.
def clearCookie(self, request: Request): (source)

Queue expiration of the current browser's persistent credential.

Parameters
request:RequestRequest that will emit the expired cookie.
Returns
NoneAn expired cookie is queued on the request state.
async def forget(self, request: Request, identity: IAuthenticatable): (source)

Forget an identity's persistent credential.

Parameters
request:RequestRequest that will emit the cleared cookie.
identity:IAuthenticatableIdentity whose remember token should be removed.
Returns
NoneThe server-side token is cleared when present and the cookie expires.
async def issue(self, request: Request, identity: IAuthenticatable): (source)

Issue a persistent credential after password verification.

Parameters
request:RequestRequest that will receive the remember cookie.
identity:IAuthenticatableActive identity whose prior remembered credential is replaced.
Returns
NoneThe stored token is updated and its cookie is queued.
Raises
AuthExceptionIf HTTPS is required but unavailable, or token persistence fails.
async def restore(self, request: Request) -> IAuthenticatable | None: (source)

Restore an identity by validating and rotating its cookie.

Parameters
request:RequestRequest carrying the remember cookie.
Returns
IAuthenticatable | NoneRestored identity, or None when the cookie is invalid, expired, stale, or could not be rotated.
async def revoke(self, request: Request, identifier: object): (source)

Revoke a remembered credential and clear the browser cookie.

Parameters
request:RequestRequest that will emit the cleared cookie.
identifier:objectPersisted identity identifier associated with the current session.
Returns
NoneThe server-side token is revoked when its identity still exists.
identities = (source)

Undocumented

settings = (source)

Undocumented