THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
class documentation
Store expiring token digests and rotate them on persistent login.
| Static Method | _generate |
Create a cookie value containing an identity, expiry, and secret. |
| Static Method | _stored |
Bind a credential to its identity, expiry, and password hash. |
| Method | __init__ |
Initialize persistent-login settings and dependencies. |
| Method | _queue |
Queue a cookie change on the current request. |
| Method | clear |
Queue expiration of the current browser's persistent credential. |
| Async Method | forget |
Forget an identity's persistent credential. |
| Async Method | issue |
Issue a persistent credential after password verification. |
| Async Method | restore |
Restore an identity by validating and rotating its cookie. |
| Async Method | revoke |
Revoke a remembered credential and clear the browser cookie. |
| Instance Variable | identities |
Undocumented |
| Instance Variable | settings |
Undocumented |
Create a cookie value containing an identity, expiry, and secret.
| Parameters | |
identity:IAuthenticatable | Identity that owns the persistent credential. |
expiry:int | Unix timestamp when the credential expires. |
| Returns | |
str | Cookie value containing the identity selector and random secret. |
Bind a credential to its identity, expiry, and password hash.
| Parameters | |
cookie:str | Public remember-cookie value. |
identity:IAuthenticatable | Identity that owns the credential. |
expiry:int | Unix timestamp when the credential expires. |
| Returns | |
str | Versioned digest bound to the cookie and identity password hash. |
Initialize persistent-login settings and dependencies.
| Parameters | |
app:IApplication | Application exposing the remember-me and session configuration. |
identities:IIdentityProvider | Provider used to retrieve identities and update remember tokens. |
| Returns | |
None | Settings and the identity provider are retained on the instance. |
| Raises | |
ValueError | If the remember cookie name matches the session cookie name. |
Queue a cookie change on the current request.
| Parameters | |
request:Request | Request that owns the pending response state. |
value:str | Cookie value to issue, or an empty string to clear it. |
maxint | Cookie lifetime in seconds; zero expires the cookie immediately. |
| Returns | |
None | Cookie attributes are stored on the request state. |
Forget an identity's persistent credential.
| Parameters | |
request:Request | Request that will emit the cleared cookie. |
identity:IAuthenticatable | Identity whose remember token should be removed. |
| Returns | |
None | The server-side token is cleared when present and the cookie expires. |
Issue a persistent credential after password verification.
| Parameters | |
request:Request | Request that will receive the remember cookie. |
identity:IAuthenticatable | Active identity whose prior remembered credential is replaced. |
| Returns | |
None | The stored token is updated and its cookie is queued. |
| Raises | |
AuthException | If HTTPS is required but unavailable, or token persistence fails. |
Restore an identity by validating and rotating its cookie.
| Parameters | |
request:Request | Request carrying the remember cookie. |
| Returns | |
IAuthenticatable | None | Restored identity, or None when the cookie is invalid, expired, stale, or could not be rotated. |