ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

class AccessTokenRepository(IAccessTokenRepository): (source)

Constructor: AccessTokenRepository(app, db)

View In Hierarchy

Persist personal access tokens through the Orionis query builder.

Tokens are opaque: the client receives a random secret and the store only keeps its SHA-256 digest in a unique column. Verification is a single indexed lookup on that digest, so no plain text secret ever needs to be compared.

Concurrency

Issuance uses a unique digest, with an optional ID lookup for drivers that do not return generated keys. Revocation and usage confirmation use conditional updates. Usage cannot reactivate a revoked token; concurrent timestamps are last-writer-wins. Purging uses two deletes.

Method __init__ Initialise the repository from the token configuration.
Async Method create Issue a new personal access token for an identity.
Async Method findByPlainText Resolve a token from the value presented by the client.
Async Method purgeExpired Delete tokens that expired or were revoked.
Async Method revoke Revoke a single token.
Async Method revokeAll Revoke every active token of an identity.
Async Method touch Confirm token validity and record its use atomically.
Class Variable __slots__ Undocumented
Instance Variable __db Undocumented
Instance Variable __expiration Undocumented
Instance Variable __secret_bytes Undocumented
Instance Variable __table Undocumented
def __init__(self, app: IApplication, db: IQueryBuilder): (source)

Initialise the repository from the token configuration.

Parameters
app:IApplicationApplication exposing the auth.tokens configuration.
db:IQueryBuilderGateway used to build queries over the token table.
Returns
NoneOnly configuration values and the gateway are retained.
async def create(self, tokenable: IAuthorizable, name: str, *, abilities: Iterable[str] | None = None, expires_at: datetime | None = None) -> NewAccessToken: (source)

Issue a new personal access token for an identity.

Parameters
tokenable:IAuthorizableIdentity the token belongs to.
name:strHuman readable label describing the token.
abilities:Iterable[str] | None, optionalAbilities the token may use, or None to keep the full authorization of the identity.
expires_at:datetime | None, optionalExplicit expiration. None applies the configured default.
Returns
NewAccessTokenStored metadata plus the plain text value of the token.
Raises
TokenExceptionWhen the token name is empty.
async def findByPlainText(self, plain_text: str) -> AccessToken | None: (source)

Resolve a token from the value presented by the client.

Parameters
plain_text:strValue received in the Authorization header.
Returns
AccessToken | NoneMatching token, or None when the value is unknown, has been revoked or has already expired.
async def purgeExpired(self) -> int: (source)

Delete tokens that expired or were revoked.

Returns
intNumber of rows removed from the store.
async def revoke(self, token_id: object) -> bool: (source)

Revoke a single token.

Parameters
token_id:objectIdentifier of the token to revoke.
Returns
boolTrue when this call revoked a token that was still active.
async def revokeAll(self, tokenable: IAuthorizable) -> int: (source)

Revoke every active token of an identity.

Parameters
tokenable:IAuthorizableIdentity whose tokens must be revoked.
Returns
intNumber of tokens revoked by this call.
async def touch(self, token_id: object) -> bool: (source)

Confirm token validity and record its use atomically.

Parameters
token_id:objectIdentifier of the token to update.
Returns
boolTrue only if a non-revoked, unexpired row was updated. This is the final validity check before a guard publishes identity.
__slots__: tuple[str, ...] = (source)

Undocumented

Undocumented

__expiration: int | None = (source)

Undocumented

__secret_bytes: int = (source)

Undocumented

Undocumented