THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
class AccessTokenRepository(IAccessTokenRepository): (source)
Constructor: AccessTokenRepository(app, db)
Persist personal access tokens through the Orionis query builder.
Tokens are opaque: the client receives a random secret and the store only keeps its SHA-256 digest in a unique column. Verification is a single indexed lookup on that digest, so no plain text secret ever needs to be compared.
Concurrency
Issuance uses a unique digest, with an optional ID lookup for drivers that do not return generated keys. Revocation and usage confirmation use conditional updates. Usage cannot reactivate a revoked token; concurrent timestamps are last-writer-wins. Purging uses two deletes.
| Method | __init__ |
Initialise the repository from the token configuration. |
| Async Method | create |
Issue a new personal access token for an identity. |
| Async Method | find |
Resolve a token from the value presented by the client. |
| Async Method | purge |
Delete tokens that expired or were revoked. |
| Async Method | revoke |
Revoke a single token. |
| Async Method | revoke |
Revoke every active token of an identity. |
| Async Method | touch |
Confirm token validity and record its use atomically. |
| Class Variable | __slots__ |
Undocumented |
| Instance Variable | __db |
Undocumented |
| Instance Variable | __expiration |
Undocumented |
| Instance Variable | __secret |
Undocumented |
| Instance Variable | __table |
Undocumented |
Initialise the repository from the token configuration.
| Parameters | |
app:IApplication | Application exposing the auth.tokens configuration. |
db:IQueryBuilder | Gateway used to build queries over the token table. |
| Returns | |
None | Only configuration values and the gateway are retained. |
IAuthorizable, name: str, *, abilities: Iterable[ str] | None = None, expires_at: datetime | None = None) -> NewAccessToken:
(source)
¶
Issue a new personal access token for an identity.
| Parameters | |
tokenable:IAuthorizable | Identity the token belongs to. |
name:str | Human readable label describing the token. |
abilities:Iterable[str] | None, optional | Abilities the token may use, or None to keep the full authorization of the identity. |
expiresdatetime | None, optional | Explicit expiration. None applies the configured default. |
| Returns | |
NewAccessToken | Stored metadata plus the plain text value of the token. |
| Raises | |
TokenException | When the token name is empty. |
Resolve a token from the value presented by the client.
| Parameters | |
plainstr | Value received in the Authorization header. |
| Returns | |
AccessToken | None | Matching token, or None when the value is unknown, has been revoked or has already expired. |
Revoke every active token of an identity.
| Parameters | |
tokenable:IAuthorizable | Identity whose tokens must be revoked. |
| Returns | |
int | Number of tokens revoked by this call. |