ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

class Encrypter(IEncrypter): (source)

Constructor: Encrypter(app)

View In Hierarchy

Undocumented

Method __decodePayload Decode base64 payload and parse as typed _Payload struct.
Method __decryptCBC Decrypt CBC-encrypted data and remove PKCS7 padding.
Method __decryptGCM Decrypt GCM-encrypted data using AESGCM with authentication tag.
Method __encryptCBC Encrypt data using AES-CBC with PKCS7 padding.
Method __encryptGCM Encrypt data using AES-GCM mode with authentication.
Method __extractPayloadData Extract payload fields, base64-decoding binary values.
Method __init__ Initialize the encrypter with application configuration.
Method __performDecryption Perform decryption based on the configured cipher mode.
Method __validateCipherMatch Validate that payload cipher matches the configured cipher.
Method __validateIvSize Validate that the IV size matches the configured cipher requirements.
Method decrypt Decrypt an encrypted payload using the configured cipher algorithm.
Method encrypt Encrypt plaintext using the configured cipher algorithm.
Constant AES_128_KEY_SIZE Undocumented
Constant AES_256_KEY_SIZE Undocumented
Constant CBC_IV_SIZE Undocumented
Constant GCM_IV_SIZE Undocumented
Constant GCM_TAG_SIZE Undocumented
Constant PKCS7_BLOCK_SIZE Undocumented
Constant SUPPORTED_CIPHERS Undocumented
Class Variable __slots__ Undocumented
Instance Variable _aesgcm Undocumented
Instance Variable _is_gcm Undocumented
Instance Variable cipher Undocumented
Instance Variable key Undocumented
def __decodePayload(self, payload: str) -> _Payload: (source)

Decode base64 payload and parse as typed _Payload struct.

Parameters
payload:strBase64-encoded JSON payload string to decode.
Returns
_PayloadDecoded and schema-validated payload struct.
Raises
ValueErrorIf payload cannot be decoded or parsed as JSON.
def __decryptCBC(self, ct: bytes, iv: bytes) -> bytes: (source)

Decrypt CBC-encrypted data and remove PKCS7 padding.

Parameters
ct:bytesThe encrypted ciphertext to decrypt.
iv:bytesThe initialization vector used during encryption.
Returns
bytesThe decrypted plaintext with padding removed.
Raises
ValueErrorIf decrypted data is empty or padding is invalid.
RuntimeErrorIf CBC decryption fails.
def __decryptGCM(self, value: bytes, iv: bytes, tag: bytes | None) -> bytes: (source)

Decrypt GCM-encrypted data using AESGCM with authentication tag.

Parameters
value:bytesThe encrypted ciphertext to decrypt.
iv:bytesThe initialization vector used during encryption.
tag:bytes | NoneThe authentication tag for GCM mode verification.
Returns
bytesThe decrypted plaintext as raw bytes.
Raises
ValueErrorIf tag is None or GCM verification fails.
RuntimeErrorIf GCM decryption fails for any other reason.
def __encryptCBC(self, data: bytes) -> str: (source)

Encrypt data using AES-CBC with PKCS7 padding.

Parameters
data:bytesThe raw data to encrypt.
Returns
strBase64-encoded JSON payload containing IV, encrypted value, and cipher.
Raises
RuntimeErrorIf CBC encryption fails.
def __encryptGCM(self, data: bytes) -> str: (source)

Encrypt data using AES-GCM mode with authentication.

Parameters
data:bytesThe raw data to encrypt.
Returns
strBase64-encoded JSON payload containing IV, encrypted value, tag, and cipher.
Raises
RuntimeErrorIf GCM encryption fails.
def __extractPayloadData(self, data: _Payload) -> tuple[str, bytes, bytes, bytes | None]: (source)

Extract payload fields, base64-decoding binary values.

Parameters
data:_PayloadParsed payload struct (fields already validated by msgspec).
Returns
tuple[str, bytes, bytes, bytes | None]Tuple containing (cipher, iv, value, tag) where tag may be None.
Raises
ValueErrorIf base64 decoding of any field fails.
def __init__(self, app: IApplication): (source)

Initialize the encrypter with application configuration.

Parameters
app:IApplicationThe application instance providing configuration access.
Returns
NoneThis method initializes the instance and returns None.
Raises
ValueErrorIf the cipher is not supported or key length is invalid.
def __performDecryption(self, value: bytes, iv: bytes, tag: bytes | None) -> str: (source)

Perform decryption based on the configured cipher mode.

Parameters
value:bytesThe encrypted data to decrypt.
iv:bytesThe initialization vector used during encryption.
tag:bytes | NoneThe authentication tag for GCM mode, None for CBC mode.
Returns
strThe decrypted plaintext as a UTF-8 string.
Raises
ValueErrorIf tag requirements are not met for GCM mode.
RuntimeErrorIf decryption fails for any reason.
def __validateCipherMatch(self, cipher: str): (source)

Validate that payload cipher matches the configured cipher.

Parameters
cipher:strThe cipher algorithm name from the payload.
Returns
NoneThis method validates compatibility and returns None.
Raises
ValueErrorIf the payload cipher does not match the configured cipher.
def __validateIvSize(self, iv: bytes): (source)

Validate that the IV size matches the configured cipher requirements.

Parameters
iv:bytesThe initialization vector bytes to validate.
Returns
NoneThis method validates IV size and returns None.
Raises
ValueErrorIf IV size does not match the cipher requirements.
def decrypt(self, payload: str) -> str: (source)

Decrypt an encrypted payload using the configured cipher algorithm.

Parameters
payload:strBase64-encoded encrypted payload containing IV, value, tag, and cipher.
Returns
strThe decrypted plaintext as a UTF-8 string.
Raises
TypeErrorIf payload is not a string.
ValueErrorIf payload is empty or invalid.
RuntimeErrorIf decryption fails.
def encrypt(self, plaintext: str) -> str: (source)

Encrypt plaintext using the configured cipher algorithm.

Parameters
plaintext:strThe text to encrypt.
Returns
strBase64-encoded encrypted payload containing IV, value, tag, and cipher.
Raises
TypeErrorIf plaintext is not a string.
ValueErrorIf plaintext is empty or has encoding issues.
RuntimeErrorIf encryption fails.
AES_128_KEY_SIZE: int = (source)

Undocumented

Value
16
AES_256_KEY_SIZE: int = (source)

Undocumented

Value
32
CBC_IV_SIZE: int = (source)

Undocumented

Value
16
GCM_IV_SIZE: int = (source)

Undocumented

Value
12
GCM_TAG_SIZE: int = (source)

Undocumented

Value
16
PKCS7_BLOCK_SIZE: int = (source)

Undocumented

Value
16
SUPPORTED_CIPHERS: ClassVar[frozenset[str]] = (source)

Undocumented

Value
frozenset((cipher.value for cipher in OrionisCipher))
_aesgcm: AESGCM | None = (source)

Undocumented

Undocumented

Undocumented

Undocumented