THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
Undocumented
| Method | __decode |
Decode base64 payload and parse as typed _Payload struct. |
| Method | __decrypt |
Decrypt CBC-encrypted data and remove PKCS7 padding. |
| Method | __decrypt |
Decrypt GCM-encrypted data using AESGCM with authentication tag. |
| Method | __encrypt |
Encrypt data using AES-CBC with PKCS7 padding. |
| Method | __encrypt |
Encrypt data using AES-GCM mode with authentication. |
| Method | __extract |
Extract payload fields, base64-decoding binary values. |
| Method | __init__ |
Initialize the encrypter with application configuration. |
| Method | __perform |
Perform decryption based on the configured cipher mode. |
| Method | __validate |
Validate that payload cipher matches the configured cipher. |
| Method | __validate |
Validate that the IV size matches the configured cipher requirements. |
| Method | decrypt |
Decrypt an encrypted payload using the configured cipher algorithm. |
| Method | encrypt |
Encrypt plaintext using the configured cipher algorithm. |
| Constant | AES |
Undocumented |
| Constant | AES |
Undocumented |
| Constant | CBC |
Undocumented |
| Constant | GCM |
Undocumented |
| Constant | GCM |
Undocumented |
| Constant | PKCS7 |
Undocumented |
| Constant | SUPPORTED |
Undocumented |
| Class Variable | __slots__ |
Undocumented |
| Instance Variable | _aesgcm |
Undocumented |
| Instance Variable | _is |
Undocumented |
| Instance Variable | cipher |
Undocumented |
| Instance Variable | key |
Undocumented |
Decode base64 payload and parse as typed _Payload struct.
| Parameters | |
payload:str | Base64-encoded JSON payload string to decode. |
| Returns | |
_Payload | Decoded and schema-validated payload struct. |
| Raises | |
ValueError | If payload cannot be decoded or parsed as JSON. |
Decrypt CBC-encrypted data and remove PKCS7 padding.
| Parameters | |
ct:bytes | The encrypted ciphertext to decrypt. |
iv:bytes | The initialization vector used during encryption. |
| Returns | |
bytes | The decrypted plaintext with padding removed. |
| Raises | |
ValueError | If decrypted data is empty or padding is invalid. |
RuntimeError | If CBC decryption fails. |
Decrypt GCM-encrypted data using AESGCM with authentication tag.
| Parameters | |
value:bytes | The encrypted ciphertext to decrypt. |
iv:bytes | The initialization vector used during encryption. |
tag:bytes | None | The authentication tag for GCM mode verification. |
| Returns | |
bytes | The decrypted plaintext as raw bytes. |
| Raises | |
ValueError | If tag is None or GCM verification fails. |
RuntimeError | If GCM decryption fails for any other reason. |
Encrypt data using AES-CBC with PKCS7 padding.
| Parameters | |
data:bytes | The raw data to encrypt. |
| Returns | |
str | Base64-encoded JSON payload containing IV, encrypted value, and cipher. |
| Raises | |
RuntimeError | If CBC encryption fails. |
Encrypt data using AES-GCM mode with authentication.
| Parameters | |
data:bytes | The raw data to encrypt. |
| Returns | |
str | Base64-encoded JSON payload containing IV, encrypted value, tag, and cipher. |
| Raises | |
RuntimeError | If GCM encryption fails. |
_Payload) -> tuple[ str, bytes, bytes, bytes | None]:
(source)
¶
Extract payload fields, base64-decoding binary values.
| Parameters | |
data:_Payload | Parsed payload struct (fields already validated by msgspec). |
| Returns | |
tuple[str, bytes, bytes, bytes | None] | Tuple containing (cipher, iv, value, tag) where tag may be None. |
| Raises | |
ValueError | If base64 decoding of any field fails. |
Initialize the encrypter with application configuration.
| Parameters | |
app:IApplication | The application instance providing configuration access. |
| Returns | |
None | This method initializes the instance and returns None. |
| Raises | |
ValueError | If the cipher is not supported or key length is invalid. |
Perform decryption based on the configured cipher mode.
| Parameters | |
value:bytes | The encrypted data to decrypt. |
iv:bytes | The initialization vector used during encryption. |
tag:bytes | None | The authentication tag for GCM mode, None for CBC mode. |
| Returns | |
str | The decrypted plaintext as a UTF-8 string. |
| Raises | |
ValueError | If tag requirements are not met for GCM mode. |
RuntimeError | If decryption fails for any reason. |
Validate that payload cipher matches the configured cipher.
| Parameters | |
cipher:str | The cipher algorithm name from the payload. |
| Returns | |
None | This method validates compatibility and returns None. |
| Raises | |
ValueError | If the payload cipher does not match the configured cipher. |
Validate that the IV size matches the configured cipher requirements.
| Parameters | |
iv:bytes | The initialization vector bytes to validate. |
| Returns | |
None | This method validates IV size and returns None. |
| Raises | |
ValueError | If IV size does not match the cipher requirements. |
Decrypt an encrypted payload using the configured cipher algorithm.
| Parameters | |
payload:str | Base64-encoded encrypted payload containing IV, value, tag, and cipher. |
| Returns | |
str | The decrypted plaintext as a UTF-8 string. |
| Raises | |
TypeError | If payload is not a string. |
ValueError | If payload is empty or invalid. |
RuntimeError | If decryption fails. |
Encrypt plaintext using the configured cipher algorithm.
| Parameters | |
plaintext:str | The text to encrypt. |
| Returns | |
str | Base64-encoded encrypted payload containing IV, value, tag, and cipher. |
| Raises | |
TypeError | If plaintext is not a string. |
ValueError | If plaintext is empty or has encoding issues. |
RuntimeError | If encryption fails. |