THE ORIONIS API
Build with clarity.
Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.
class documentation
class HTTPCsrf(BaseEntity): (source)
CSRF protection configuration for web routes.
| Method | __post |
Validate all CSRF configuration fields after dataclass construction. |
| Method | __validate |
Validate that cookie_domain is a string or None. |
| Method | __validate |
Validate that cookie_name is acceptable by the response cookie serializer. |
| Method | __validate |
Validate that cookie_path is a string. |
| Method | __validate |
Validate that cookie_same_site is a recognised SameSite value. |
| Method | __validate |
Validate that enabled is a boolean. |
| Method | __validate |
Validate that session_key is a non-empty string. |
| Method | __validate |
Validate that token_length is a plain integer >= 32. |
| Method | __validate |
Validate that xsrf_cookie is a boolean. |
| Instance Variable | cookie |
Domain attribute for the XSRF cookie. None omits it. Defaults to None. |
| Instance Variable | cookie |
Name of the XSRF cookie. Defaults to "XSRF-TOKEN". |
| Instance Variable | cookie |
Path attribute for the XSRF cookie. Defaults to "/". |
| Instance Variable | cookie |
SameSite attribute for the XSRF cookie. Defaults to "lax". |
| Instance Variable | cookie |
Set the Secure attribute on the XSRF cookie. When False, the middleware automatically promotes the flag to True on HTTPS requests. Defaults to False. |
| Instance Variable | enabled |
Enable or disable CSRF validation globally. Defaults to True. |
| Instance Variable | session |
Session key under which the token is stored. Defaults to "_csrf_token". |
| Instance Variable | token |
Number of random bytes used to generate the token via secrets.token_urlsafe. 32 bytes yields 256 bits of entropy (43 URL-safe characters). Defaults to 32. |
| Instance Variable | xsrf |
When True, set a readable XSRF-TOKEN cookie on every response so that JavaScript clients (Angular, Axios) can forward it as X-XSRF-Token. Defaults to False. |
Inherited from BaseEntity:
| Class Method | _cached |
Retrieve field definitions and normalized types cached by class. |
| Method | get |
Describe field names, normalized types, defaults, and metadata. |
| Method | to |
Convert the dataclass instance to a recursively copied dictionary. |
| Class Variable | __slots__ |
Undocumented |
Validate all CSRF configuration fields after dataclass construction.
| Returns | |
None | No value is returned; validation runs as a side effect. |
| Raises | |
TypeError | If any field has an unexpected type. |
ValueError | If token_length is below the minimum secure threshold or any string field is empty or otherwise invalid. |
Validate that cookie_name is acceptable by the response cookie serializer.
| Returns | |
None | No value is returned; raises on invalid input. |
| Raises | |
ValueError | If cookie_name is not valid. |
Validate that cookie_same_site is a recognised SameSite value.
| Returns | |
None | No value is returned; raises on invalid input. |
| Raises | |
ValueError | If cookie_same_site is not one of "lax", "strict", or "none". |
Validate that session_key is a non-empty string.
| Returns | |
None | No value is returned; raises on invalid input. |
| Raises | |
ValueError | If session_key is not a string or is an empty string. |
Validate that token_length is a plain integer >= 32.
| Returns | |
None | No value is returned; raises on invalid input. |
| Raises | |
TypeError | If token_length is not a plain int (bool subclass is excluded). |
ValueError | If token_length is below 32 (minimum 256 bits of entropy). |
Set the Secure attribute on the XSRF cookie. When False, the middleware automatically promotes the flag to True on HTTPS requests. Defaults to False.