ORIONIS API REFERENCE

THE ORIONIS API

Build with clarity.

Explore the building blocks of an async-first Python framework. Every module, class, and method — connected, searchable, and ready to build with.

class documentation

class ForgotPasswordController(BaseController): (source)

View In Hierarchy

Undocumented

Static Method _private Mark a response as private and prevent reset URL referrers.
Async Method _form Render the reset form without exposing password values.
Async Method _sendConfirmation Notify the account owner after the password reset commits.
Async Method _sendLink Issue and deliver a reset link after the response.
Async Method index Render the forgot-password page.
Async Method resetPassword Reset the password without flashing credentials or tokens.
Async Method sendResetLinkEmail Queue a password-reset message without revealing account existence.
Async Method showResetForm Display a reset form for an unconsumed link.
Constant SENT_MESSAGE Undocumented
def _private(result: HttpResponse) -> HttpResponse: (source)

Mark a response as private and prevent reset URL referrers.

Parameters
result:HttpResponseResponse whose security headers are updated.
Returns
HttpResponseThe same response with privacy and indexing headers applied.
async def _form(self, email: str, token: str, *, valid: bool, errors: dict[str, str] | ValidationException | None = None) -> HTMLResponse: (source)

Render the reset form without exposing password values.

Parameters
email:strEmail value retained only when the link is valid.
token:strReset token retained only when the link is valid.
valid:boolWhether the reset link passed token validation.
errors:dict[str, str] | ValidationException | None, optionalValidation errors to display on the form.
Returns
HTMLResponsePrivate reset form response with optional validation errors.
async def _sendConfirmation(self, email: str): (source)

Notify the account owner after the password reset commits.

Parameters
email:strAccount email address that receives the notification.
Returns
NoneCompletes after the reset notification is sent.
async def _sendLink(self, email: str, base_url: str, broker: PasswordBroker): (source)

Issue and deliver a reset link after the response.

Parameters
email:strEmail address submitted for password recovery.
base_url:strApplication base URL used to construct the link.
broker:PasswordBrokerService that issues the reset token and loads the account.
Returns
NoneCompletes after delivery or when no matching account is found.
async def index(self) -> HTMLResponse: (source)

Render the forgot-password page.

Returns
HTMLResponseRendered forgot-password page response.
async def resetPassword(self, request: Request, broker: PasswordBroker) -> HttpResponse: (source)

Reset the password without flashing credentials or tokens.

Parameters
request:RequestCurrent HTTP request containing the reset form payload.
broker:PasswordBrokerService that validates and consumes the reset token.
Returns
HttpResponseReset form response for invalid input, or a private login redirect after a successful reset.
async def sendResetLinkEmail(self, payload: ForgotPasswordSchema, request: Request, broker: PasswordBroker) -> HttpResponse: (source)

Queue a password-reset message without revealing account existence.

Parameters
payload:ForgotPasswordSchemaValidated email address submitted by the requester.
request:RequestCurrent HTTP request used to build the reset URL.
broker:PasswordBrokerService that issues and validates reset tokens.
Returns
HttpResponsePrivate redirect response returned before account lookup.
async def showResetForm(self, request: Request, broker: PasswordBroker) -> HTMLResponse: (source)

Display a reset form for an unconsumed link.

Parameters
request:RequestCurrent HTTP request containing the email and token query values.
broker:PasswordBrokerService that validates the reset token.
Returns
HTMLResponseReset form response with the link validity state.
SENT_MESSAGE: str = (source)

Undocumented

Value
'If an account matches that email, you will receive a password reset link.'