Authentication and User Management#
- class APITokenScopeEnum[source]#
-
Named scopes for API tokens
A token’s scope is what it is allowed to do, relative to its owner’s role - the effective permission can only ever be a restriction of the role, never an extension. A scope is stored and transmitted as a plain string, validated by validate_api_token_scope(); this enum lists the named values that validator accepts. Currently there is exactly one,
unlimited, meaning the token carries the owner’s full role. Future scopes may be parameterized (for example, limiting writes to particular projects) and so will be handled by the validator’s grammar rather than listed here. The “everything” scope is always this explicit named value - a null or empty scope must never be interpreted as unlimited access.- unlimited = 'unlimited'#
- __init__(*args, **kwds)#
- validate_api_token_scope(scope)[source]#
Validates an API token scope, returning its canonical string form
This is the single place scope values are validated, shared by the client models and the server. Today the grammar is trivial - the only valid scope is “unlimited” - and future parameterized scopes extend the grammar here, without changing any field or column type.
Raises ValueError for a scope this version does not recognize.
- Parameters:
scope (str | APITokenScopeEnum)
- Return type:
- looks_like_api_token(raw)[source]#
Returns whether a string is shaped like an API token
This is a cheap syntactic check (prefix, length, character set), shared by the client (to fail fast before a network round trip) and the server (to reject obviously-bad input before hashing). It says nothing about whether the token actually exists or is valid.
- is_valid_password(password)[source]#
Checks that a password is acceptable as a new password
This is the password policy applied when a password is being set (adding a user or changing a password). It is deliberately not applied when verifying a password at login time – see the verification-time checks in the user socket – since tightening this policy would otherwise lock out existing users with older, weaker passwords.
Raises an InvalidPasswordError if the password is not acceptable.
- Parameters:
password (str)
- Return type:
None
- class UserInfo[source]#
Bases:
BaseModelInformation about a user
Fields# Field
Type
Required
Default
Constraints
No
<AuthTypeEnum.password: 'password'>No
''max_length=128
Yes
No
''max_length=128
No
[]No
NoneNo
''max_length=128
Yes
Yes
- auth_type: AuthTypeEnum#
Type of authentication the user uses
- fullname: Annotated[str, StringConstraints(strip_whitespace=None, to_upper=None, to_lower=None, strict=None, min_length=None, max_length=128, pattern=None, ascii_only=None)]#
The full name or description of the user
- Constraints:
max_length =
128
- class APIToken[source]#
Bases:
BaseModelMetadata about a long-lived API token
This never contains the token itself. The plaintext token is shown exactly once, when the token is created (see NewAPIToken); afterwards only this metadata is available.
Fields# Field
Type
Required
Default
Yes
No
NoneYes
No
NoneYes
No
'unlimited'Yes
Yes
- class NewAPIToken[source]#
Bases:
BaseModelA newly-created API token, including the plaintext token
The plaintext token is only available here, in the response to creating the token. It is not stored and cannot be retrieved later.
- class APITokenCreateBody[source]#
Bases:
BaseModelOptions for creating a new API token
Fields# Field
Type
Required
Default
Constraints
No
NoneYes
min_length=1, max_length=128
No
'unlimited'- name: str#
A name to identify the token. Must be unique among the user’s tokens.
- Constraints:
min_length =
1max_length =
128
- scope: str#
What the token should be allowed to do. Currently only “unlimited” (the owner’s full role) exists. A plain (but validated) string, so the public schema never changes when new scopes are added; a scope this server does not recognize is rejected
- expires_at: AwareDatetime | None#
When the token should expire. Must be timezone-aware. Null requests a non-expiring token, subject to the server’s api_token_default_lifetime and api_token_max_lifetime policy