Skip to main content

English · Русский

Orcestr banner

orcestr-auth

PyPI Python License: MPL 2.0

Python authentication core and FastAPI/SQLAlchemy adapters for the Orcestr ecosystem.

The application keeps its real user model and product lifecycle. The package owns password, token, session, cookie, recovery, OAuth and WebSocket authentication mechanics.

Install

pip install "orcestr-auth[all]"

Optional groups:

Extra Includes
fastapi dependencies, cookie/CSRF flow and router factory
sqlalchemy auth models, direct user repository and Alembic operations
oauth GitHub, Google and Yandex provider clients
all every first-party adapter

Main APIs

Import Purpose
orcestr_auth config, password helpers, token codec and extension ports
orcestr_auth.sqlalchemy create_auth_models, UserFieldMap, user repository
orcestr_auth.services sessions, verification/reset codes and WebSocket tickets
orcestr_auth.oauth optional provider clients and normalized profiles
orcestr_auth.fastapi auth dependencies, redirect policy and router factory
orcestr_auth.migrations versioned Alembic operations for auth-owned schema

SQLAlchemy Wiring

Attach auth tables to the application's registry and real user primary key:

from orcestr_auth.sqlalchemy import UserFieldMap, create_auth_models

auth_models = create_auth_models(
    registry=Base.registry,
    user_model=UserORM,
)

user_fields = UserFieldMap(
    id=UserORM.id,
    username=UserORM.username,
    email=UserORM.email,
    password_hash=UserORM.password_hash,
    is_active=UserORM.is_active,
    email_verified_at=UserORM.email_verified_at,
)

This creates direct indexed queries and real foreign keys. It does not create a second user table and does not use runtime reflection.

FastAPI Wiring

from orcestr_auth.fastapi import create_auth_dependencies, create_auth_router

auth_dependencies = create_auth_dependencies(
    config=auth_config,
    session_dependency=get_control_db_session,
    user_model=UserORM,
    user_fields=user_fields,
    models=auth_models,
)

router = create_auth_router(
    config=auth_config,
    application_dependency=get_auth_http_application,
    current_user_dependency=auth_dependencies.current_user,
    register_model=RegisterRequest,
    user_response_model=UserRead,
)

The consumer implements the small AuthHttpApplication boundary for product-specific work: user creation, legal acceptance, tenant bootstrap, email delivery, audit and rate limits. Standard endpoints, cookies and token responses remain library-owned.

Security Model

  • browser tokens live in HttpOnly cookies and never appear in browser auth JSON;
  • cookie mutations require the configured CSRF header;
  • refresh tokens are opaque, hashed, rotated and replay-protected;
  • access JWTs validate issuer, audience, expiry, type, JTI and server session state;
  • recovery codes are hashed, expiring, attempt-limited and one-time;
  • OAuth validates redirects and supports state/PKCE without implicit account linking;
  • WebSocket access uses short-lived one-time tickets.

See security invariants and architecture boundaries.

Development

uv sync --frozen
uv run pytest -q
uv build

Ecosystem

License

Licensed under the Mozilla Public License 2.0. Commercial use is permitted; see the repository NOTICE and trademark policy.

Release files for orcestr-auth 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for orcestr-auth 0.3.0
File Size Uploaded
orcestr_auth-0.3.0.tar.gz 30.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for orcestr-auth 0.3.0
File Interpreter ABI Platform
orcestr_auth-0.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 63.0 kB

Release files / orcestr_auth-0.3.0.tar.gz

Download URL orcestr_auth-0.3.0.tar.gz
Size 30.9 kB
Tags Source
SHA-256 checksum
How to use checksums
ad4093c6343c6e36eac359bc407fc92eab2ebff6e541ec8a0b1a75c82c2e37f8
BLAKE2b-256 checksum
How to use checksums
0e538a372390a2cdb179a37641ab0c215e4dc0a5ca8279d688fae6b1a0e0ca18
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.0 {"installer":{"name":"uv","version":"0.12.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / orcestr_auth-0.3.0-py3-none-any.whl

Download URL orcestr_auth-0.3.0-py3-none-any.whl
Size 32.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
afb83e31ee0a0e25e959e31582b038c09535980e80da4d9fa06e626157326cb1
BLAKE2b-256 checksum
How to use checksums
9d7cbd04183b5aa5b56cae4527e9d349a25b74743fd258806924c0554f25f7e8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.0 {"installer":{"name":"uv","version":"0.12.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

0.4.2

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

This release

0.3.0 This release

2 release files

0.2.0

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page