primus.auth.cognito module

Cognito hosted-authorization support for interactive Primus CLI users.

exception primus.auth.cognito.ApplicationAuthenticationRequired

Bases: ValueError

Raised when a user must sign in again before using the application API.

class primus.auth.cognito.AuthorizationRequest(url: 'str', state: 'str', code_verifier: 'str')

Bases: object

__init__(url: str, state: str, code_verifier: str) → None
code_verifier: str
state: str
url: str
class primus.auth.cognito.CognitoAuthConfig(domain: str, client_id: str, region: str | None = None, redirect_uri: str = 'http://127.0.0.1:8765/callback', scopes: tuple[str, ...] = ('openid', 'email', 'profile'))

Bases: object

Stable deployment-to-CLI discovery contract for hosted authorization.

__init__(domain: str, client_id: str, region: str | None = None, redirect_uri: str = 'http://127.0.0.1:8765/callback', scopes: tuple[str, ...] = ('openid', 'email', 'profile')) → None
client_id: str
domain: str
classmethod from_environment() → CognitoAuthConfig
redirect_uri: str = 'http://127.0.0.1:8765/callback'
region: str | None = None
scopes: tuple[str, ...] = ('openid', 'email', 'profile')
class primus.auth.cognito.CognitoAuthService(config: ~primus.auth.cognito.CognitoAuthConfig | None = None, credential_store: ~primus.auth.cognito.RefreshTokenStore | None = None, http: ~typing.Any = <module 'requests' from '/home/runner/work/Primus/Primus/.venv/lib/python3.11/site-packages/requests/__init__.py'>, browser_opener: ~typing.Callable[[str], bool] = <function open>, sleeper: ~typing.Callable[[float], None] = <built-in function sleep>)

Bases: object

Performs authorization-code login and supplies current bearer tokens.

__init__(config: ~primus.auth.cognito.CognitoAuthConfig | None = None, credential_store: ~primus.auth.cognito.RefreshTokenStore | None = None, http: ~typing.Any = <module 'requests' from '/home/runner/work/Primus/Primus/.venv/lib/python3.11/site-packages/requests/__init__.py'>, browser_opener: ~typing.Callable[[str], bool] = <function open>, sleeper: ~typing.Callable[[float], None] = <built-in function sleep>)
complete_authorization(code: str, code_verifier: str) → str
create_authorization_request(state: str | None = None, code_verifier: str | None = None) → AuthorizationRequest
get_access_token() → str
login() → str
logout() → None
static validate_callback(query: Mapping[str, str], expected_state: str) → str
whoami() → str
class primus.auth.cognito.KeyringRefreshTokenStore(keyring_module: Any = None)

Bases: object

Stores the long-lived refresh credential in the operating-system keychain.

__init__(keyring_module: Any = None)
delete() → None
get() → str | None
set(refresh_token: str) → None
exception primus.auth.cognito.LoopbackCallbackError

Bases: ApplicationAuthenticationRequired

Raised for an invalid hosted-authorization callback.

exception primus.auth.cognito.MissingApplicationSession

Bases: ApplicationAuthenticationRequired

Raised when no durable CLI refresh credential is available.

exception primus.auth.cognito.RefreshCredentialRejected

Bases: ApplicationAuthenticationRequired

Raised when the authorization server confirms a refresh credential is invalid.

class primus.auth.cognito.RefreshTokenStore(*args, **kwargs)

Bases: Protocol

__init__(*args, **kwargs)
delete() → None
get() → str | None
set(refresh_token: str) → None
exception primus.auth.cognito.RefreshTransportFailure

Bases: ApplicationAuthenticationRequired

Raised when a refresh attempt failed without proving the credential invalid.

class primus.auth.cognito.TokenSet(access_token: 'str', id_token: 'Optional[str]', expires_at: 'datetime')

Bases: object

__init__(access_token: str, id_token: str | None, expires_at: datetime) → None
access_token: str
expires_at: datetime
id_token: str | None