auth
auth ¶
Domo authentication classes for various authentication methods.
This module re-exports authentication classes for different Domo auth methods: - DomoAuth: Base authentication class - DomoFullAuth: Username/password authentication - DomoTokenAuth: Access token authentication - DomoDeveloperAuth: OAuth2 client credentials authentication - DomoJupyterAuth: Base Jupyter authentication - DomoJupyterFullAuth: Jupyter with username/password - DomoJupyterTokenAuth: Jupyter with access token
Type Hinting:
All authentication classes (DomoTokenAuth, DomoFullAuth, DomoDeveloperAuth, etc.)
inherit from DomoAuth and implement the same interface via shared mixins, so
functions can accept DomoAuth and work with any auth subclass.
DomoAuth ¶
Bases: ABC
Abstract contract for Domo authentication implementations.
All concrete auth classes must inherit from this class and provide the required authentication surface used by routes and entities.
auth_header
abstractmethod
property
¶
auth_header: dict
Generate authentication headers for API requests.
url_manual_login
property
¶
url_manual_login: str
Generate the manual login URL for the Domo instance.
cache_stats ¶
cache_stats() -> dict
Get HTTP cache statistics.
Source code in src/crew_dcs/auth/base.py
205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 | |
clear_cache ¶
clear_cache() -> None
Clear all HTTP caches for this auth instance.
Source code in src/crew_dcs/auth/base.py
198 199 200 201 202 203 | |
close_session
async
¶
close_session() -> None
Close and drop the pooled session cached on this auth, if any.
A reused session is otherwise held open until the auth is GC'd. Call this (or use the auth as an async context manager) for clean teardown::
async with DomoTokenAuth(...) as auth:
await DomoCard.create(auth=auth, ...) # reuses one pooled session
# session closed here
Source code in src/crew_dcs/auth/base.py
50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 | |
elevate_otp
async
¶
elevate_otp(
one_time_password: str,
debug_api: bool = False,
session: AsyncClient | None = None,
debug_num_stacks_to_drop: int = 2,
) -> ResponseGetData
Elevate the authentication to include OTP (One-Time Password) if required.
Source code in src/crew_dcs/auth/base.py
134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 | |
get_auth_token
abstractmethod
async
¶
get_auth_token(**context_kwargs) -> str | ResponseGetData
Retrieve or generate an authentication token.
Source code in src/crew_dcs/auth/base.py
97 98 99 100 101 102 103 | |
invalidate_cache
async
¶
invalidate_cache(url_pattern: str) -> None
Manually invalidate cache entries matching URL pattern.
Source code in src/crew_dcs/auth/base.py
227 228 229 230 231 232 | |
print_is_token
async
¶
print_is_token(
token_name: str | None = None, **context_kwargs
) -> bool
Print token status and return True if token is valid, otherwise False.
Source code in src/crew_dcs/auth/base.py
170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 | |
set_cache_strategy ¶
set_cache_strategy(strategy) -> None
Change cache invalidation strategy.
Source code in src/crew_dcs/auth/base.py
234 235 236 237 238 239 | |
who_am_i
async
¶
who_am_i(**context_kwargs) -> ResponseGetData
Perform an API call to identify the user associated with the token.
Source code in src/crew_dcs/auth/base.py
105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 | |
DomoDeveloperAuth
dataclass
¶
DomoDeveloperAuth(
domo_client_id: str,
domo_client_secret: str,
domo_instance: str,
token_name: str | None = None,
token: str | None = None,
user_id: str | None = None,
is_valid_token: bool = False,
cache_responses: bool = False,
cache_size: int = 1000,
cache_default_ttl: int = 300,
cache_strategy: str | None = None,
custom_cache_rules: dict[str, list[str]] | None = None,
)
Bases: DomoAuth
Developer authentication using client credentials.
This authentication method uses OAuth2 client credentials (client ID and secret) to obtain bearer tokens. This is typically used for applications built on Domo's developer platform and requires developer app registration.
Attributes:
| Name | Type | Description |
|---|---|---|
domo_client_id |
str
|
OAuth2 client ID from developer app registration |
domo_client_secret |
str
|
OAuth2 client secret (not shown in repr) |
domo_instance |
str
|
The Domo instance identifier |
token_name |
str | None
|
Name identifier for the token |
token |
str | None
|
The bearer token (not shown in repr) |
user_id |
str | None
|
The authenticated user's ID |
is_valid_token |
bool
|
Whether the current token is valid |
cache_responses |
bool
|
Enable HTTP response caching (default: False) |
cache_size |
int
|
Maximum number of cache entries (default: 1000) |
cache_default_ttl |
int
|
Default cache TTL in seconds (default: 300) |
cache_strategy |
str | None
|
Cache invalidation strategy (default: None, uses SMART) |
custom_cache_rules |
dict | None
|
Custom cache invalidation rules (default: None) |
Example
auth = DomoDeveloperAuth( ... domo_client_id="your-client-id", ... domo_client_secret="
", # pragma: allowlist secret ... domo_instance="mycompany" ... ) token = await auth.get_auth_token()
auth_header
property
¶
auth_header: dict
Generate the authentication header for developer token authentication.
get_auth_token
async
¶
get_auth_token(**context_kwargs) -> str
Retrieve the developer token using client credentials and update internal attributes.
Source code in src/crew_dcs/auth/developer.py
79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 | |
who_am_i
async
¶
who_am_i(**context_kwargs) -> ResponseGetData
Use cached user_id from get_auth_token response (no separate API call).
Source code in src/crew_dcs/auth/developer.py
123 124 125 126 127 128 129 130 131 132 133 134 | |
DomoFullAuth
dataclass
¶
DomoFullAuth(
domo_instance: str,
domo_username: str,
domo_password: str,
token_name: str | None = None,
token: str | None = None,
user_id: str | None = None,
is_valid_token: bool = False,
cache_responses: bool = False,
cache_size: int = 1000,
cache_default_ttl: int = 300,
cache_strategy: str | None = None,
custom_cache_rules: dict[str, list[str]] | None = None,
)
Bases: DomoAuth
Full authentication using Domo username and password.
This class provides authentication using Domo credentials (username and password) to obtain session tokens. It's typically used for direct user authentication where username/password login is permitted.
Attributes:
| Name | Type | Description |
|---|---|---|
domo_instance |
str
|
The Domo instance identifier |
domo_username |
str
|
Domo username for authentication |
domo_password |
str
|
Domo password for authentication (not shown in repr) |
token_name |
str | None
|
Name identifier for the token |
token |
str | None
|
The authentication token (not shown in repr) |
user_id |
str | None
|
The authenticated user's ID |
is_valid_token |
bool
|
Whether the current token is valid |
cache_responses |
bool
|
Enable HTTP response caching (default: False) |
cache_size |
int
|
Maximum number of cache entries (default: 1000) |
cache_default_ttl |
int
|
Default cache TTL in seconds (default: 300) |
cache_strategy |
str | None
|
Cache invalidation strategy (default: None, uses SMART) |
custom_cache_rules |
dict | None
|
Custom cache invalidation rules (default: None) |
Example
auth = DomoFullAuth( ... domo_instance="mycompany", ... domo_username="user@company.com", ... domo_password="
", # pragma: allowlist secret ... ) token = await auth.get_auth_token()
auth_header
property
¶
auth_header: dict
Generate the full authentication header specific to product APIs.
get_auth_token
async
¶
get_auth_token(
return_raw: bool = False, **context_kwargs
) -> str | ResponseGetData
Retrieve the authentication token from product APIs using the provided credentials.
Source code in src/crew_dcs/auth/full.py
80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 | |
DomoJupyterAuth ¶
Mixin for Jupyter auth. Not instantiable alone.
Provides jupyter_token, service_location, service_prefix validation and jupyter_auth_header. Use DomoJupyterFullAuth or DomoJupyterTokenAuth.
jupyter_auth_header
property
¶
jupyter_auth_header: dict
Header for Jupyter server API (Authorization: Token ...).
DomoJupyterFullAuth
dataclass
¶
DomoJupyterFullAuth(
jupyter_token: str,
service_location: str,
service_prefix: str,
domo_instance: str,
domo_username: str,
domo_password: str,
token_name: str | None = None,
token: str | None = None,
user_id: str | None = None,
is_valid_token: bool = False,
cache_responses: bool = False,
cache_size: int = 1000,
cache_default_ttl: int = 300,
cache_strategy: str | None = None,
custom_cache_rules: dict[str, list[str]] | None = None,
)
Bases: DomoJupyterAuth, DomoAuth
Jupyter authentication using full credentials (username/password).
auth_header
property
¶
auth_header: dict
Combined Domo + Jupyter headers (no guard — Jupyter token always present).
convert_auth
classmethod
¶
convert_auth(
auth: DomoFullAuth,
jupyter_token: str,
service_location: str,
service_prefix: str,
) -> DomoJupyterFullAuth
Create DomoJupyterFullAuth from DomoFullAuth + Jupyter params.
Source code in src/crew_dcs/auth/jupyter.py
125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 | |
get_auth_token
async
¶
get_auth_token(
return_raw: bool = False, **context_kwargs
) -> str | ResponseGetData
Retrieve the authentication token from product APIs.
Source code in src/crew_dcs/auth/jupyter.py
87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 | |
DomoJupyterTokenAuth
dataclass
¶
DomoJupyterTokenAuth(
jupyter_token: str,
service_location: str,
service_prefix: str,
domo_instance: str,
domo_access_token: str,
token_name: str | None = None,
token: str | None = None,
user_id: str | None = None,
is_valid_token: bool = False,
cache_responses: bool = False,
cache_size: int = 1000,
cache_default_ttl: int = 300,
cache_strategy: str | None = None,
custom_cache_rules: dict[str, list[str]] | None = None,
)
Bases: DomoJupyterAuth, DomoAuth
Jupyter authentication using access tokens.
auth_header
property
¶
auth_header: dict
Combined Domo + Jupyter headers (no guard — both tokens always present).
convert_auth
classmethod
¶
convert_auth(
auth: DomoTokenAuth,
jupyter_token: str,
service_location: str,
service_prefix: str,
) -> DomoJupyterTokenAuth
Create DomoJupyterTokenAuth from DomoTokenAuth + Jupyter params.
Source code in src/crew_dcs/auth/jupyter.py
209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 | |
get_auth_token
async
¶
get_auth_token(
token_name: str | None = None, **context_kwargs
) -> str
Retrieve the access token, validating via who_am_i if needed.
Source code in src/crew_dcs/auth/jupyter.py
188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 | |
DomoTokenAuth
dataclass
¶
DomoTokenAuth(
domo_access_token: str,
domo_instance: str,
token_name: str | None = None,
token: str | None = None,
user_id: str | None = None,
is_valid_token: bool = False,
cache_responses: bool = False,
cache_size: int = 1000,
cache_default_ttl: int = 300,
cache_strategy: str | None = None,
custom_cache_rules: dict[str, list[str]] | None = None,
)
Bases: DomoAuth
Token-based authentication using pre-generated access tokens.
This authentication method uses access tokens generated from Domo's admin panel (Admin > Access Tokens). This is particularly useful in environments where direct username/password authentication is not permitted or for automated systems.
Attributes:
| Name | Type | Description |
|---|---|---|
domo_access_token |
str
|
Pre-generated access token (not shown in repr) |
domo_instance |
str
|
The Domo instance identifier |
token_name |
str | None
|
Name identifier for the token |
token |
str | None
|
The authentication token (not shown in repr) |
user_id |
str | None
|
The authenticated user's ID |
is_valid_token |
bool
|
Whether the current token is valid |
cache_responses |
bool
|
Enable HTTP response caching (default: False) |
cache_size |
int
|
Maximum number of cache entries (default: 1000) |
cache_default_ttl |
int
|
Default cache TTL in seconds (default: 300) |
cache_strategy |
str | None
|
Cache invalidation strategy (default: None, uses SMART) |
custom_cache_rules |
dict | None
|
Custom cache invalidation rules (default: None) |
Example
auth = DomoTokenAuth( ... domo_access_token="your-access-token-here", ... domo_instance="mycompany" ... ) token = await auth.get_auth_token()
auth_header
property
¶
auth_header: dict
Generate the authentication header for access token based authentication.
get_auth_token
async
¶
get_auth_token(
token_name: str | None = None, **context_kwargs
) -> str
Retrieve the access token, updating internal attributes as necessary.
Source code in src/crew_dcs/auth/token.py
75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 | |
test_is_full_auth ¶
test_is_full_auth(
auth,
function_name: str | None = None,
debug_num_stacks_to_drop: int = 1,
) -> None
Test that the provided object is a DomoFullAuth instance.
This validation function ensures that the authentication object is of the correct type for functions that specifically require full authentication.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
auth
|
The authentication object to validate |
required | |
function_name
|
str | None
|
Override function name for error reporting |
None
|
debug_num_stacks_to_drop
|
int
|
Number of stack frames to drop for debugging |
1
|
Raises:
| Type | Description |
|---|---|
AuthError
|
If auth is not a DomoFullAuth instance |
Source code in src/crew_dcs/auth/utils.py
12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 | |
test_is_jupyter_auth ¶
test_is_jupyter_auth(
auth, required_auth_type_ls: list | None = None
) -> None
Test that the provided object is a valid Jupyter authentication instance.
This validation function ensures that the authentication object is one of the accepted Jupyter authentication types for functions that specifically require Jupyter authentication capabilities.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
auth
|
The authentication object to validate |
required | |
required_auth_type_ls
|
list | None
|
list of acceptable auth types. Defaults to [DomoJupyterFullAuth, DomoJupyterTokenAuth] |
None
|
Raises:
| Type | Description |
|---|---|
AuthError
|
If auth is not one of the required Jupyter auth types |
Source code in src/crew_dcs/auth/utils.py
46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 | |