thunderbird_accounts.authentication.clients
Classes
Client for Keycloak's built-in Account REST API. |
|
|
|
Client for the keycloak-mfa-rest provider. |
|
Base client for realm-scoped Keycloak calls made as the end user. |
|
|
|
- class thunderbird_accounts.authentication.clients.ActiveSessionResponse[source]
Bases:
GeoIPSession
- class thunderbird_accounts.authentication.clients.ConnectedAppResponse[source]
Bases:
GeoIPSession
- class thunderbird_accounts.authentication.clients.KeycloakSelfServiceClient[source]
Bases:
objectBase client for realm-scoped Keycloak calls made as the end user.
These use the end user’s forwarded OIDC access token and operate on the token subject: Keycloak’s built-in Account REST API and our self-service provider APIs. Keep this separate from the admin API client so the two trust boundaries cannot accidentally share auth or endpoint routing.
- class thunderbird_accounts.authentication.clients.KeycloakAccountClient[source]
Bases:
KeycloakSelfServiceClientClient for Keycloak’s built-in Account REST API.
- class thunderbird_accounts.authentication.clients.KeycloakMfaClient[source]
Bases:
KeycloakSelfServiceClientClient for the keycloak-mfa-rest provider.
- start_totp_setup(user_access_token: str) TotpSetupResponse[source]
Generate a TOTP secret + otpauth URI for the calling user without writing it.