Accounts and identity
How ABRIA creates real user IDs, sessions, device links and one-time credentials.
Source map
- python/abria_server/abr_identity.py
- python/abria_server/abr_storage.py
Account creation
ABRIdentityStore creates a UUID user id, a unique abr-<hex> username and a 24-character generated password. Passwords are hashed with scrypt and a random 16-byte salt before storage.
- Password returned once at account creation
- Session token is stored only as a SHA-256 digest in durable session state
- Default session lifetime is configurable and clamped to 1..365 days
AETHER-backed records
Identity data is not stored in a new local SQLite database by this implementation. Account/session/link records are committed through ABRAetherBridge.
Device linking
Authenticated users can create a short-lived link code, bind identity metadata, then consume the code on another device to receive a fresh session token.
Docs mini identity
The embedded docs bot uses a same-origin Next route that creates one real ABRIA account when needed and stores only the session token in an HttpOnly cookie. Browser JavaScript never receives the raw bearer token or one-time password.