Skip to main content

LocalUser

SQL-backed user.

Stores credentials and profile information locally. Users may be identified
by email, username, or phone_number; at least one identifier is required.
Default implementation for rapid development.

Attributes:
email: Optional unique email address
username: Optional unique username
phone_number: Optional unique phone number
email_verified: Whether email ownership has been verified
phone_verified: Whether phone ownership has been verified
password_hash: Argon2 hash of password (excluded from serialization)
full_name: Optional display name
is_active: Whether user can log in (default True)
roles: List of assigned roles used for RBAC checks

Security:
- password_hash is excluded from model_dump() and model_dump_json()
- Never store plaintext passwords
- Use argon2 for hashing (see LocalIdentityAdapter)

Example:
user = LocalUser(
email="john@example.com",
password_hash="$argon2id$v=19$...",
full_name="John Doe",
)

Source: user.py

Fields

FieldTypeRequiredDescriptionValidators
emailNoneUnique email address (optional if username/phone provided)-
usernameNoneUnique username (optional if email/phone provided)-
phone_numberNoneUnique phone number (optional if email/username provided)-
email_verifiedboolWhether the email address has been verified-
phone_verifiedboolWhether the phone number has been verified-
password_hashNonepassword hash-
full_nameNoneUser's display name-
is_activeboolWhether user can log in-
roleslist[str]Assigned RBAC roles-
tenantslist[str](
"Tenant binds this user may access. Empty means unscoped: combined with "
"the 'System' role it yields a trustee/back-office view across every "
"registered tenant; without 'System' an empty list grants no tenant data."
) | - |

Permissions

RoleCreateDeleteReadWrite
Admin
User

Configuration

SettingValue
SubmittableFalse
Track ChangesTrue

Controller

Controller hooks are implemented in *_controller.py files. Available lifecycle hooks:

  • validate() - Called before save, raise exceptions for validation errors
  • before_insert() - Called before inserting a new document
  • after_insert() - Called after successfully inserting
  • before_save() - Called before saving (insert or update)
  • after_save() - Called after saving
  • before_delete() - Called before deleting
  • after_delete() - Called after deleting