6 ms·
If you're writing a REST api, invest the time to learn Django Rest Framework. It is well worth it.
by n0us 8y ago
If you're writing a REST api, invest the time to learn Django Rest Framework. It is well worth it.
- Alex3917 8y agoAgreed, but with the caveat that there are a lot of bad parts of DRF. It's probably the best tool to build a REST API, but only if you're using some minimal subset of the tools available.
- blowski 8y agoWhat are the bad bits? Why are they bad?
- Alex3917 8y agoToo many issue to enumerate them here, but there are just a lot of things that are likely to lead to security vulnerabilities or hidden performance problems. I'm planning to write a blog post on this in the next few weeks.
- douglaswlance 8y agoHow do I subscribe to get it?
- Alex3917 8y agoI'll post it here, you can subscribe via email: http://alexkrupp.typepad.com/ http://alexkrupp.typepad.com/
- k1ns 8y agoSeconded. It provides an API similar to that of Django's various Form classes. It should feel somewhat familiar, even to newcomers. Their documentation is also great with rich examples and explanations.
- pure_ambition 8y agoIt's my understanding that you can use Django's Form classes to replicate any POST/UPDATE/DELETE operations you'd like to use DRF for. I'm not sure what else DRF gets you besides more API-like auth - for example I don't know how well Django would support token-based auth out-of-the-box as compared to DRF.
- Daishiman 8y agoYou get: * pluggable authentication methods (literally adding JWT, session and cookie tokens takes one line of code * pluggable output serializers (want YAML? Plug in a renderer. XML? Same thing) * pluggable documentation generators * Utility methods for handling RESTful response types DRF has a staggering amount of features that, if implemented by hand, require a stupid amount of time and a 100% guarantee of subtle bugs.
- akx 8y agoDRF is nice enough 90% of the way, but when you need to do something that its authors haven't really thought of, you need to dig in very deep to fix things, I've found. :/
- Demiurge 8y agoAgreed, for this reason I stopped using it, the investment in those digs were not worth the time to not copy/paste some CRUD api views. Which is what I do now, and modify as needed. If the number of models and views grows too much and gets brittle, maybe it will be worth trying again.
- buttscicles 8y agoI think this is true of django in general.
- sotojuan 8y ago> I think this is true of django in general Probably goes for all opinionated frameworks. That's part of the tradeoff you make when choosing one.
- douglaswlance 8y agoIf that's the case, you should take a step back and think about it from another angle to make absolutely sure that you're not attacking the problem from the wrong vector.
- dwaltrip 8y agoI have heard great things about DRF, and often it is good to resist coloring outside the lines. That being said, your comment assumes that DRF has indeed thought of everything. All abstractions leak, some more than others. Clean escape hatches are very valuable.
- douglaswlance 8y agoI never said that you MUST be thinking about it wrong. I just said to make sure you're not thinking about it wrong. No framework has thought of everything.
- rb808 8y agoIsn't Flask simpler for REST stuff?
- jrs95 8y agoSort of, but you'll have to assemble several different libraries to make it good. It doesn't handle request validation, JSON serialization/deserialization, or databases well out of the box. If you use Flask with Flask-SQLAlchemy be sure to use apply_driver_hacks to enable the pool_pre_ping option or you'll end up in production wondering why 1/3 of your requests are getting a bad DB connection from the pool. Honestly, it seems like many somewhat essential libraries for Flask APIs are being maintained by one person on GitHub. I wouldn't want to put my faith in that for a core part of my business. Django has a lot more resources going into it even if it's not as powerful as SQLAlchemy or as simple as Flask.
- shakna 8y agoHug [0] has my goto for REST. Validation, versioning, serialization, automatic documentation. [0] http://hug.rest http://hug.rest
- jrs95 8y agoThis looks great! I've been keeping my eye on APIStar but that still seems like it's undergoing a lot of breaking changes. This delivers a lot of the same benefits but it looks like it's actually production ready!
- cup-of-tea 8y agoFlask-Restful seems pretty well maintained and it's very easy to use. If you use marshmallow it's very easy to get request validation with meaningful errors. There is also a package called apispec that can make a Swagger specification from your flask paths and marshmallow models. I like Django but unless I'm using it already I've not seen a reason to use it instead of these simpler libraries for APIs.
- major505 8y ago