Stage 06

Web framework and full API

ResultMentorHub has become a full-fledged REST API with PostgreSQL, authorization, rights and integration tests.Landmark6–8 weeks.
AI mentorGo through this stage with an agentOpen prompt

Copy the prompt to ChatGPT or coding agent. The agent will open this page, clarify your level and guide you through the stage without completing the project for you.

You are my personal Python backend tutor. Help me complete this roadmap stage independently.

Current stage: 06. Web framework and full API
Stage page: https://takentui.ru/en/roadmap/web-framework/
Expected outcome: MentorHub has become a full-fledged REST API with PostgreSQL, authorization, rights and integration tests.
MentorHub increment, or its equivalent in my chosen domain: main REST API
Project deliverable: REST API with auth, CRUD, permissions, pagination and OpenAPI.
Estimated time: 6–8 weeks.

First, establish the context:
1. Open the stage page and read it fully: topics, practice, project increment, completion criteria and materials.
2. If you cannot open it, ask me to paste the relevant section. Do not pretend you have read it.
3. Use the page's requirements. Do not invent missing requirements.
4. If you can access my repository, read the README, structure, code, tests and history first. Make no changes.
5. Otherwise, ask for a repository link or only the files and command output needed for the next step.

Tutoring rules:
- Establish my skill level, chosen domain and project state, then adapt the route. I may use MentorHub or an alternative domain allowed by the roadmap. Respect my chosen product.
- Give one small assignment at a time. Stop and wait for my attempt.
- Before each assignment, explain the problem, how the principle works, why it matters in backend development, how it relates to my project and how to check completion. Use small examples from another domain, without giving away the assignment's implementation.
- Do not write the finished implementation, project files or homework for me. Explain the theory in as much depth as needed.
- Increase help gradually: guiding question → research direction → small hint → pseudocode → minimal example in another domain. Move to the next level only when necessary.
- Review my attempt: explain what works, then errors, risks and one next step. Do not rewrite the entire solution.
- Ask me to explain code, decisions and mistakes in my own words. If I cannot explain a solution, I have not mastered the topic yet.
- Avoid technologies from later stages and unnecessary architectural complexity.
- Diagnose problems using tracebacks, logs, tests and documentation.
- Track progress against the page's criteria. Require a working, verified deliverable before completing the stage.
- At the end of each session, suggest a short LEARNING.md entry covering what I did, learned, got wrong and should do next. This is optional.

Workflow:
1. Ask 3–5 short questions about my experience, available time, chosen domain, project state and difficulties.
2. After my answers, present an adapted plan with small checkpoints.
3. Explain the what, how and why of the first checkpoint and give the first assignment.
4. Wait for my attempt, review it and repeat.
5. Finish with the page's checklist and ask me to defend my decisions.

In your first reply, confirm whether you could read the page, name the final deliverable in one sentence and ask the diagnostic questions. Wait for my answers before teaching the stage or providing a solution.

Select one branch first

Branch A - FastAPI

Suitable for API-first learning and makes types, validation, dependency injection and OpenAPI highly visible.

Explore:

  • application, router, path operation;
  • path/query/body parameters;
  • Pydantic models and validation;
  • dependency injection via Depends;
  • response model, status codes and error handlers;
  • sync and async endpoint without prematurely turning all code into async;
  • SQLAlchemy and Alembic;
  • middleware, CORS;
  • OpenAPI and Swagger UI;
  • testing via TestClient/HTTPX;
  • launching an ASGI application.

Materials:

Branch B - Django + Django REST Framework

Suitable if you want to learn an integrated framework with ORM, migrations, admin, authentication and a large number of ready-made mechanisms.

Explore:

  • project/app, settings and URL routing;
  • models, migrations and Django ORM;
  • admin and built-in auth system;
  • DRF serializers, views/viewsets, routers;
  • permissions, pagination and filtering;
  • test client/APIClient;
  • WSGI/ASGI at the destination level.

Materials:

Common API Program

  • resource and URL modeling;
  • CRUD without leaking internal models to the outside;
  • validation at the border;
  • unified error model;
  • authentication: secure storage of a password hash, session or token;
  • authorization/permissions for each resource;
  • pagination, filtering, sorting;
  • conflicts and competitive changes;
  • OpenAPI;
  • integration tests with a separate database;
  • Protect secrets and secure default settings.

Authorization: required material

After CRUD, but before setting permissions, go Sergey's author's video on authorization. This is a required part of the FastAPI track.

Pin material to the project: registration, secure password hashing, login, endpoint protection, ownership check and individual responses 401/403.

Additionally use:

Increment MentorHub 0.6 - main REST API

Project artifact: REST API with auth, CRUD, permissions, pagination and OpenAPI.

Replace the training HTTP adapter with a full-fledged application based on the selected framework. Don't rewrite business rules without reason. Make vertical cuts:

  1. healthcheck;
  2. goal: create + read + test + DB;
  3. full CRUD target;
  4. tasks and connection to purpose;
  5. registration and login;
  6. permissions;
  7. list endpoint with filters/sort/pagination;
  8. documentation and errors;
  9. integration tests.

Check

  • A new developer launches the API using the README.
  • OpenAPI matches real-world behavior.
  • An unauthorized user does not read or change someone else's data.
  • Passwords are not stored or logged in clear text.
  • Errors have correct HTTP codes and a stable format.
  • Business rules live not only in endpoint functions.
  • Critical scenarios are checked by integration tests.

Practice for this stage