Build a blog-shaped API¶
Start with the ticket-desk tutorial to learn Aksara's complete model → migration → protected REST → test workflow. Then inspect the Blog example for Post/Comment relationships and custom publishing actions.
This page merges the older standalone blog tutorial into the canonical learning path. The old tutorial promised a complete registration/login application while mixing legacy request/serializer APIs and incomplete authentication wiring. Those snippets are no longer the recommended implementation.
Transfer the concepts¶
| Blog requirement | Where to learn the implementation |
|---|---|
| Persist posts and comments | Models and migrations |
| Relate a comment to its post | Ticket-desk relations and relations reference |
| Generate CRUD endpoints | First project and ViewSets |
| Validate titles and content | Serializer validation |
| Identify the caller | Authentication and the first-project identity adapter |
| Restrict publishing or editing | Permissions and custom actions |
| Separate customer workspaces | Tenant isolation |
| Queue a report or notification | Background reports |
| Reauthorize delayed actions | Durable actions |
An author relationship stores a reference; it does not by itself verify the requesting user's identity or authorize editing. Decide explicitly whether posts are public to read, whether authors may edit only their own posts, and which role may publish. Apply those rules to custom actions as well as CRUD.
Run the supplementary example¶
The repository Blog README supplies its exact package entry point and migration
commands. The example contains Post and Comment; it is not a complete user
registration or production publishing system. Its API-key helper does not
establish a Principal for generated writes, so the historical unauthenticated
seed POST is denied. Do not remove permissions to make that request succeed.
Use the canonical tutorial's verified identity integration when adapting the pattern. Replace its local token mapping with your actual identity service before exposing an application publicly. Test successful create/update/delete, input rejection, anonymous denial and denied edits by another author.
The example catalog distinguishes startup checks from complete authenticated application tests. Follow the production guide before deploying your adaptation.