Skip to content

Build a blog-shaped API

Start with the ticket-desk tutorial to learn Aksara's complete model → migration → protected REST → test workflow. Then inspect the Blog example for Post/Comment relationships and custom publishing actions.

This page merges the older standalone blog tutorial into the canonical learning path. The old tutorial promised a complete registration/login application while mixing legacy request/serializer APIs and incomplete authentication wiring. Those snippets are no longer the recommended implementation.

Transfer the concepts

Blog requirement Where to learn the implementation
Persist posts and comments Models and migrations
Relate a comment to its post Ticket-desk relations and relations reference
Generate CRUD endpoints First project and ViewSets
Validate titles and content Serializer validation
Identify the caller Authentication and the first-project identity adapter
Restrict publishing or editing Permissions and custom actions
Separate customer workspaces Tenant isolation
Queue a report or notification Background reports
Reauthorize delayed actions Durable actions

An author relationship stores a reference; it does not by itself verify the requesting user's identity or authorize editing. Decide explicitly whether posts are public to read, whether authors may edit only their own posts, and which role may publish. Apply those rules to custom actions as well as CRUD.

Run the supplementary example

The repository Blog README supplies its exact package entry point and migration commands. The example contains Post and Comment; it is not a complete user registration or production publishing system. Its API-key helper does not establish a Principal for generated writes, so the historical unauthenticated seed POST is denied. Do not remove permissions to make that request succeed.

Use the canonical tutorial's verified identity integration when adapting the pattern. Replace its local token mapping with your actual identity service before exposing an application publicly. Test successful create/update/delete, input rejection, anonymous denial and denied edits by another author.

The example catalog distinguishes startup checks from complete authenticated application tests. Follow the production guide before deploying your adaptation.