This is a basic crud app that allows a media company to manage actors
and movies
resources. This app uses:
- flask for backend service
- auth0 for third party authentication
- postgresql for database
Create a database for local unitesting
Login to the psql console and create a database
psql -U postgres psql> CREATE DATABASE capstone_test;
Create a file it should have the following contents:
# Setup data base path
export DATABASE_URL="postgresql://{user}:{pw}@localhost:5432/{database_name}"
# Setup Auth0 credentials
export AUTH0_DOMAIN=""
export API_AUDIENCE="casting"
export ALGORITHMS="RS256"
Now install all the dependencies in a virtual environment using
pip intsall -r requirements.txt
Now run
to run all the unitests -
In order to run the app first run the migrations
python db init python db migrate
Then run the app:
export FLASK_APP=run_local
export FLASK_ENV=development
export DEBUG=1
flask run
There are three users who have been mapped to three roles:
- User1
- Username: [email protected]
- Password: casting@1234
- Permissions: get:actors, get:movies
- Role: Casting Assistant
- User2
- Username: [email protected]
- Password: director@123
- Permissions: get:actors, get:movies, post:actors, patch:actors, delete:actors, patch:movies
- Role: Casting Director
- User3
- Username: [email protected]
- Password: producer@123
- Permissions: get:movies, get:actors, delete:movies, delete:actors, post:movies, post:actors, patch: movies, patch:actors
- Role: Executive Producer
Use tokens stored in to test the api locally
The app is hosted on heroku at This app can also be hosted on any linux box. Make sure a postgres server is running and a database for the use by this app is available.
Follow steps 1 to 5 given in Running Locally section. To run the actual server use gunicorn
gunicorn --bind server:app
┣ 📂app
┃ ┣ 📂auth
┃ ┃ ┣ 📜 ## Provides requires_auth decorator
┃ ┃ ┗ 📜
┃ ┣ 📂models
┃ ┃ ┣ 📜 ## Manages tables and db utils
┃ ┃ ┗ 📜
┃ ┣ 📂routes
┃ ┃ ┣ 📜 ## Logic for endpoints
┃ ┃ ┗ 📜
┃ ┗ 📜
┣ 📜 ## Manages migrations
┣ 📜
┣ 📜requirements.txt
┣ 📜 ## Runs local development server
┣ 📜 ## Environment Variables
┗ 📜 ## Unittests
Login to the app, this takes you to the login page, using user credentials for User1 or User2 or User3 given above one can obtain tokens.
Note: In case tokens in expire, please use this endpoint to obtain fresh tokens
Health check for app returns the following json
This returns a json object with id,age,gender,count and a Boolean on the success of the call. A sample json is given below:
GET /movies
This will return the id, title and release date. See example below
DELETE /actors/id
Deletes an actor from the database based his/her id
The end point can be reached as
curl -H "Authorization: Bearer mytoken123" -X DELETE http://{{domian}}/api/actors/1
If the actor with actor id exists the following response will be shown
If the actor doesn't exist a 404 response will be sent back
DELETE /movies/id
This will delete the movie given the id. This endpoint can be reached as:
curl -H "Authorization: Bearer mytoken123" -X DELETE http://{{domian}}/api/movies/1
If the movie with given id exists, then the following response will be sent back:
If the movie id doesn't exist a 404 will be sent
POST /actors
This will create a new actor resource. The body will be json with fields such as name,age and gender. The field gender can only take values male or female and can't be empty.
The end point can be reached as follows:
curl -H "Content-Type: application/json" -H "Authorization: Bearer mytoken123" \
--request POST \
--data '{"name":"xyz","age":30,"gender":"male"}' \
If the actor resource is successfully created following json response will be sent:
In case the resource can't be created a 422 error code will be raised
POST /movies
This will create a new movie resource. The body will be json with fields such as title and release_date (dd/mm/yyyy).
The end point can be reached as follows:
curl -H "Content-Type: application/json" -H "Authorization: Bearer mytoken123"
--request POST \
--data '{"title":"xyz","release_date":"20/11/2020"}' \
If the movie resource is successfully created following json response will be sent:
In case the the resource can't be created a 422 will be raised
PATCH /actors/id
This will update an actor resource. The body will be json with fields such as name or age or gender . The field gender can only take values male or female and can't be empty.
curl -H "Content-Type: application/json" -H "Authorization: Bearer mytoken123"
--request PATCH \
--data '{"name":"xyz","age":30}' \
If the actor resource is successfully created following json response will be sent:
In case the update fails a 422 will be raised
PATCH /movies/id
This will update a movie resource. The body will be json with fields such as title and release date
curl -H "Content-Type: application/json" -H "Authorization: Bearer mytoken123"
--request PATCH \
--data '{"title":"xyz","release_date":"20/11/2020"}' \
If the movie resource is successfully created following json response will be sent:
In case the movie resource can't be updated a 422 will be raised.