1. API Versioning
# settings.py
REST_FRAMEWORK = {
'DEFAULT_VERSIONING_CLASS': 'rest_framework.versioning.URLPathVersioning',
'DEFAULT_VERSION': 'v1',
'ALLOWED_VERSIONS': ['v1', 'v2'],
}
# urls.py
urlpatterns = [
path('api/<str:version>/', include(router.urls)),
]
# views.py
class ProductViewSet(viewsets.ModelViewSet):
def get_serializer_class(self):
if self.request.version == 'v2':
return ProductV2Serializer
return ProductV1Serializer
2. Throttling (Rate Limiting)
# settings.py
REST_FRAMEWORK = {
'DEFAULT_THROTTLE_CLASSES': [
'rest_framework.throttling.AnonRateThrottle',
'rest_framework.throttling.UserRateThrottle',
],
'DEFAULT_THROTTLE_RATES': {
'anon': '100/hour',
'user': '1000/hour',
'burst': '60/min',
},
}
# Custom throttle
from rest_framework.throttling import SimpleRateThrottle
class BurstRateThrottle(SimpleRateThrottle):
scope = 'burst'
def get_cache_key(self, request, view):
if request.user.is_authenticated:
return self.cache_format % {
'scope': self.scope,
'ident': request.user.pk,
}
return self.get_ident(request)
3. API Docs với drf-spectacular
pip install drf-spectacular
# settings.py
INSTALLED_APPS = [..., 'drf_spectacular']
REST_FRAMEWORK = {
'DEFAULT_SCHEMA_CLASS': 'drf_spectacular.openapi.AutoSchema',
}
SPECTACULAR_SETTINGS = {
'TITLE': 'My API',
'DESCRIPTION': 'API documentation',
'VERSION': '1.0.0',
}
# urls.py
from drf_spectacular.views import SpectacularAPIView, SpectacularSwaggerView
urlpatterns = [
path('api/schema/', SpectacularAPIView.as_view(), name='schema'),
path('api/docs/', SpectacularSwaggerView.as_view(url_name='schema')),
]
Custom Schema Annotations
from drf_spectacular.utils import extend_schema, OpenApiParameter
class ProductViewSet(viewsets.ModelViewSet):
@extend_schema(
parameters=[
OpenApiParameter('category', str, description='Filter by category slug'),
OpenApiParameter('min_price', float),
],
responses={200: ProductSerializer(many=True)},
)
def list(self, request, *args, **kwargs):
return super().list(request, *args, **kwargs)
4. CORS Configuration
pip install django-cors-headers
# settings.py
INSTALLED_APPS = [..., 'corsheaders']
MIDDLEWARE = ['corsheaders.middleware.CorsMiddleware', ...]
CORS_ALLOWED_ORIGINS = [
'https://frontend.example.com',
]
CORS_ALLOW_CREDENTIALS = True
Bài tiếp theo: Authentication — Session, Token & JWT.