weblayer is made up of a number of components. You can use them “out of the box”, as shown by the Hello World example, or you can pick and choose from and override them, as introduced in the Components section.
You can then take advantage of the Request Handler API when writing your web application.
helloworld.py shows how to start writing a web application using weblayer‘s default configuration:
from weblayer import Bootstrapper, RequestHandler, WSGIApplication
class Hello(RequestHandler):
def get(self, world):
return u'hello %s' % world
mapping = [(r'/(.*)', Hello)]
config = {
'cookie_secret': '...',
'static_files_path': '/var/www/static',
'template_directories': ['templates']
}
bootstrapper = Bootstrapper(settings=config, url_mapping=mapping)
application = WSGIApplication(*bootstrapper())
def main():
from wsgiref.simple_server import make_server
make_server('', 8080, application).serve_forever()
if __name__ == '__main__': # pragma: no cover
main()
Let’s walk through it. First up, we import Bootstrapper, RequestHandler and WSGIApplication:
from weblayer import Bootstrapper, RequestHandler, WSGIApplication
We then see Hello, a simple request handler (aka “view”) that subclasses the RequestHandler class we imported:
class Hello(RequestHandler):
def get(self, world):
return u'hello %s' % world
Hello defines a single method: get, which will be called when Hello receives an HTTP GET request.
Note
By default, request handlers accept GET and HEAD requests (i.e.: they are theoretically read only). You can explicitly specify which methods of each request handler should be exposed using the __all__ property.
For example, to handle HEAD, GET, POST and DOFOO requests, you might write something like:
class Hello2(RequestHandler):
""" I explicitly accept only HEAD, GET, POST and DOFOO requests.
"""
__all__ = ('head', 'get', 'post', 'dofoo')
def get(self):
form = u'<form method="post"><input name="name" /></form>'
return u'What is your name? %s' % form
def post(self):
return u'Hello %s!' % self.request.params.get('name')
def dofoo(self):
return u'I just did foo!'
Note
In the above example, HEAD requests will be handled by the def get() method. This special case is carried through from the underlying webob.Response implementation (and is documented in select_method()). In most cases, the trick is simply to remember to include 'head' in your __all__ list of exposed methods wherever you expose 'get'.
Note
In order to protect against XSRF attacks, POST Requests (that are not XMLHttpRequest requests) are validated to check for the presence and value of an _xsrf parameter. You can include this in your forms using the xsrf_input (available as xrsf_input in your templates, e.g.:
<form>
${xsrf_input}
</form>
You can disable XSRF validation by setting check_xsrf to False in your application level settings and / or by overriding the check_xsrf RequestHandler class attribute, e.g.:
class Hello3(RequestHandler):
""" I don't validate POST requests against XSRF request forgery.
"""
check_xsrf