Back to archive

June 25, 2021

šŸš€ FastAPI and friends newsletter: security updates, the future of FastAPI, MongoDB tools...

Issue #3, security updates, the future of FastAPI, MongoDB tools...

FastAPI and Friends - the official newsletter

Hey there! šŸ‘‹

There’s lots of news about FastAPI and friends, security releases, new tools, articles, and more.

These are exciting times! Have fun. šŸ¤“

@tiangolo (SebastiƔn Ramƭrez)

šŸ”’ Security: FastAPI version 0.65.5 includes a security fix for a CSRF vulnerability

Please upgrade to FastAPI 0.65.2 as soon as possible if you haven’t already.

This version fixes a CSRF vulnerability in applications that use cookies to authenticate path operations that receive JSON payloads sent by browsers.

You can read more about it in the CVE-2021-32677.

šŸ“¢ News: The Future of FastAPI and Pydantic is Bright

This is because we all, as the Python community, define their future. ✨

You might have heard not long ago about PEP 563, PEP 649, and some changes that could have affected Pydantic and FastAPI in future versions of Python.

If you want to understand a bit more what was that about and what happened in the end, I wrote this article to try and clarify it.

TL;DR: It all turned out well, with the community stronger, and the Python Steering Council demonstrated their commitment to supporting the whole Python Community, including FastAPI and Pydantic. šŸŽ‰

šŸ”’ Security: Pydantic released a security fix for datetime fields

If possible, you should upgrade to the latest version.

But if you are limited to a version range, you can upgrade to versions:

  • 1.8.2
  • 1.7.4
  • 1.6.2

You can read more about it in the CVE-2021-29510.

šŸ“¢ News: FastAPI is the 3rd most used Python web framework

FastAPI was included for the first time in the last official Python Developer Survey, and it’s already ranked as the third most used Python web framework, right below Flask and Django! šŸŽ‰

It’s an honor to be among these great libraries.

There are also many other great insights in the survey results, check them out!

šŸ“ Learning: Deploying FastAPI apps with HTTPS powered by Traefik recording available

This session, teaches how to easily and simply deploy a FastAPI app to production with HTTPS using Traefik. If you need a simple and easy way to deploy a web app using HTTPS this might be interesting to you.

šŸ“¢ News: Enterprises should start trying out FastAPI, says ThoughtWorks

ThoughtWorks recently released their latest Technology Radar, including FastAPI as one of the technologies they recommend enterprises should include in their trials.

šŸ“ Learning: Getting Started with MongoDB and FastAPI

Do you like MongoDB? Are you curious about it?

The MongoDB team recently released a couple of articles on how to get started with MongoDB and FastAPI, check them out!

šŸ”§ Tools: MongoDB ODMs, ODMantic and Beanie

Continuing with MongoDB, if you are interested in using it with FastAPI, you will probably benefit from declaring the schema for your documents with classes. The tools that help you doing that are called ā€œObject-Document Mappersā€ or ODMs.

In these cases, you might benefit from using one of the ODMs based on Pydantic, to simplify your code and keep it consistent.

One option is to simply use Pydantic directly to manipulate the data, and handle the queries manually. Just as in the example above, in the article Getting Started with MongoDB and FastAPI.

But in other cases, you might benefit from an actual ODM with other features that can, for example, help you building queries. In these cases you might want to check out these tools:

Both libraries have different styles, but both are based on Pydantic, so you will get the same familiar way of declaring your data with them and avoid code duplication.

šŸ“ Learn: Get started with FastAPI JWT on Deta

Are you using Deta?

In this tutorial you can learn how to use JWT authentication with Deta using FastAPI.

šŸ”§ Tools: Poetry Version plugin for building packages

This is not strictly related to FastAPI, or Typer, but it will make it easier for me to build new complementing Python packages.

I’m a fan of Poetry, if you haven’t seen it, check it out.

It’s a single, simple tool to:

  • Manage virtual environments, like venv, Pipenv, or others
  • Manage dependencies, like requirements.txt
  • Install dependencies, like pip, but adding them automatically to your project’s configuration file
  • Build and publish Python packages

That’s a lot of features from a simple tool, and learning it for just some tasks can make it easier to achieve other tasks in the future.

The only caveat it had for me, which is a very subjective one, is that I couldn’t declare the version of a package in a variable like:

__version__ = "0.1.0"

But the latest Alpha version of Poetry supports plugins, so I built a Poetry Version Plugin that does that for me.

If you are building Python packages to publish to PyPI, it might also be interesting for you. šŸ¤“

šŸŽ™ Interviews: I (SebastiĆ”n RamĆ­rez) was recently interviewed at Real Python and Console

If you are curious, you can read about some of the details behind my work with FastAPI, Typer, and others:

šŸ“¢ News: Work change, more open source

A couple of months ago I announced that I decided to leave Explosion to be able to dedicate more time to FastAPI, Typer, and other open source projects.

I’m doing some external consultancy for some teams to make it all sustainable.

As part of that, I recently joined the team at Forethought, and announced it here on Twitter. Part of the arrangement includes a lot of work on open source. ✨

They also accepted to have me only 3 days a week, so I’ll still be able to help other companies and teams. šŸ¤“

Forethought is growing and continuously hiring top-notch talent. They are awesome. Check the open positions. šŸ’° This also means that YOU could be working with me šŸ˜Ž …if that sounds cool. šŸ˜…

What do you think about the newsletter?

Let me know what you liked, what you didn’t, or what other things you would like to see here.

An email or Twitter works. šŸ˜‰