June 25, 2021
š FastAPI and friends newsletter: security updates, the future of FastAPI, MongoDB tools...
Issue #3, security updates, the future of FastAPI, MongoDB tools...

Hey there! š
Thereās lots of news about FastAPI and friends, security releases, new tools, articles, and more.
These are exciting times! Have fun. š¤
@tiangolo (SebastiĆ”n RamĆrez)
š Security: FastAPI version 0.65.5 includes a security fix for a CSRF vulnerability
Please upgrade to FastAPI 0.65.2 as soon as possible if you havenāt already.
This version fixes a CSRF vulnerability in applications that use cookies to authenticate path operations that receive JSON payloads sent by browsers.
You can read more about it in the CVE-2021-32677.
š¢ News: The Future of FastAPI and Pydantic is Bright
This is because we all, as the Python community, define their future. āØ
You might have heard not long ago about PEP 563, PEP 649, and some changes that could have affected Pydantic and FastAPI in future versions of Python.
If you want to understand a bit more what was that about and what happened in the end, I wrote this article to try and clarify it.
TL;DR: It all turned out well, with the community stronger, and the Python Steering Council demonstrated their commitment to supporting the whole Python Community, including FastAPI and Pydantic. š
š Security: Pydantic released a security fix for datetime fields
If possible, you should upgrade to the latest version.
But if you are limited to a version range, you can upgrade to versions:
- 1.8.2
- 1.7.4
- 1.6.2
You can read more about it in the CVE-2021-29510.
š¢ News: FastAPI is the 3rd most used Python web framework
FastAPI was included for the first time in the last official Python Developer Survey, and itās already ranked as the third most used Python web framework, right below Flask and Django! š
Itās an honor to be among these great libraries.
There are also many other great insights in the survey results, check them out!
š Learning: Deploying FastAPI apps with HTTPS powered by Traefik recording available
This session, teaches how to easily and simply deploy a FastAPI app to production with HTTPS using Traefik. If you need a simple and easy way to deploy a web app using HTTPS this might be interesting to you.
š¢ News: Enterprises should start trying out FastAPI, says ThoughtWorks
ThoughtWorks recently released their latest Technology Radar, including FastAPI as one of the technologies they recommend enterprises should include in their trials.
š Learning: Getting Started with MongoDB and FastAPI
Do you like MongoDB? Are you curious about it?
The MongoDB team recently released a couple of articles on how to get started with MongoDB and FastAPI, check them out!
- Getting Started with MongoDB and FastAPI using pure Pydantic models.
- Build a Cocktail API with Beanie and MongoDB using Beanie, an ODM based on Pydantic.
š§ Tools: MongoDB ODMs, ODMantic and Beanie
Continuing with MongoDB, if you are interested in using it with FastAPI, you will probably benefit from declaring the schema for your documents with classes. The tools that help you doing that are called āObject-Document Mappersā or ODMs.
In these cases, you might benefit from using one of the ODMs based on Pydantic, to simplify your code and keep it consistent.
One option is to simply use Pydantic directly to manipulate the data, and handle the queries manually. Just as in the example above, in the article Getting Started with MongoDB and FastAPI.
But in other cases, you might benefit from an actual ODM with other features that can, for example, help you building queries. In these cases you might want to check out these tools:
Both libraries have different styles, but both are based on Pydantic, so you will get the same familiar way of declaring your data with them and avoid code duplication.
š Learn: Get started with FastAPI JWT on Deta
Are you using Deta?
In this tutorial you can learn how to use JWT authentication with Deta using FastAPI.
š§ Tools: Poetry Version plugin for building packages
This is not strictly related to FastAPI, or Typer, but it will make it easier for me to build new complementing Python packages.
Iām a fan of Poetry, if you havenāt seen it, check it out.
Itās a single, simple tool to:
- Manage virtual environments, like venv, Pipenv, or others
- Manage dependencies, like requirements.txt
- Install dependencies, like pip, but adding them automatically to your projectās configuration file
- Build and publish Python packages
Thatās a lot of features from a simple tool, and learning it for just some tasks can make it easier to achieve other tasks in the future.
The only caveat it had for me, which is a very subjective one, is that I couldnāt declare the version of a package in a variable like:
__version__ = "0.1.0"
But the latest Alpha version of Poetry supports plugins, so I built a Poetry Version Plugin that does that for me.
If you are building Python packages to publish to PyPI, it might also be interesting for you. š¤
š Interviews: I (SebastiĆ”n RamĆrez) was recently interviewed at Real Python and Console
If you are curious, you can read about some of the details behind my work with FastAPI, Typer, and others:
- Real Python: Python Community Interview With SebastiĆ”n RamĆrez. This interview was done some months ago, while I was still working for Explosion, but the rest is still relevant, including what are the features I consider important, what I try to optimize in code, some hobbies, etc.
- Console: An Interview With SebastiĆ”n RamĆrez of FastAPI. Jackson asked questions about several of the things I have strong opinions about š , check it out if you want to hear me (read me) ranting about different topics, people that have influenced me, day-to-day apps I use, open source and sustainability, and more.
š¢ News: Work change, more open source
A couple of months ago I announced that I decided to leave Explosion to be able to dedicate more time to FastAPI, Typer, and other open source projects.
Iām doing some external consultancy for some teams to make it all sustainable.
As part of that, I recently joined the team at Forethought, and announced it here on Twitter. Part of the arrangement includes a lot of work on open source. āØ
They also accepted to have me only 3 days a week, so Iāll still be able to help other companies and teams. š¤
Forethought is growing and continuously hiring top-notch talent. They are awesome. Check the open positions. š° This also means that YOU could be working with me š ā¦if that sounds cool. š
What do you think about the newsletter?
Let me know what you liked, what you didnāt, or what other things you would like to see here.
An email or Twitter works. š