5.3 KiB
Online Booking Application
Cliff Hill's Coding Project
This is a full-stack application simulating an online booking system for conference rooms.
Backend decisions
I decided to push to Python 3.13, because there are always language improvements as they are advanced, some of them help make the code more readable (like the use of pipe syntax for type hinting) others are the improved error messages and better interactive interpreter in 3.13, both of which help with debugging.
The structure I picked for the backend is what I have found from research to be the preferred way to structure the code. When a file gets too large, I split it into multiple files under a subdirectory - like with services, where it simply was unweildly to manage.
Security concerns
There is no login or security in place with this project. However if set up with zero trust, an example scenario could use OpenID or similar login security, encrypted JWTs, secure connections could be established to the database as well as all traffic being moved to https rather than http, locking everything down to ensure that those who communicate with any part of this system are authenticated and have only the access that they are authorized. Each endpoint would need to be able to check that the user is authenticated and has a valid token that has not expired in order to be used.
There already is several pieces for helping secure the application on the backend, using the HyperModern Python cookiecutter and the tools it brings into play, however additional systems could be tied into github to help check things further (like New Relic).
Typically, the database username/password/etc would not be stored in the repo but in a secrets component and loaded separately. This was bypassed this time as that was outside of the scope of this project and was additional overhead to work with.
AI Use
I used AI to stub out a couple of files:
- The backend/Dockerfile and frontend/Dockerfile - to speed up the process of getting docker loaded efficiently for the project.
- The compose.yml file - getting the different images gathered together quickly.
- The compose.dev.yml file - used to get a further understanding of how to hook up an extension to the previous file.
- The mermaid diagrams used in this file.
- I have the CodeGPT plugin in VSCode, and it has helped with docstrings, logging messages, and sometimes reducing the time it takes me to write out the code.
Running for production
The standard docker compose file is used to set up the project in the production environment, and can be run from the following command:
docker compose up
In this mode, only one port is exposed in docker - the port 3000, which is the frontend. Postgres and the backend ports are hidden.
Local running
There is an alternative compose file specifically designed for running this project locally which allows for real-time editing and updating of either the frontend or backend components. The command ro tun everything locally is:
docker compose -f compose.dev.yml up
This compose file extends the standard compose file, adding in the necessary pieces to make the application usable in a local dev environment. In this configuration, the frontend is accessable from port 3000 like normal, the backend is accessable from port 8000, and postgres DB from 5432. The way this is set up, that command can easily be run in a separate terminal window during development for rapid testing of the piece(s) being worked on. Logging is at Debug level, and SQLAlchemy is set to echo mode, so queries are also logged. Realtime changes are reflected in the application as the code is run, and commands can be run locally from your terminal (like alembic) without needing to shell into the docker image.
For development builds, running "pre-commit install" inside the backend folder will install the pre-commit components for ensuring the code is good and clean before it gets commited to the repo.
The .env.sample can be copied to .env as well in order to get basic environment variables configured. As this is a system that usually has no external means to reach the database (in the production environment) I have left the actual username/password/etc for the database intact in the files in the repo.
Diagrams
Docker Compose Components:
graph TD
subgraph Docker_Network
B[Frontend] -->|HTTP/REST: Port 8000| C[Backend]
C -->|SQL: Port 5432| D[PostgreSQL]
end
A[World] -->|HTTP: Port 3000| B
Backend Request Data Path:
sequenceDiagram
participant Frontend
participant FastAPI_Router as FastAPI Router
participant API_Endpoint as API Endpoint
participant Pydantic_Schema as Pydantic Schema
participant Service_Layer as Service Layer
participant Model
participant Database
Frontend->>FastAPI_Router: HTTP Request
FastAPI_Router->>API_Endpoint: Matches Route
API_Endpoint->>Pydantic_Schema: Validate Input
Pydantic_Schema-->>API_Endpoint: Validated Data
API_Endpoint->>Service_Layer: Pass Validated Data
Service_Layer->>Model: Apply Business Logic
Model->>Database: Perform DB Operations
Database-->>Model: Return Query Result
Model-->>Service_Layer: Return Processed Data
Service_Layer-->>API_Endpoint: Return Response Data
API_Endpoint-->>Frontend: HTTP Response