ZCore LogoZCore
Quick learn

Step 8 - Web Layer & Plugin System

Scaffold 8 secure endpoints instantly and register your domain with the application Kernel.

Instead of writing 8 redundant route functions for every model, ZCore's BaseRouter generates them securely out-of-the-box (including dynamic search and field-projected lookups). We then register everything cleanly via the Plugin system.

Configure the Router

Open tasks/routers.py and link your schemas, model, and service:

# tasks/routers.py
from zcore import BaseRouter, RouteKey
from .models import Task
from .schemas import TaskCreate, TaskUpdate, TaskResponse
from .services import TaskService

class TaskRouter(BaseRouter):
    model = Task
    create_schema = TaskCreate
    update_schema = TaskUpdate
    schema_out = TaskResponse
    lookup_schema = TaskResponse  # Required to activate the /lookup endpoint
    service = TaskService
    prefix = "/tasks"
    tags = ["Tasks"]
    
    # Example: Exclude the DELETE endpoint
    exclude = {RouteKey.DELETE}

router_instance = TaskRouter()

Tip: When the DELETE endpoint is enabled, it automatically supports the ?force=true query parameter to execute permanent physical hard-deletions when using soft-delete models.

Wire the Plugin

Open tasks/plugin.py. The Plugin class manages the lifecycle of your domain. Ensure it includes your router:

# tasks/plugin.py
from zcore import Plugin
from fastapi import FastAPI
from .routers import TaskRouter

class TaskPlugin(Plugin):
    name = "tasks"
    version = "0.1.0"
    dependencies = [] # Can list other plugin names if needed

    def setup(self, app: FastAPI) -> None:
        from .routers import router_instance
        app.include_router(router_instance.router)

Register with the Kernel

Finally, open your root main.py and register the plugin with the Kernel. The Kernel uses topological sorting to ensure plugins start in the correct order.

# main.py (Add this before kernel.setup(app))
from tasks.plugin import TaskPlugin

# ... existing setup code ...
kernel.add_plugin(TaskPlugin())
kernel.setup(app)

Check it out: Run zc run and navigate to http://127.0.0.1:8000/docs. You will see 7 fully functional, secure endpoints (POST, GET, GET_ALL, SEARCH, LOOKUP, UPDATE, PATCH) generated automatically!

We have a working API. But how do we secure it and make the Zchema masking actually work? Let's add authentication.

On this page