Step 8 - Web Layer & Plugin System
Scaffold 8 secure endpoints instantly and register your domain with the application Kernel.
Instead of writing 8 redundant route functions for every model, ZCore's BaseRouter generates them securely out-of-the-box (including dynamic search and field-projected lookups). We then register everything cleanly via the Plugin system.
Configure the Router
Open tasks/routers.py and link your schemas, model, and service:
# tasks/routers.py
from zcore import BaseRouter, RouteKey
from .models import Task
from .schemas import TaskCreate, TaskUpdate, TaskResponse
from .services import TaskService
class TaskRouter(BaseRouter):
model = Task
create_schema = TaskCreate
update_schema = TaskUpdate
schema_out = TaskResponse
lookup_schema = TaskResponse # Required to activate the /lookup endpoint
service = TaskService
prefix = "/tasks"
tags = ["Tasks"]
# Example: Exclude the DELETE endpoint
exclude = {RouteKey.DELETE}
router_instance = TaskRouter()Tip: When the DELETE endpoint is enabled, it automatically supports the ?force=true query parameter to execute permanent physical hard-deletions when using soft-delete models.
Wire the Plugin
Open tasks/plugin.py. The Plugin class manages the lifecycle of your domain. Ensure it includes your router:
# tasks/plugin.py
from zcore import Plugin
from fastapi import FastAPI
from .routers import TaskRouter
class TaskPlugin(Plugin):
name = "tasks"
version = "0.1.0"
dependencies = [] # Can list other plugin names if needed
def setup(self, app: FastAPI) -> None:
from .routers import router_instance
app.include_router(router_instance.router)Register with the Kernel
Finally, open your root main.py and register the plugin with the Kernel. The Kernel uses topological sorting to ensure plugins start in the correct order.
# main.py (Add this before kernel.setup(app))
from tasks.plugin import TaskPlugin
# ... existing setup code ...
kernel.add_plugin(TaskPlugin())
kernel.setup(app)Check it out: Run zc run and navigate to http://127.0.0.1:8000/docs. You will see 7 fully functional, secure endpoints (POST, GET, GET_ALL, SEARCH, LOOKUP, UPDATE, PATCH) generated automatically!
We have a working API. But how do we secure it and make the Zchema masking actually work? Let's add authentication.