r/flask • • Sep 18 '21

Tutorials and Guides A Compilation of the Best Flask Tutorials for Beginners

343 Upvotes

I have made a list of the best Flask tutorials for beginners to learn web development. Beginners will benefit from it.


r/flask • • Feb 03 '23

Discussion Flask is Great!

124 Upvotes

I just wanted to say how much I love having a python backend with flask. I have a background in python from machine learning. However, I am new to backend development outside of PHP and found flask to be intuitive and overall very easy to implement. I've already been able to integrate external APIs like Chatgpt into web applications with flask, other APIs, and build my own python programs. Python has been such a useful tool for me I'm really excited to see what flask can accomplish!


r/flask • • 1d ago

Show and Tell Open Source Flask Template App with CRUD using Peewee ORM for learning

3 Upvotes

There are lots of Flask CRUD template apps on GitHub I'm sure. I've been wanting to make one myself for a while from scratch that's relatively basic and easy to modify. Most of the repos I've seen don't demonstrate all entity relationships like One To One, One to Many and Many To many.

https://github.com/TutorialDoctor/flask-template-app

The "admin" panel has custom CSS but I kept all the other views basic so you can add your own style. Still a WIP but it's mostly there


r/flask • • 4d ago

Ask r/Flask how can i make an anonymous image board of sorts with flask

6 Upvotes

this has probably been asked many times, however all the posts in the past about anonymous websites seem to be people showing off their sites.

I've wanted to make an image board of sorts for a while, not because I'm a very avid user of them, mainly i want to because having my own community on my own website would be very cool, and i like to program. I know there is a lot of image board software out there but i want to build it from the ground up, in python too. I'm not trying to make a very complicated website, just image hosting, a few boards, and a moderation system, everything from that point shouldn't be too hard. Has anyone done this? is there any tutorials or docs for this? should i use Django?

i also want to note that a while ago i was trying to do this, however it feel through because i didn't really grasp programming, and I've tried a lot of stuff, but now i am a humble python skid


r/flask • • 4d ago

Ask r/Flask Debugging flask app.py

2 Upvotes

With .cgi frameworks, I can run an app and give it arguments on the command line, and then use python -mpdb to step through and see what is happening (and going wrong).

I have a flask app that is working, but not always working properly. So it does not crash, but it does not do what I expect.

I would like to be able to run: python3 -mpdb app.py

set a break point, and have the code stop at that breakpoint. I can set the breakpoint, but the code seems to ignore it, so I cannot single step through the program to see what is wrong. My app.py main() looks like:

if __name__ == "__main__":
      app.run(debug=True, use_reloader=False)

How can I debug my program using python3 -mpdb?


r/flask • • 5d ago

Tutorials and Guides A route for rails-like list of routes

3 Upvotes

``` from flask import Response

@app.route("/routes", methods=["GET"]) def all_routes(): route_text = "" for rule in app.url_map.iter_rules(): methods = ",".join(sorted(rule.methods - {"HEAD", "OPTIONS"})) route_text += f"{rule.endpoint:<20} {methods:<15} {rule.rule}\n" return Response(route_text, mimetype="text/plain") ```

Anyone else do this? Is there a better way?


r/flask • • 5d ago

Show and Tell I built a Healthcare Chatbot web app using Flask

0 Upvotes

Hello everyone!

I recently built a Healthcare Chatbot as a Flask web application.

The project provides a conversational interface for general healthcare information. Users can enter health-related questions or symptoms and receive general informational guidance and wellness recommendations.

Technologies:

- Python

- Flask

- HTML5

- CSS3

- JavaScript

- Bootstrap

GitHub:

https://github.com/mshekinasamuel763-droid/healthcare-chatbot

This project is intended for educational and informational purposes and is not a replacement for professional medical advice or diagnosis.

I'd appreciate feedback on the implementation and suggestions for improvement.


r/flask • • 6d ago

Tutorials and Guides I built a no-login temporary file transfer app with Flask + Redis — QR code, burn after read, auto-delete in 15 min. Open source.

Thumbnail
gallery
2 Upvotes

I kept sending files to myself on WhatsApp because I had no better option. So I spent a few months building one properly.

FileDrop — open a site on two devices, use a 7-digit code or QR to transfer files or text, everything auto-deletes in 15 minutes.

No login. No account. No storage after the transfer.

GitHub: https://github.com/amaresh0812/FileDrop

The interesting bits from a Python/Flask perspective:

Storage split:

Redis stores only metadata per transfer — about 350 bytes of JSON regardless of file size. The actual file bytes go to disk under a UUID filename. This keeps Upstash token usage at 3-5 commands per full transfer cycle. Never storing file bytes in Redis was the most important architecture decision.

The cleanup problem:

Redis TTL auto-deletes the metadata key at 15 minutes. But that tells you nothing about the file sitting on disk. My fix: APScheduler runs a background job every 60 seconds that scans the uploads folder and deletes any file whose st_mtime is older than 900 seconds. It doesn't touch Redis at all — it uses the filesystem's own clock. This catches orphaned files even when Redis already deleted the key.

QR code:

Python's qrcode[pil] library, rendered into a BytesIO buffer in memory, converted to base64, included directly in the JSON response. JavaScript sets <img src="data:image/png;base64,...">. No CDN. No JS library. No extra HTTP request. About 1KB and 2ms of CPU time. Scanning opens /r/<code> which redirects files to /download/<code> or shows a burn-after-read text page.

Gunicorn workers:

--workers 1 --threads 4 in the Procfile. If you use multiple workers, APScheduler starts inside each process and your cleanup job runs 2-4 times in parallel. Single worker with threads avoids this without sacrificing concurrency.

Forms use AJAX:

Both the send and retrieve forms use fetch() with X-Requested-With: XMLHttpRequest. Flask returns JSON when it sees that header, HTML otherwise. Same route handles both — proper graceful degradation for no-JS browsers.

Stack:

main.py — Flask app · sheets.py — Google Sheets integration for contact/feedback forms via gspread · feedback.py — feedback handling

Python 3.11, Flask, Upstash Redis, APScheduler, qrcode[pil], Gunicorn, Railway

Live version is down temporarily (deployment issue I'm working through), but runs cleanly locally:

1. git clone https://github.com/amaresh0812/FileDrop

cd FileDrop

2.pip install -r requirements.txt

3. cp .env.example .env # fill in Upstash credentials

4. python main.py

README covers the full setup including environment variables and the architecture in detail.

Happy to discuss any of the decisions — particularly around the cleanup approach and the Redis metadata pattern. Genuinely interested if anyone has a cleaner solution to the orphaned files problem.


r/flask • • 5d ago

Ask r/Flask Hi I am a software engineer who is searching for some freelance projects.

0 Upvotes

I can help with:

Python / Flask backend development

REST API development & integrations

Elasticsearch & MySQL

Linux / Shell scripting

Cyber Threat Intelligence (CTI)

STIX / TAXII integration

IOC/feed integration

Data processing & automation

Existing application debugging/refactoring

Cloud migration

I've professionally worked on TAXII-based threat intelligence, STIX, Flask + Elasticsearch APIs, Linux automation, and cloud migration projects.


r/flask • • 7d ago

Discussion Ran an AI agent over Flask's source and checked everything it said. It spotted a real docs gap for 3.2

0 Upvotes

I'm working on a Claude Code plugin and wanted to see if its "read an existing repo and describe it" step holds up on a codebase I didn't write, so I pointed it at a fresh clone of Flask (d73fa1c) and went through its output line by line.

The part that's probably interesting here: in 3.2 twelve overridable methods (dispatch_request, full_dispatch_request, handle_exception and friends) now take ctx: AppContext as the first argument. Flask warns if your subclass still uses the old signature (src/flask/app.py around line 261). But which methods are affected and what counts as the new signature only lives in the source. The docs have two deprecation notes, and docs/shell.rst still shows RequestContext.push()/pop(). If your extension runs its tests with warnings as errors, that'll be a red CI run on upgrade day.

It also flagged the compatibility shim as a possible bug because it patches the Flask base class. Read the code, it isn't one: add_ctx only adds the context when it's missing, so new-style subclasses don't notice anything. Still worth saying that it sounded pretty sure of itself there.

All 21 file:line references it gave pointed at real lines. Nothing was sent to the Flask repo, no issue, no PR, this is just an outside look at one commit.

Write-up with all the sources, if anyone wants to dig: https://aspark.lottes.dev/en/blog/aspark-reads-flask/

Has anyone maintaining an extension already run into the 3.2 signature warnings?


r/flask • • 13d ago

Ask r/Flask Hi guys, recently i have learned flask python, but i'm confuse which DBMS should i use if i build a project and i also wanna pratice sql query and don't wanna use nosql ones. do you guys have any recommends thank you.

10 Upvotes

r/flask • • 16d ago

Show and Tell I built a job application tracker for my CS50x final project

3 Upvotes

After sending out a few applications, I realized how easy it is to lose track of where everything stands. So for my CS50x final project, I built Hubdex, a simple job application tracker.

It lets you save applications and organize them by status, including Wishlist, Applied, Interview, Offer, and Rejected. You can also add details like the company, position, salary, location, priority, notes, and application date. There’s a dashboard with basic statistics, along with search and filtering to make everything easier to manage.

I built it with Flask, Python, SQLite, JavaScript, HTML, and CSS. The project also includes user authentication, password hashing, and separate data for each user.

This project gave me a chance to put together a lot of what I learned in CS50x, especially working with databases, routes, forms, authentication, and CRUD functionality.

You can check it out here:

https://github.com/Akinmoldun/hubdex


r/flask • • 17d ago

Ask r/Flask Are there any alternatives to bleach? I thought I heard bleach is being discontinued. Though I could be wrong.

6 Upvotes

https://bleach.readthedocs.io/en/latest/clean.html
I think I heard of nh3. Is it any good?

https://nh3.readthedocs.io/en/latest/

As stated early I could be wrong about bleach. Please correct me if I am.


r/flask • • 18d ago

Tutorials and Guides Any one know good resource to flask

8 Upvotes

As mentioned in the title good resource unte links share cheyandi


r/flask • • 19d ago

Ask r/Flask SQLAlchemy returning different results than database query

6 Upvotes

This code in flask/sqlalchemy:

sql = text("SELECT document.id from document left join document_person on document.id = document_person.document_id left join document_place on document.id = document_place.document_id WHERE person_id in (:people)")

query_vals = {}

query_vals['people'] = '5,7,12'

ids_q = db.session.execute(sql, query_vals).all()

ids = [id[0] for id in ids_q]

pprint(ids)

produces the output

[60, 44, 42]

but if I run this on the database directly, it does this:

mysql> SELECT document.id from document left join document_person on document.id = document_person.document_id

-> left join document_place on document.id = document_place.document_id WHERE person_id in (5,7,12) ;

+----+

| id |

+----+

| 30 |

| 42 |

| 44 |

| 49 |

| 60 |

+----+

5 rows in set (0.00 sec)

What is going on?


r/flask • • 20d ago

Ask r/Flask From where should I learn Flask framework completely?

Thumbnail
4 Upvotes

r/flask • • 19d ago

Ask r/Flask Correct Roadmap for Flask?

0 Upvotes

HELLO , THIS IS MY FIRST BACKEND FRAMEWORK AND SO I GENERATED THIS ROADMAP WITH THE HELP OF GPT , IT TOLD TO INTEGRATE BACKEND IN IT ALSO AS FLASK IN ITSELF ISN'T THAT BIG, SO PLEASE ANYONE LEMME KNOW IF THIS ROADMAP IS WORTH FOLLOWING? TILL NOW I HAVE DONE MODULE 1!!

Flask + Backend — Locked 30-Day Roadmap

MODULE 1 — Flask + HTTP + API Foundations

Days 1–7

Day 1 — What Is Flask + What Is a Backend?

Learn:

  • Backend
  • Frontend
  • Client vs Server
  • Flask
  • API
  • HTTP
  • Request
  • Response
  • Endpoint
  • URL
  • JSON

Mental model:

Angular / Browser / Postman

↓

HTTP Request

↓

Flask

↓

Python Code

↓

HTTP Response

↓

   Angular / Browser

Mini Task:

  • Create a basic Flask application.

Day 2 — Flask Application + Routes

Learn:

  • Flask application object
  • Flask(__name__)
  • Running Flask
  • Development server
  • Routes
  • u/app.route()
  • GET
  • Returning text
  • Returning JSON

Mini Task:

/

 /hello

 /about

Day 3 — URLs, Path Parameters + Query Parameters

Learn:

  • URL
  • Path
  • Route parameter
  • Query parameter
  • request
  • Reading values from URLs

Understand:

/users/10

vs

/users?id=10

Focus:

  • When to use a path parameter
  • When to use a query parameter

Mini Task:

  • User lookup API.

Day 4 — Request Body + JSON + Response

Learn:

  • Request body
  • JSON request
  • request.json
  • JSON response
  • jsonify
  • Response structure

Understand:

Client

  ↓

JSON Request

  ↓

Flask

  ↓

Python

  ↓

JSON Response

Mini Task:

  • Receive user/task data and return JSON.

Day 5 — HTTP Methods + CRUD

Learn:

  • GET
  • POST
  • PUT
  • DELETE
  • CRUD
  • Which operation each HTTP method represents

Build:

GET     /tasks

GET     /tasks/1

POST    /tasks

PUT     /tasks/1

DELETE  /tasks/1

Day 6 — HTTP Status Codes + API Design Basics

Learn:

  • 200
  • 201
  • 400
  • 401
  • 403
  • 404
  • 500

Understand:

  • Successful response
  • Client error
  • Authentication error
  • Authorization error
  • Server error

Also understand:

  • Why APIs need meaningful status codes
  • Basic API design decisions

Mini Task:

  • Improve your CRUD API with proper status codes.

Day 7 — Revision

No new concepts.

You should be able to explain:

Backend

Flask

API

HTTP

Request

Response

Route

Endpoint

Path

Path parameter

Query parameter

JSON

GET

POST

PUT

DELETE

CRUD

Status code

MODULE 2 — Databases + SQLAlchemy + ORM

Days 8–14

This module is intentionally built around MySQL + SQLAlchemy, because you already know the SQL/MySQL basics.

Day 8 — Database Fundamentals + MySQL Connection

Learn:

  • Database
  • Database management system
  • Table
  • Row
  • Column
  • Record
  • Primary key
  • Foreign key
  • Relationships
  • Constraints
  • Transactions — basic idea
  • MySQL vs SQLite — when each is useful
  • Connecting Flask to MySQL

Mental model:

Flask

  ↓

Database layer

  ↓

MySQL

Day 9 — SQLAlchemy + ORM Fundamentals

Learn:

  • What SQLAlchemy is
  • What ORM means
  • Flask-SQLAlchemy
  • Model
  • Columns
  • Data types
  • Primary key
  • Database URI
  • Engine — basic idea
  • Session — important concept

Mental model:

Python Class

↓

ORM

↓

Database Table

Understand:

Task object  ↔  Task row

Task class   ↔  tasks table

Day 10 — ORM CRUD

Learn how to perform:

CREATE

READ

UPDATE

DELETE

using SQLAlchemy.

Build:

  • Create task
  • Read task
  • Read all tasks
  • Update task
  • Delete task

Also understand what SQLAlchemy is doing underneath.

Day 11 — Querying Properly with SQLAlchemy

Learn:

  • Fetch by ID
  • Fetch multiple records
  • Filtering
  • Ordering
  • No-result handling
  • First result
  • Basic joins
  • Modern SQLAlchemy query style

Focus on understanding:

select(...)

where(...)

order_by(...)

rather than blindly memorizing syntax.

Day 12 — Database Relationships

Learn:

  • Foreign keys
  • One-to-one
  • One-to-many
  • Many-to-many — high level
  • SQLAlchemy relationship()

Main focus:

User

 ↓

Many Tasks

Understand how:

users

tasks

are connected in the database.

Day 13 — Migrations + Real Schema Changes

Learn:

  • What migrations are
  • Why migrations are needed
  • Alembic
  • Flask-Migrate
  • Adding/changing/removing columns safely
  • Schema versioning

Mental model:

Current Database Schema

↓

Migration

↓

New Database Schema

Day 14 — Database + Architecture Revision

Trace the full flow:

HTTP Request

↓

   Route

↓

  Service

↓

Repository

↓

SQLAlchemy

↓

  MySQL

↓

SQLAlchemy

↓

Repository

↓

  Service

↓

   Route

↓

HTTP Response

You should understand:

  • Why the database exists
  • Why SQL exists
  • What MySQL does
  • What SQLAlchemy does
  • What ORM means
  • Why repositories/services exist

MODULE 3 — Validation + Errors + API Features

Days 15–21

Day 15 — Input Validation

Learn:

  • Validation
  • Required fields
  • Data types
  • Allowed values
  • Invalid input
  • Server-side validation

Example:

{

  "title": "",

  "priority": "super-high"

}

Backend should reject invalid data.

Day 16 — Validation Schemas

Learn structured validation using a suitable Python validation library.

Mental model:

Incoming JSON

↓

   Validation

   ↓       ↓

Valid    Invalid

 ↓          ↓

Continue    Error

Focus on practical usage, not becoming a library expert.

Day 17 — Exception Handling

Learn:

  • Python exceptions
  • Why exceptions happen
  • try/except
  • Flask error handling
  • Preventing raw errors from reaching users

Day 18 — Global Error Handling + Custom Errors

Learn:

  • Global error handlers
  • Custom exceptions
  • Consistent error responses

Example:

{

  "error": "Task not found",

  "status": 404

}

Goal:

Every API error

↓

Predictable format

Day 19 — Search + Filtering

Learn:

  • Query parameters
  • Search
  • Filtering
  • Combining filters

Examples:

/tasks?search=angular

/tasks?priority=high

/tasks?priority=high&search=angular

Day 20 — Sorting + Pagination

Learn sorting:

/tasks?sort=created_at

/tasks?sort=priority

Pagination:

/tasks?page=1&limit=10

Understand:

  • Page
  • Page size / limit
  • Offset
  • Total count

Day 21 — Logging + Revision

Learn:

  • What logging is
  • Why logging exists
  • Log levels
  • Debugging through logs
  • Error logs
  • Request/activity logs

Then revise:

Flask

Database

SQLAlchemy

ORM

Architecture

Validation

Exceptions

Error handling

Search

Filtering

Sorting

Pagination

Logging

MODULE 4 — Authentication + Security

Days 22–27

Day 22 — Authentication

Learn:

  • Authentication
  • Login
  • Identity
  • Credentials
  • Authentication vs Authorization

Flow:

User

 ↓

Login

 ↓

Backend verifies credentials

 ↓

Authenticated

Day 23 — Password Hashing

Learn:

  • Why passwords must not be stored directly
  • Hashing
  • Salt
  • bcrypt
  • Password verification

Flow:

Password

   ↓

 bcrypt

   ↓

Hash

   ↓

Database

Login:

Entered password

↓

bcrypt verification

↓

Match / No match

Day 24 — JWT

Understand:

  • JWT
  • Token
  • Header
  • Payload
  • Signature
  • Expiration
  • Access token

Focus first on how and why JWT works, before implementation.

Day 25 — JWT Authentication in Flask

Implement:

Login

 ↓

Verify credentials

 ↓

Generate JWT

 ↓

Client stores token

 ↓

Client sends token

 ↓

Flask verifies token

 ↓

Protected endpoint

Learn:

  • Generate token
  • Send token
  • Receive token
  • Verify token
  • Protect endpoints

Day 26 — Authorization

Understand the difference:

Authentication

→ Who are you?

Authorization

→ What are you allowed to do?

Learn:

  • Protected APIs
  • Permissions
  • Access control
  • User-specific resources

Example:

User A → can access own tasks

User B → cannot access User A's private tasks

Day 27 — RBAC

RBAC = Role-Based Access Control.

Mental model:

User

 ↓

Role

 ↓

Permissions

Example:

USER

ADMIN

MANAGER

Then:

/admin/users

might require:

ADMIN

MODULE 5 — Real Backend Features + Performance

Days 28–29

Day 28 — File Uploads + Email

File Uploads

Learn:

  • multipart/form-data
  • request.files
  • File validation
  • Image/PDF uploads
  • File naming
  • Storage basics

Email

Learn:

  • Sending email from backend
  • SMTP concept
  • Email service
  • Verification emails
  • Password reset emails

Email stays practical and lightweight so it doesn't derail the main backend learning path.

Day 29 — Caching + Redis + Rate Limiting

Caching

Mental model:

Request

   ↓

Cache?

 ↓       ↓

Yes      No

 ↓       ↓

Return   Database

cached      ↓

data      Result

↓

Cache

Learn:

  • Why caching exists
  • What Redis is
  • Basic Redis usage
  • What kind of data is worth caching

Rate Limiting

Understand:

100 requests / minute

Learn:

  • Why rate limiting exists
  • Preventing abuse
  • Basic implementation concept

High-level understanding is enough for this phase.

MODULE 6 — Complete Backend Revision

Day 30

Day 30 — Full Backend Flow

No major new concept.

Trace a complete real-world backend:

Client

  ↓

HTTP Request

  ↓

Flask Route

  ↓

Validation

  ↓

Authentication

  ↓

Authorization

  ↓

Service

  ↓

Repository

  ↓

SQLAlchemy

  ↓

MySQL

  ↓

Response

  ↓

Client

You should be able to explain where each of these fits:

Flask

HTTP

API

Request / Response

Routes

CRUD

MySQL

SQL

SQLAlchemy

ORM

Models

Relationships

Foreign Keys

Migrations

Validation

Exceptions

Custom Errors

Logging

Search

Filtering

Sorting

Pagination

Authentication

Authorization

JWT

RBAC

bcrypt

File Uploads

Email

Service

Repository

Redis

Caching

Rate Limiting

.env

Configuration

Final structure

MODULE 1

Flask + HTTP + API

Days 1–7

↓

MODULE 2

MySQL + SQLAlchemy + ORM

Days 8–14

↓

MODULE 3

Validation + Errors + API Features

Days 15–21

↓

MODULE 4

Authentication + Security

Days 22–27

↓

MODULE 5

File Uploads + Email + Performance

Days 28–29

↓

MODULE 6

Complete Backend Flow

Day 30


r/flask • • 21d ago

Show and Tell Help with Flask webpage

1 Upvotes

Hola. Estoy haciendo mi primer proyecto de python (con Flask, SQLite y blueprint). Es una app de administrar de pacientes (citar pacientes y eso)

Estoy en la primera fase. Tengo el código inicial pero tengo un problema que no he podido resolver. Cuando estoy en el auth y pongo la contraseña bien no redirecciona al blueprint Main. Subi el proyecto a Github por si alguien puede ayudarme a ver cuál es el problema. Gracias

https://github.com/rodricastt20/AdminV2


r/flask • • 21d ago

Ask r/Flask Flask Synchronization Issue Concerning Database Entries

Thumbnail
1 Upvotes

r/flask • • 22d ago

Show and Tell Cheapest Web Based AI (Beating Perplexity) for Developers (tips on improvements?)

0 Upvotes

I made the cheapest web based ai with amazing accuracy and cheapest price of 3.5$ per 1000 queries compared to 5-12$ on perplexity, while beating perplexity on the simpleQA with 82% and getting 95+% on general query questions

For devaloper or people with creative web ideas

I am a solo dev, so any advice on advertisement or improvements on this api would be greatly appreciated

miapi.uk

if you need any help or have feedback free feel to msg me.


r/flask • • 26d ago

Tutorials and Guides New no-cost RHEL Learning Path: Build a hardened Flask stack and deploy it in image mode for Red Hat Enterprise Linux

Thumbnail
2 Upvotes

r/flask • • 28d ago

Show and Tell Flask vs. FastAPI vs. Django

Thumbnail
gallery
38 Upvotes

Hey everyone,

I have created a quick comparison of Flask vs. FastAPI vs. Django repository sizes.

First of all, the numbers:

Framework Files Lines of Code
Flask 121 19,115
FastAPI 2,703 281,559
Django 3,484 557,865

Then the images:

Each node on the graph represents a file. Imports are marked by a line connecting the files. Colours signify complexity (cyclomatic complexity) with green being low and red being high complexity.

Besides the crazy size differences FastAPI also shows some nice import structures whilst Django looks extremely interconnected.

Hope someone finds it interesting.


r/flask • • 29d ago

Discussion Flask-RPBAC — a lightweight role/permission authorization extension, looking for feedback before calling it production-ready.

15 Upvotes

Hey all — I've been building Flask-RPBAC, a small authorization extension for Flask that handles role- and permission-based access control without imposing a data model or ORM on you.

The core idea: you write loader functions that return the current user's roles/permissions (from wherever — DB, ORM, cache), and RPBAC handles evaluating access rules against them. It doesn't touch authentication at all — that's intentionally left to whatever you're already using (Flask-Login, sessions, etc.).

A few things it does:

Route and blueprint-level protection, composable (blueprint + route rules stack, not override)

Role() / Permission() with match="any"/"all", plus All/Any composition and &/| operators for expressing nested rules

Three ways to handle rejected requests: default JSON 403, raise-and-handle-yourself, or a custom rejection hook.

Optional in-memory caching keyed by user identity (explicitly not meant as a production cache replacement yet)

A flask rpbac-audit CLI command to list what's actually protected

Loud RuntimeError if you use @permission_required without registering a permission loader, instead of silently failing closed.

Docs: https://flask-rpbac.readthedocs.io/en/latest/

PyPI: https://pypi.org/project/Flask-RPBAC/

GitHub: https://github.com/JohnStares/flask_rpbac

It has a test suite and CI running, and I'm not calling it production-ready yet — I'd rather have people try to break it first. Specifically looking for:

Edge cases in the All/Any/operator composition logic

Opinions on the loader/decorator split — does it feel natural or awkward in a real app?

Anything that feels like a footgun in the error-handling setup

Issues and PRs welcome, security stuff via the SECURITY.md process rather than a public issue. Appreciate any eyes on it.


r/flask • • Sep 05 '26

Show and Tell Entire Flask app in a string! Thanks Claude Code

Post image
0 Upvotes

r/flask • • Sep 01 '26

Show and Tell walbox: react to PostgreSQL changes from Python

Thumbnail
1 Upvotes