您可以将骨干集合/模型指向您想要的任何 url,并在您的骨干“子类”中解析响应。
型号.url:
http://documentcloud.github.com/backbone/docs/backbone.html#section-43
Collection.parse:
http://documentcloud.github.com/backbone/docs/backbone.html#section-69
您可以设置一次性请求处理程序,该处理程序可以返回一些 json 供骨干网解析/摄取,无需活塞或美味派。但是,是的,这是使用 django 进行综合 REST 的两个很好的解决方案。
这里有一些很好的提示:http://joshbohde.com/blog/backbonejs-and-django 将骨干与美味派一起使用。
使用 sweetpie,您可以通过自定义授权/身份验证来限制对 api 的访问。
http://django-tastypie.readthedocs.org/en/latest/authentication_authorization.html
您可以创建一个授权方案,确保将对象列表过滤为仅是用户“拥有”的对象,如下所示:
class PerUserAuthorization(Authorization):
def apply_limits(self, request, object_list):
if request and hasattr(request, 'user'):
if request.user.is_authenticated():
object_list = object_list.filter(user=request.user)
return object_list
return object_list.none()
或者/另外,您可以通过覆盖ModelResource.apply_authorization_limits 方法来创建仅返回用户对象的资源,并通过覆盖obj_create 方法自动将用户与创建的对象关联,例如:
class PerUserModelResource(ModelResource):
def obj_create(self, bundle, request=None, **kwargs):
return ModelResource.obj_create(self, bundle, request, user=request.user)
def apply_authorization_limits(self, request, object_list):
return object_list.filter(user=request.user)
然后,您可以从 PerUserModelResource 继承和/或使 PerUserAuthorization 成为资源的授权。
class ImageGroupResource(PerUserModelResource):
study = fields.ForeignKey(StudyResource, "study")
uploads = fields.ToManyField('cm.api.UploadResource', 'uploads', null=True)
class Meta:
queryset = ImageGroup.objects.all()
list_allowed_methods = ['get', 'post']
detail_allowed_methods = ['get', 'post', 'put', 'delete']
resource_name = 'cm/imagegroup'
authorization = PerUserAuthorization()
filtering = {
'name': ALL,
'created_dt': ['exact', 'range', 'gt', 'gte', 'lt', 'lte'],
}
Backbone 和 django-tastypie 有很好的文档记录。花点时间构建一个简单的概念证明并通读几遍文档。它们像豌豆和胡萝卜一样在一起。