पाठ 26 / 26

A Python Web Backend Checklist

Review before shipping.

Questions to ask

Is the framework choice justified by the product? Are inputs validated (Pydantic models or forms) and outputs filtered (response models or explicit serialisation)? Are migrations reviewed, small and backward compatible? Are queries free of N+1 problems, with query-count tests? Are multi-step writes atomic, with constraints in the database? Are passwords hashed with the framework's tools? Do tests use test clients, overrides or isolated databases? Does check --deploy pass, with DEBUG off and secrets from the environment? Is the app served by a production server behind TLS?

The checklist

Use it in reviews.

[ ] input validated (Pydantic / forms); output filtered (response_model / serializers)
[ ] async only with async libraries; no blocking calls in async def
[ ] migrations small, reviewed (sqlmigrate), backward compatible
[ ] select_related / prefetch_related; assertNumQueries on key views
[ ] transaction.atomic for multi-step writes; DB constraints in place
[ ] passwords via framework hashers (PBKDF2 / Argon2)
[ ] tests with TestClient / Django test client; dependency overrides
[ ] check --deploy clean; DEBUG=False; secrets from environment
[ ] gunicorn/uvicorn workers behind TLS proxy; static via CDN/WhiteNoise
[ ] background jobs for slow work; caching where measured

Automate what you can

Linters (ruff), type checkers (mypy), tests and check --deploy in CI catch most checklist items automatically.

त्वरित जाँच: Which item belongs on a Python web backend checklist?

  • No blocking calls inside async def endpoints
  • DEBUG=True in production
  • Plain-text password storage
  • Skipping migrations review
Answer

No blocking calls inside async def endpoints — Correct, efficient, secure.