HTTP QUERY¶
aiodrf provides explicit compatibility support for QUERY: an idempotent,
read-only request with selection criteria in its body. Support is scoped to
aiodrf views, routing, parsing and test clients; Django is not monkeypatched.
Application handler¶
from aiodrf import serializers
from aiodrf.response import Response
from aiodrf.views import APIView
class SearchInput(serializers.Serializer):
term = serializers.CharField(max_length=40)
class SearchView(APIView):
async def query(self, request):
criteria = SearchInput(data=await request.adata())
await criteria.ais_valid(raise_exception=True)
return Response({"term": criteria.validated_data["term"]})
curl -X QUERY http://127.0.0.1:8108/search/ \
-H 'Content-Type: application/json' -d '{"term":"Ada"}'
Validation errors and unsupported media types retain DRF handling. Keep the operation read-only: clients can retry it. Configure body-size limits, authentication, row visibility and throttling as for other API methods.
Permissions, CSRF and caching¶
Third-party code that hardcodes DRF's SAFE_METHODS may omit QUERY. Test the
actual permission and middleware stack. Session-authenticated requests may
require CSRF tokens under the underlying Django contract; the compatibility
layer does not disable CSRF globally.
Two QUERY requests to one URL can have different bodies. Ordinary URL-only
caches must not merge their results. aiodrf.cache.cache_page retains Django's
GET/HEAD caching policy and does not cache QUERY. A custom body-query cache must
include body identity and correct principal isolation, Vary, freshness and
invalidation. Validate ingress/proxy method acceptance and cache keying separately.
OpenAPI and generated clients¶
OpenAPI 3.0/3.1 Path Item objects do not define a query operation. Configure
aiodrf.contrib.spectacular.hooks.preprocess_exclude_query_method to exclude
QUERY from these schemas. It does not convert QUERY into another method.
Generated clients therefore do not expose it. See the
OpenAPI specification.
Offer an explicitly documented POST endpoint for schema-generated clients. It can delegate the search operation, but keeps POST's own CSRF/cache behavior. The policies example includes both methods, schema validation and Swagger UI.
Transition to Django APIs¶
In tests, send QUERY requests with the query() method of AsyncAPIClient and
AsyncAPIRequestFactory.
aiodrf adds QUERY only when Django does not dispatch it itself. Once Django supports the method, aiodrf will use Django's implementation, and its own compatibility code will be removed when the oldest supported Django version includes it.