Python programs operate on objects with explicit input, ownership and failure contracts.
Learning roadmap
This section contains 23 written lessons or quiz banks. Programs are verified on CPython 3.14.6. Standard-library lessons target 3.11+ syntax; lessons using data, web, machine-learning or testing packages state their tested dependencies separately. Framework programs use local test clients, not a deployed service. Read the stated limits before adapting a fixture into an application.
Flask request contracts
Read the contract, run its program and inspect the failure case.
- Flask routing: application factories, converters and test clients
- Flask JSON API: reject unknown fields, booleans and oversized bodies
Django routing and validation
Read the contract, run its program and inspect the failure case.
- Django URL routing: local dispatch and parameter boundaries
- Django forms: ASCII wire fields and cleaned domain values
Stored state and request boundaries
Read the contract, run its program and inspect the failure case.
- Django models: database constraints survive an unchecked save
- Django select_related: measure the foreign-key N plus one query pattern
- Django atomic transactions: rollback the batch and defer callbacks
- Django migrations: generate and apply an owned application schema
- Django templates: escape untrusted text at HTML output
- Django CSRF checks: require the token without confusing it with identity
- Django keyset pagination: stable ordering and a bounded next page
Persistent local requests and REST field/owner checks
Read the contract, run its program and inspect the failure case.
- Flask SQLite application: own the request connection and verify a clean reopen
- Django REST Framework serializers: reject coercion outside the wire contract
- Django REST Framework object permissions: check the retrieved record, not only login
List visibility, creation ownership and public failure shapes
Read the contract, run its program and inspect the failure case.
- Django REST Framework list visibility: filter the principal’s rows before paging
- Django REST Framework creation ownership: assign the owner from the principal
- Flask error responses: preserve status without exposing internal exception text
Reception and database-enforced identity boundaries
Read the contract, run its program and inspect the failure case.
- Python Flask multipart uploads: bound the body, part count and accepted file
- Python Django database constraints: enforce receipt identity per owner
Target policies and conditional representations
Read the contract, run its program and inspect the failure case.
- Python urlsplit: parsing a URL does not authorize a request target
- Python Flask ETag responses: preserve cache validators across conditional reads
Indexed list boundaries
Read the contract, run its program and inspect the failure case.
Conditional writes
Read the contract, run its program and inspect the failure case.
Continue learning
Move between tutorial, collections, advanced material and practice using the subject tabs. The sidebar changes with each section; related examples keep one canonical lesson URL.
