Ruby on Rails Backend

  • API (REST, JSON)

  • Secured by basic auth

  • User mode ­ with 3 roles (admin, user, guest)

  • Access limitation to given part of API depend of User role

  • Admin has access to everything

  • User can read all, create all, but update and deleted only his records

  • Guest has only read access

  • Article and comment models in relation (1 to many)

cURL command examples:

  1. User API:

    curl -H "Content-Type: application/json" -X GET --user user@example.com:testtest http://localhost:3000/api/users/1
    curl -H "Content-Type: application/json" -X GET -d '{"page":"1"}' --user admin@example.com:testtest http://localhost:3000/api/users/
    curl -H "Content-Type: application/json" -X POST -d '{"user": {"email":"xyz@xyz.xyz", "name":"xyz", "password":"xyzxyz", "role":"user"}}' --user user@example.com:testtest http://localhost:3000/api/users
    curl -H "Content-Type: application/json" -X PUT -d '{"user": {"email":"xyz", "name":"xyz", "password":"xyz"}}' --user user@example.com:testtest http://localhost:3000/api/users/1
    curl -H "Content-Type: application/json" -X DELETE --user user@example.com:testtest http://localhost:3000/api/users/1
  2. Article API:

    curl -H "Content-Type: application/json" -X GET --user user@example.com:testtest http://localhost:3000/api/users/1/articles/1
    curl -H "Content-Type: application/json" -X GET -d '{"page":"1"}' --user admin@example.com:testtest http://localhost:3000/api/users/1/articles
    curl -H "Content-Type: application/json" -X POST -d '{"article": {"name":"xyz", "content":"xyzxyz"}}' --user user@example.com:testtest http://localhost:3000/api/users/1/articles
    curl -H "Content-Type: application/json" -X PUT -d '{"article": {"name":"xyz", "content":"xyzxyz"}}' --user user@example.com:testtest http://localhost:3000/api/users/1/articles/1
  3. Comment API:

    curl -H "Content-Type: application/json" -X GET --user user@example.com:testtest http://localhost:3000/api/users/1/articles/1/comments/1
    curl -H "Content-Type: application/json" -X GET -d '{"page":"1"}' --user admin@example.com:testtest http://localhost:3000/api/users/1/articles/1/comments
    curl -H "Content-Type: application/json" -X POST -d '{"comment": {"content":"xyzxyz"}}' --user user@example.com:testtest http://localhost:3000/api/users/1/articles/1/comments
    curl -H "Content-Type: application/json" -X PUT -d '{"comment": {"content":"xyzxyz"}}' --user user@example.com:testtest http://localhost:3000/api/users/1/articles/1/comments/1