Shared Django runtime foundations for Baltimore civic applications
Project description
baltimore-patapsco (Python)
Reusable Django runtime primitives for Baltimore civic applications.
INSTALLED_APPS += ["baltimore.patapsco"]
REST_FRAMEWORK = {
"EXCEPTION_HANDLER": "baltimore.patapsco.api.exception_handler",
}
urlpatterns = [path("", include("baltimore.patapsco.urls"))]
Place RequestContextMiddleware early in MIDDLEWARE — after
SecurityMiddleware (and WhiteNoise when present), before session, auth, and
anything that can short-circuit a response — so every later middleware, view,
and log line sees the bound request ID. The reference app shows the canonical
order:
MIDDLEWARE = [
"django.middleware.security.SecurityMiddleware",
"whitenoise.middleware.WhiteNoiseMiddleware",
"baltimore.patapsco.observability.RequestContextMiddleware",
# sessions, common, csrf, auth, messages, clickjacking...
]
Stable health and readiness views
Applications that mount or extend the operational views directly use the public facade:
from baltimore.patapsco.api import HealthView, ReadinessView
HealthView is process-only liveness. ReadinessView runs the established
database check and returns its public-safe 200 or 503 status document. Both use
no authentication classes and AllowAny, and both remain ordinary DRF
APIView classes with as_view().
An application may subclass either class, override get(), and call
super().get(request) before composing app-owned public-safe checks. The parent
response status, request ID, and database result remain the starting contract;
the application owns an explicit serializer and OpenAPI annotation for any
extended payload.
The previous baltimore.patapsco.api.views imports resolve to the same class
objects for compatibility. DiagnosticsView remains available only from that
module and through the packaged URL configuration; it is intentionally absent
from baltimore.patapsco.api.__all__ because its staff/public policy is a
separate operational surface. The settings-free package root exports neither
view class.
api_error_response() and the DRF exception handler force every 5xx response to
the public internal_error code, generic message, and no details. Application
callers cannot opt a server failure out of that safety boundary.
Use build_logging_config() for the shared JSON/pretty log shape. Modules are
incrementally adoptable; installing the package does not enable auth, email, or
Sentry by itself.
Sentry privacy defaults
Install the observability extra and call the shared initializer only when a DSN
is configured:
from baltimore.patapsco.observability import configure_sentry
configure_sentry(
environment="production",
release="my-app@1.2.3",
traces_sample_rate=0.1,
)
configure_sentry() is deny-by-default: it disables automatic PII, request-body
capture, and stack-frame local variables. Its event pipeline also removes request
cookies and query strings, strips query/fragment data from request URLs, and
recursively redacts Sentry's credential/session denylist plus common civic contact
and precise-location fields. Safe operational fields such as request IDs, routes,
and HTTP methods remain available.
Redaction is key-based. Applications must not attach sensitive values under misleading keys or place resident data in exception messages. Product-specific fields still require a privacy review before being added to Sentry context.
Configuration surface
Everything the library reads from the environment or Django settings:
| Name | Kind | Default | Meaning |
|---|---|---|---|
APP_ENV |
env var | local |
Environment label in diagnostics and Sentry events; overridden by PATAPSCO_ENVIRONMENT when set |
APP_RELEASE |
env var | — | Release identifier in diagnostics and Sentry events; overridden by PATAPSCO_RELEASE when set |
APP_LOG_FORMAT |
env var | json |
json or pretty output from build_logging_config() |
APP_LOG_LEVEL |
env var | INFO |
Root log level from build_logging_config() |
SENTRY_DSN |
env var | — | Enables configure_sentry(); absent means Sentry stays off |
PATAPSCO_SERVICE_NAME |
Django setting | project name | Service label in the diagnostics payload |
PATAPSCO_ENVIRONMENT |
Django setting | APP_ENV env var |
Overrides the diagnostics environment field via Django settings instead of the process environment (a real override_settings test seam) |
PATAPSCO_RELEASE |
Django setting | APP_RELEASE env var |
Overrides the diagnostics release field via Django settings instead of the process environment (a real override_settings test seam) |
PATAPSCO_DIAGNOSTICS_PUBLIC |
Django setting | False |
Security-relevant: flips /api/diagnostics from IsAdminUser to AllowAny. Leave False unless the deployment deliberately publishes runtime metadata |
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file baltimore_patapsco-0.4.0.tar.gz.
File metadata
- Download URL: baltimore_patapsco-0.4.0.tar.gz
- Upload date:
- Size: 79.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: uv/0.11.28 {"installer":{"name":"uv","version":"0.11.28","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
119dc8a3dbafab99ecb9294a3af3f7deb20e40e8f0558a68a5c1e9912969fe0f
|
|
| MD5 |
bec9edc4dd850046ef1dba70e44f9dfd
|
|
| BLAKE2b-256 |
9296333b30f9f5f7447cdf0416536bab20c6c14743e3f10896392b1b4fa1cbba
|
File details
Details for the file baltimore_patapsco-0.4.0-py3-none-any.whl.
File metadata
- Download URL: baltimore_patapsco-0.4.0-py3-none-any.whl
- Upload date:
- Size: 92.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: uv/0.11.28 {"installer":{"name":"uv","version":"0.11.28","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4fe16dc8a9ec002aa7586e86bb9053fe36e025e146e32a9c96c9fc82910a6b6a
|
|
| MD5 |
e5b32b5834ae5c01cb63dfba63703f0d
|
|
| BLAKE2b-256 |
df36f98a44cb4d047848244846a57fe540f1fcd07f79aeb5fc93b1ccd4182896
|