Flask is a web framework for Python. It facilitates the creation of web apps (dynamic web pages).
Run Flask
Flask comes with its own server for debugging purposes, which can be started with:
flask run
Folder Structure
app.py # main code
requirements.txt # required libraries
static/ # files that never change
templates/ # dynamic files
“Hello, name” — Example App
<!DOCTYPE html>
<html lang="en">
<meta name = "viewport" content="initial-scale=1, width=device-width">
hello, {{ name_placeholder }} <!-- Jinja template -->
from flask import Flask, render_template, request
app = Flask(__name__)
# When user visits / (the website root), load index.html.
# If the key name exists, store the value in a variable. If not, store world.
def index():
name = request.args.get("name", "world")
return render_template("index.html", name_placeholder=name)
Sample App
<!DOCTYPE html>
<html lang="en">
<meta name = "viewport" content="initial-scale=1, width=device-width">
<input autocomplete="off" autofocus name="name" placeholder="Name" type="text">
<button type="submit">Greet</button>
from flask import Flask, render_template, request
app = Flask(__name__)
# When user visits / (the website root), load index.html.
# If the key name exists, store the value in a variable. If not, store world.
def index():
name = request.args.get("name", "world")
return render_template("index.html", name_placeholder=name)
Custom Route
Both the form and /greet works.
<!DOCTYPE html>
<html lang="en">
<meta name = "viewport" content="initial-scale=1, width=device-width">
<form action="/greet" method="get">
<input autocomplete="off" autofocus name="name" placeholder="Name" type="text">
<button type="submit">Greet</button>
<!DOCTYPE html>
<html lang="en">
<meta name = "viewport" content="initial-scale=1, width=device-width">
from flask import Flask, render_template, request
app = Flask(__name__)
# When user visits / (the website root), load index.html.
# If the key name exists, store the value in a variable. If not, store world.
def index():
name = request.args.get("name", "world")
return render_template("index.html", name_placeholder=name)
def greet():
return render_template("greet.html", name=request.args.get("name", "world"))
Avoid HTML Repetition
Use a layout instead of copying blocks.
{% extends "layout.html" %}
{% block body %}
<form action="/greet" method="get">
<input autocomplete="off" autofocus name="name" placeholder="Name" type="text">
<button type="submit">Greet</button>
{% endblock %}
{% extends "layout.html" %}
{% block body %}
hello, {{name}}
{% endblock %}
<!DOCTYPE html>
<html lang="en">
<meta name = "viewport" content="initial-scale=1, width=device-width">
{% block body %}{% endblock %}
from flask import Flask, render_template, request
app = Flask(__name__)
# When user visits / (the website root), load index.html.
# If the key name exists, store the value in a variable. If not, store world.
def index():
name = request.args.get("name", "world")
return render_template("index.html", name_placeholder=name)
def greet():
return render_template("greet.html", name=request.args.get("name", "world"))
Hide Sensitive Requests from the URL
Use post instead of get.
{% extends "layout.html" %}
{% block body %}
<form action="/greet" method="post">
<input autocomplete="off" autofocus name="name" placeholder="Name" type="text">
<button type="submit">Greet</button>
{% endblock %}
{% extends "layout.html" %}
{% block body %}
hello, {{name}}
{% endblock %}
<!DOCTYPE html>
<html lang="en">
<meta name = "viewport" content="initial-scale=1, width=device-width">
{% block body %}{% endblock %}
The name doesn’t appear in the URL anymore.
from flask import Flask, render_template, request
app = Flask(__name__)
# When user visits / (the website root), load index.html.
# If the key name exists, store the value in a variable. If not, store world.
def index():
name = request.args.get("name", "world")
return render_template("index.html", name_placeholder=name)
@app.route("/greet", methods=["POST"])
def greet():
return render_template("greet.html", name=request.form.get("name", "world"))
Combine Routes to save Resources
GET is always the default.
POST is used to send information to the server.
{% extends "layout.html" %}
{% block body %}
<form action="/" method="post">
<input autocomplete="off" autofocus name="name" placeholder="Name" type="text">
<button type="submit">Greet</button>
{% endblock %}
{% extends "layout.html" %}
{% block body %}
hello, {{name}}
{% endblock %}
<!DOCTYPE html>
<html lang="en">
<meta name = "viewport" content="initial-scale=1, width=device-width">
{% block body %}{% endblock %}
from flask import Flask, render_template, request
app = Flask(__name__)
# When user visits / (the website root), load index.html.
# If the key name exists, store the value in a variable. If not, store world.
@app.route("/", methods=["GET, POST"])
def index():
if request.method == "GET":
return render_template("index.html")
elif request.method == "POST":
return render_template("greet.html", name=request.form.get("name", "world"))
Cookies - Session
Used to store data and to recognize the user.
- Server → Client
Set-Cookie session=value
- Client → Server
Cookie session
from flask import session
# Configure app
app = Flask(__name__)
# Configure session
app.config["SESSION_PERMANENT"] = False
app.config["SESSION_TYPE"] = "filesystem"
# Redirect to login if no cookie exists
def index():
if not session.get("name"):
return redirect("/login")
return render_template("index.html")
# session is a dictionary
session["cart"] = []
books = db.execute("SELECT * FROM books WHERE id IN (?)", session["cart"])