What this prompt does
This prompt builds a Flask REST API for [resource_name] using Marshmallow for validation and serialization, aimed at [client_type] clients. It separates concerns into a CreateSchema for writes — with [required_fields] required and [optional_fields] optional with defaults — and a ReadSchema for responses, plus validators (Length, Range, OneOf, Regexp) on [validated_fields] and a @validates_schema method for [cross_field_validation].
The ReadSchema nests [nested_objects], marks [computed_fields] as dump-only, and conditionally includes [admin_only_fields] based on context for admin users. Route handlers use schema.load() for validated input (raising ValidationError with field-level messages), schema.dump() for single objects, and schema.dump(many=True) for collections, while a global handler for marshmallow.ValidationError returns [error_format] with per-field messages. It also adds a pagination schema with maximum limits returning [pagination_response], file upload validation for [allowed_file_types] up to [max_file_size], and a versioning strategy via [versioning_approach] that evolves schemas without breaking v1 clients. Keeping validation in the schema layer means malformed input is rejected before it reaches your handlers.
When to use it
- You're building a Flask API consumed by a React SPA or mobile app and want strict input validation
- You want write and read schemas separated so responses stay predictable as fields grow
- You need nested serialization of related objects in responses
- You want consistent, field-level error responses on validation failures
- You need pagination with enforced maximum page sizes
- You're versioning an API and must add fields without breaking existing clients
- You want validation to reject bad data before it ever reaches your route handlers
Example output
The AI returns Marshmallow schema classes (Create and Read), validator definitions for [validated_fields], route handlers calling load/dump, a global error handler producing [error_format], a pagination schema enforcing a max per_page, a file-upload handler validating type and size, and a versioning section showing how to add fields safely. Expect code grouped by the seven numbered concerns rather than one file, so you can adopt the schemas and error handling independently.
Pro tips
- Keep
[required_fields]and[optional_fields]disjoint and explicit so the CreateSchema validates exactly what you intend - Put genuinely cross-field rules (end after start, paid events need a refund policy) in
[cross_field_validation]via@validates_schema, not individual field validators - Use schema context to gate
[admin_only_fields]so non-admins never see sensitive computed values - Cap page size in the pagination schema; without a max, a client can request an enormous
per_page - Validate both type and
[max_file_size]on uploads — checking only the extension is easy to bypass - Mark
[computed_fields]as dump-only so clients can't try to write values your server derives - Use a
@validates_schemamethod for[cross_field_validation]since rules spanning two fields can't live on either field alone - When evolving the API under
[versioning_approach], add fields as optional so v1 clients keep working