Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Building API For The REST of Us
Search
Terry
September 26, 2016
Programming
8
730
Building API For The REST of Us
Slides in RubyConf China 2016 Chengdu
Terry
September 26, 2016
Tweet
Share
More Decks by Terry
See All by Terry
RubyConf China Welcome Slides
poshboytl
1
87
Rails Girls Chengdu 2014
poshboytl
2
320
Refactoring Re-education
poshboytl
5
980
How we test our projects
poshboytl
29
1.9k
Other Decks in Programming
See All in Programming
TerraformとStrands AgentsでAmazon Bedrock AgentCoreのSSO認証付きエージェントを量産しよう!
neruneruo
4
2.6k
DevFest Android in Korea 2025 - 개발자 커뮤니티를 통해 얻는 가치
wisemuji
0
190
[AI Engineering Summit Tokyo 2025] LLMは計画業務のゲームチェンジャーか? 最適化業務における活⽤の可能性と限界
terryu16
2
410
MDN Web Docs に日本語翻訳でコントリビュート
ohmori_yusuke
0
590
The Art of Re-Architecture - Droidcon India 2025
siddroid
0
170
AI Agent Dojo #4: watsonx Orchestrate ADK体験
oniak3ibm
PRO
0
130
Kotlin Multiplatform Meetup - Compose Multiplatform 외부 의존성 아키텍처 설계부터 운영까지
wisemuji
0
180
組織で育むオブザーバビリティ
ryota_hnk
0
140
それ、本当に安全? ファイルアップロードで見落としがちなセキュリティリスクと対策
penpeen
7
2.3k
ZJIT: The Ruby 4 JIT Compiler / Ruby Release 30th Anniversary Party
k0kubun
1
380
カスタマーサクセス業務を変革したヘルススコアの実現と学び
_hummer0724
0
150
QAフローを最適化し、品質水準を満たしながらリリースまでの期間を最短化する #RSGT2026
shibayu36
2
3.8k
Featured
See All Featured
DevOps and Value Stream Thinking: Enabling flow, efficiency and business value
helenjbeal
1
85
Effective software design: The role of men in debugging patriarchy in IT @ Voxxed Days AMS
baasie
0
200
For a Future-Friendly Web
brad_frost
181
10k
What does AI have to do with Human Rights?
axbom
PRO
0
1.9k
Lessons Learnt from Crawling 1000+ Websites
charlesmeaden
PRO
1
1k
Groundhog Day: Seeking Process in Gaming for Health
codingconduct
0
76
The Cult of Friendly URLs
andyhume
79
6.8k
Automating Front-end Workflow
addyosmani
1371
200k
How Fast Is Fast Enough? [PerfNow 2025]
tammyeverts
3
430
Accessibility Awareness
sabderemane
0
39
Reality Check: Gamification 10 Years Later
codingconduct
0
2k
Designing for Timeless Needs
cassininazir
0
120
Transcript
Building API For The REST of Us — Terry Tai
About Me
Host of Teahour.FM
Creator of Railscasts-China
I’m working for My Color Way 619'4 䨅⃚
Co-founder of fengche.co
Co-team of Peatio Project
Let’s Building API
Conditions • Based on Ruby on Rails • Not a
pure API service, web is still the first-class citizen • Client builder is resource owner or ourselves
1. Stack Choice
VS
Performance
Flexibility
Level of abstraction
Community
I like Grape a little bit more!
DSL Higer Abstraction
Isolation
Michael Bleigh Grape is created by my coworker in Intridea.
He is also the creator of oauth2, omniauth, hashie, multi_json …
2. Routes & Version
In Rails
In Grape
Rails with version in header
Rails with version in header
Rails with version in header
Grape with version in header
3. Request & Params
Params Encoding application/x-www-form-urlencoded multipart/form-data application/json
Sending Params
Rails server side
Grape server side
Grape params real world example
4.Authentication
Basic Auth
None
With HTTPS?
None
Token Based Auth
Token Based Auth • Simple • A little bit more
secure than Basic Auth • Muti-tokens for authorisation
Digest Based Auth
What we use?
Open Source Exchange
Ancun
Zhiren
Signature based Authentication?
Amazon use the similar strategy
None
One request includes: • access_key • tonce • payload •
signature
Signature
payload
None
Everything Work Well until..
payload
WTF is that?
Why not use JSON?
One request includes: • access_key • tonce • payload •
signature
Strategy • Put business related data in payload as JSON
• Put authentication related data out of payload
Simpler than Amazon
5.Resource Presenter
If you use Grape
If you use Rails
The most quick way
Extract a Presenter layer
Extract a Presenter layer
Treat it as View!
Jbuilder
–DHH “Every time you use a loop in your view,
but you don’t use partial, you might be wrong.”
Jbuilder
RABL
None
It’s not View
Active Model Serializers
View A new layer VS
Two Stories ̽Terry ݏݏᦖඳԪ̾
Story 1
After user signup send him/her a welcome email
Where to put this line?
User model callback
after_create ?
after_commit on create
Send in Callback
Send in Controller
Which one is the BEST way?
I don’t know
The second solution is from Rails Guides
Story 2
Jan Xie Ex-Intridea programmer Ex-Peatio co-member Founder of Cryptape ruby-pinyin
author ruby-ethereum author My darling….
His last project in Ruby?
Python, Go
Sinatra Node
When A record created, B,C,D must be created at the
same time
A B C D
None
None
Communicating emotions
It’s become better but not BEST!
What’s the BEST way?
Jan’s solution — Service
My solution — PubSub
My solution — PubSub
My solution — PubSub
My solution — PubSub You can use Wisper gem to
do similar thing
Two hours PK…
We decide change Nothing
Maybe, there is no BEST way We need know why
people think different We need know compromise
Welcome to Chengdu ́౮᮷҅ Ӟଷԧ੪ӧమᐶጱउ૱̶͂
Spicy Food
Girls
Spicy Food
Girls
RubyConf China in Chengdu
We are hiring!
None
BTW҅I’m ́ፗካ͂
Enjoy your “one night in Chengdu”