python
via PatrickJS/awesome-cursorrules
Python best practices for Flask and SQLite projects with modern tooling and patterns
What is python?
Comprehensive guide for structuring, styling, and securing Python applications built with Flask and SQLite. Covers project organization, code standards, type hints, database design, authentication, testing, and deployment considerations. Use this rule to maintain consistency across Flask-based web applications and ensure adherence to Python community standards.
- Enforces src-layout project structure with organized tests, config, and static files
- Applies Black formatting, isort import sorting, and PEP 8 naming conventions with 88-character line limits
- Requires type hints for all functions using typing module and custom type definitions
- Structures Flask apps with factory pattern, Blueprints, SQLAlchemy ORM, and Alembic migrations
- Implements authentication via Flask-Login, OAuth, bcrypt password hashing, and CSRF protection
- Guides REST API design with Flask-RESTful, request validation, proper HTTP status codes, and rate limiting
Applies to
File patterns this rule matches.
Rule definition (reference)
Source of truth, from the repository.
Python Best Practices
Project Structure
- Use src-layout with
src/your_package_name/ - Place tests in
tests/directory parallel tosrc/ - Keep configuration in
config/or as environment variables - Store requirements in
requirements.txtorpyproject.toml - Place static files in
static/directory - Use
templates/for Jinja2 templates
Code Style
- Follow Black code formatting
- Use isort for import sorting
- Follow PEP 8 naming conventions:
- snake_case for functions and variables
- PascalCase for classes
- UPPER_CASE for constants
- Maximum line length of 88 characters (Black default)
- Use absolute imports over relative imports
Type Hints
- Use type hints for all function parameters and returns
- Import types from
typingmodule - Use
Optional[Type]instead ofType | None - Use
TypeVarfor generic types - Define custom types in
types.py - Use
Protocolfor duck typing
Flask Structure
- Use Flask factory pattern
- Organize routes using Blueprints
- Use Flask-SQLAlchemy for database
- Implement proper error handlers
- Use Flask-Login for authentication
- Structure views with proper separation of concerns
Database
- Use SQLAlchemy ORM
- Implement database migrations with Alembic
- Use proper connection pooling
- Define models in separate modules
- Implement proper relationships
- Use proper indexing strategies
Authentication
- Use Flask-Login for session management
- Implement Google OAuth using Flask-OAuth
- Hash passwords with bcrypt
- Use proper session security
- Implement CSRF protection
- Use proper role-based access control
API Design
- Use Flask-RESTful for REST APIs
- Implement proper request validation
- Use proper HTTP status codes
- Handle errors consistently
- Use proper response formats
- Implement proper rate limiting
Testing
- Use pytest for testing
- Write tests for all routes
- Use pytest-cov for coverage
- Implement proper fixtures
- Use proper mocking with pytest-mock
- Test all error scenarios
Security
- Use HTTPS in production
- Implement proper CORS
- Sanitize all user inputs
- Use proper session configuration
- Implement proper logging
- Follow OWASP guidelines
Performance
- Use proper caching with Flask-Caching
- Implement database query optimization
- Use proper connection pooling
- Implement proper pagination
- Use background tasks for heavy operations
- Monitor application performance
Error Handling
- Create custom exception classes
- Use proper try-except blocks
- Implement proper logging
- Return proper error responses
- Handle edge cases properly
- Use proper error messages
Documentation
- Use Google-style docstrings
- Document all public APIs
- Keep README.md updated
- Use proper inline comments
- Generate API documentation
- Document environment setup
Development Workflow
- Use virtual environments (venv)
- Implement pre-commit hooks
- Use proper Git workflow
- Follow semantic versioning
- Use proper CI/CD practices
- Implement proper logging
Dependencies
- Pin dependency versions
- Use requirements.txt for production
- Separate dev dependencies
- Use proper package versions
- Regularly update dependencies
- Check for security vulnerabilities
Related rules
Expert Python and TypeScript coding with Django, React, Tailwind, and Inertia.js best practices.
Python 3.12 FastAPI development with Pydantic, SQLAlchemy, and authentication best practices.
Python development with containerization best practices and integration.
Python development best practices with typing, testing, and modern tooling standards.
Python development guidance with CLI and file system expertise
Django development best practices guide for scalable, maintainable web applications.
