Summary
We are relying more on projects to check object permissions, add nested data based on project settings (even to single-object detail views), and increase performance of large requests (partitioning based on project). However each view currently retrieves the "current" project in a few different ways and we are requiring the project_id url param on more and more views.
One standard practice is to add a parent object to the URL structure. So instead of
/api/occurrences/?project_id=5
We use
/api/project/6/occurrences/
Related to #734 & #928
Another option is to continue to use the project_id parameter, but make it required for all endpoints. But it's not as elegant!
Summary
We are relying more on projects to check object permissions, add nested data based on project settings (even to single-object detail views), and increase performance of large requests (partitioning based on project). However each view currently retrieves the "current" project in a few different ways and we are requiring the
project_idurl param on more and more views.One standard practice is to add a parent object to the URL structure. So instead of
/api/occurrences/?project_id=5We use
/api/project/6/occurrences/Related to #734 & #928
Another option is to continue to use the
project_idparameter, but make it required for all endpoints. But it's not as elegant!