# Django UnChained

<img src="images/django.jpg">

# Making Queries

Once you’ve created your data models, Django automatically gives you a database-abstraction API that lets you create, retrieve, update and delete objects.


In [None]:
from django.db import models

class Blog(models.Model):
    name = models.CharField(max_length=100)
    tagline = models.TextField()

    def __str__(self):              # __unicode__ on Python 2
        return self.name

class Author(models.Model):
    name = models.CharField(max_length=200)
    email = models.EmailField()

    def __str__(self):              # __unicode__ on Python 2
        return self.name

class Entry(models.Model):
    blog = models.ForeignKey(Blog)
    headline = models.CharField(max_length=255)
    body_text = models.TextField()
    pub_date = models.DateField()
    mod_date = models.DateField()
    authors = models.ManyToManyField(Author)
    n_comments = models.IntegerField()
    n_pingbacks = models.IntegerField()
    rating = models.IntegerField()

    def __str__(self):              # __unicode__ on Python 2
        return self.headline

## Creating objects:

To represent database-table data in Python objects, Django uses an intuitive system:
A model class represents a database table, and an instance of that class represents a particular record in the database table.
To create an object, instantiate it using keyword arguments to the model class, then call save() to save it to the database.
Assuming models live in a file mysite/blog/models.py, here’s an example:

In [None]:
>>> from blog.models import Blog
>>> b = Blog(name='Beatles Blog', tagline='All the latest Beatles news.')
>>> b.save()

This performs an INSERT SQL statement behind the scenes.
Django doesn’t hit the database until you explicitly call save().
The save() method has no return value.

## Saving changes to objects:

To save changes to an object that’s already in the database, use save().
Given a Blog instance b5 that has already been saved to the database,
this example changes its name and updates its record in the database:

In [None]:
>>> b5.name = 'New name'
>>> b5.save()

This performs an UPDATE SQL statement behind the scenes.
Django doesn’t hit the database until you explicitly call save().

## Updating a ForeignKey:
Updating a ForeignKey field works exactly the same way as saving a normal field –
simply assign an object of the right type to the field in question.
This example updates the blog attribute of an Entry instance entry,
assuming appropriate instances of Entry and Blog are already saved to the database (so we can retrieve them below):

In [None]:
>>> from blog.models import Entry
>>> entry = Entry.objects.get(pk=1)
>>> cheese_blog = Blog.objects.get(name="Cheddar Talk")
>>> entry.blog = cheese_blog
>>> entry.save()

## Updating a ManyToManyField:
Updating a ManyToManyField works a little differently –
use the add() method on the field to add a record to the relation.
This example adds the Author instance joe to the entry object:

In [None]:
>>> from blog.models import Author
>>> joe = Author.objects.create(name="Joe")
>>> entry.authors.add(joe)

To add multiple records to a ManyToManyField in one go,
include multiple arguments in the call to add(), like this:

In [None]:
>>> john = Author.objects.create(name="John")
>>> paul = Author.objects.create(name="Paul")
>>> george = Author.objects.create(name="George")
>>> ringo = Author.objects.create(name="Ringo")
>>> entry.authors.add(john, paul, george, ringo)

## Retrieving objects:

To retrieve objects from your database, construct a QuerySet via a Manager on your model class.
    A QuerySet represents a collection of objects from your database.
    It can have zero, one or many filters.
    Filters narrow down the query results based on the given parameters.
    In SQL terms, a QuerySet equates to a SELECT statement,
    and a filter is a limiting clause such as WHERE or LIMIT.
    
  You get a QuerySet by using your model’s Manager.
    Each model has at least one Manager, and it’s called objects by default.
    Access it directly via the model class, like so:

In [None]:
>>> Blog.objects
<django.db.models.manager.Manager object at ...>
>>> b = Blog(name='Foo', tagline='Bar')
>>> b.objects
    Traceback:
        ...
    AttributeError: "Manager isn't accessible via Blog instances."

The Manager is the main source of QuerySets for a model.
        For example, Blog.objects.all() returns a QuerySet that contains all Blog objects in the database.
        
## Retrieving all objects:

 The simplest way to retrieve objects from a table is to get all of them.
    To do this, use the all() method on a Manager:
    
 The all() method returns a QuerySet of all the objects in the database.

In [None]:
>>> all_entries = Entry.objects.all()

## Retrieving specific objects with filters:
The QuerySet returned by all() describes all objects in the database table.
Usually, though, you’ll need to select only a subset of the complete set of objects.

To create such a subset, you refine the initial QuerySet,
adding filter conditions. The two most common ways to refine a QuerySet are:

    filter(**kwargs)
        Returns a new QuerySet containing objects that match the given lookup parameters.
        
    exclude(**kwargs)
        Returns a new QuerySet containing objects that do not match the given lookup parameters.
        
The lookup parameters (**kwargs in the above function definitions) should be in the format described in Field lookups below.
    For example, to get a QuerySet of blog entries from the year 2006, use filter() like so:

In [None]:
Entry.objects.filter(pub_date__year=2006)

With the default manager class, it is the same as:

In [None]:
Entry.objects.all().filter(pub_date__year=2006)

## Chaining filters:
The result of refining a QuerySet is itself a QuerySet,
so it’s possible to chain refinements together. For example:

In [None]:
>>> Entry.objects.filter(
...     headline__startswith='What'
... ).exclude(
...     pub_date__gte=datetime.date.today()
... ).filter(
...     pub_date__gte=datetime(2005, 1, 30)
... )

This takes the initial QuerySet of all entries in the database,
    adds a filter, then an exclusion, then another filter.
    The final result is a QuerySet containing all entries with a headline that starts with “What”,
    that were published between January 30, 2005, and the current day.

## Filtered QuerySets are unique:

Each time you refine a QuerySet, you get a brand-new QuerySet that is in no way bound to the previous QuerySet.
Each refinement creates a separate and distinct QuerySet that can be stored, used and reused.

Example:

In [None]:
>>> q1 = Entry.objects.filter(headline__startswith="What")
>>> q2 = q1.exclude(pub_date__gte=datetime.date.today())
>>> q3 = q1.filter(pub_date__gte=datetime.date.today())

These three QuerySets are separate.

The first is a base QuerySet containing all entries that contain a headline starting with “What”.

The second is a subset of the first, with an additional criteria that excludes records whose pub_date is today or in the future.


The third is a subset of the first, with an additional criteria that selects only the records whose pub_date is today or in the future.

The initial QuerySet (q1) is unaffected by the refinement process.

## Retrieving a single object with get():

filter() will always give you a QuerySet,
even if only a single object matches the query -
in this case, it will be a QuerySet containing a single element.

If you know there is only one object that matches your query,
you can use the get() method on a Manager which returns the object directly:

In [None]:
>>> one_entry = Entry.objects.get(pk=1)

You can use any query expression with get(), just like with filter().

Note that there is a difference between using get(), and using filter() with a slice of [0].

If there are no results that match the query, get() will raise a DoesNotExist exception.
This exception is an attribute of the model class that the query is being performed on
 
 so in the code above, if there is no Entry object with a primary key of 1,
Django will raise Entry.DoesNotExist.

Similarly, Django will complain if more than one item matches the get() query.
In this case, it will raise MultipleObjectsReturned, which again is an attribute of the model class itself.

## Limiting QuerySets:
Use a subset of Python’s array-slicing syntax to limit your QuerySet to a certain number of results.
This is the equivalent of SQL’s LIMIT and OFFSET clauses.

For example, this returns the first 5 objects (LIMIT 5):

In [None]:
>>> Entry.objects.all()[:5]

This returns the sixth through tenth objects (OFFSET 5 LIMIT 5):

In [None]:
>>> Entry.objects.all()[5:10]

Negative indexing (i.e. Entry.objects.all()[-1]) is not supported.

Generally, slicing a QuerySet returns a new QuerySet –
it doesn’t evaluate the query.
An exception is if you use the “step” parameter of Python slice syntax.
For example, this would actually execute the query
in order to return a list of every second object of the first 10:

In [None]:
>>> Entry.objects.all()[:10:2]

To retrieve a single object rather than a list (e.g. SELECT foo FROM bar LIMIT 1),
use a simple index instead of a slice. For example,
this returns the first Entry in the database, after ordering entries alphabetically by headline:

In [None]:
>>> Entry.objects.order_by('headline')[0]

This is roughly equivalent to:

In [None]:
>>> Entry.objects.order_by('headline')[0:1].get()

## Field lookups:

Field lookups are how you specify the meat of an SQL WHERE clause.
They’re specified as keyword arguments to the QuerySet methods filter(), exclude() and get().

Basic lookups keyword arguments take the form field__lookuptype=value. (That’s a double-underscore). For example:

In [None]:
>>> Entry.objects.filter(pub_date__lte='2006-01-01')

translates (roughly) into the following SQL:

In [None]:
SELECT * FROM blog_entry WHERE pub_date <= '2006-01-01';

The field specified in a lookup has to be the name of a model field.
    There’s one exception though, in case of a ForeignKey you can specify the field name suffixed with _id.
    In this case, the value parameter is expected to contain the raw value of the foreign model’s primary key. For example:

        

In [None]:
>>> Entry.objects.filter(blog_id=4)

If you pass an invalid keyword argument, a lookup function will raise TypeError.

## exact:
    An “exact” match. For example:

In [None]:
>>> Entry.objects.get(headline__exact="Cat bites dog")

Would generate SQL along these lines:

In [None]:
SELECT ... WHERE headline = 'Cat bites dog';

If you don’t provide a lookup type – that is, if your keyword argument doesn’t contain a double underscore –
the lookup type is assumed to be exact.

For example, the following two statements are equivalent:

In [None]:
>>> Blog.objects.get(id__exact=14)  # Explicit form
>>> Blog.objects.get(id=14)         # __exact is implied

This is for convenience, because exact lookups are the common case.

## iexact:
A case-insensitive match. So, the query:



In [None]:
>>> Blog.objects.get(name__iexact="beatles blog")

Would match a Blog titled "Beatles Blog", "beatles blog", or even "BeAtlES blOG".

## contains:
Case-sensitive containment test. For example:
        

In [None]:
Entry.objects.get(headline__contains='Lennon')

 Roughly translates to this SQL:
       

In [None]:
 SELECT ... WHERE headline LIKE '%Lennon%';

Note this will match the headline 'Today Lennon honored' but not 'today lennon honored'.
There’s also a case-insensitive version, icontains.

## startswith, endswith:
Starts-with and ends-with search, respectively.
There are also case-insensitive versions called istartswith and iendswith.

## Lookups that span relationships:
Django offers a powerful and intuitive way to “follow” relationships in lookups,
taking care of the SQL JOINs for you automatically, behind the scenes.
To span a relationship, just use the field name of related fields across models,
separated by double underscores, until you get to the field you want.

This example retrieves all Entry objects with a Blog whose name is 'Beatles Blog':

  

In [None]:
 >>> Entry.objects.filter(blog__name='Beatles Blog')

This spanning can be as deep as you’d like.

It works backwards, too. To refer to a “reverse” relationship, just use the lowercase name of the model.

This example retrieves all Blog objects which have at least one Entry whose headline contains 'Lennon':



In [None]:
 >>> Blog.objects.filter(entry__headline__contains='Lennon')

## The pk lookup shortcut:

For convenience, Django provides a pk lookup shortcut, which stands for “primary key”.

In the example Blog model, the primary key is the id field, so these three statements are equivalent:

 

In [None]:
>>> Blog.objects.get(id__exact=14) # Explicit form
>>> Blog.objects.get(id=14) # __exact is implied
>>> Blog.objects.get(pk=14) # pk implies id__exact


The use of pk isn’t limited to __exact queries –
any query term can be combined with pk to perform a query on the primary key of a model:

 

In [None]:
# Get blogs entries with id 1, 4 and 7
>>> Blog.objects.filter(pk__in=[1,4,7])

# Get all blog entries with id > 14
>>> Blog.objects.filter(pk__gt=14)

pk lookups also work across joins. For example, these three statements are equivalent:

In [None]:
>>> Entry.objects.filter(blog__id__exact=3) # Explicit form
>>> Entry.objects.filter(blog__id=3)        # __exact is implied
>>> Entry.objects.filter(blog__pk=3)        # __pk implies __id__exact

## Escaping percent signs and underscores in LIKE statements:

The field lookups that equate to LIKE SQL statements (iexact, contains, icontains, startswith, istartswith, endswith and iendswith)
will automatically escape the two special characters used in LIKE statements –
the percent sign and the underscore. (In a LIKE statement,
the percent sign signifies a multiple-character wildcard and
the underscore signifies a single-character wildcard.)

This means things should work intuitively,
so the abstraction doesn’t leak. For example, to retrieve all the entries that contain a percent sign,
just use the percent sign as any other character:


In [None]:
>>> Entry.objects.filter(headline__contains='%')

Django takes care of the quoting for you; the resulting SQL will look something like this:

In [None]:
SELECT ... WHERE headline LIKE '%\%%';

Same goes for underscores. Both percentage signs and underscores are handled for you transparently.

## Deleting objects:

The delete method, conveniently, is named delete().
This method immediately deletes the object and returns the number of objects deleted and
a dictionary with the number of deletions per object type. Example:


In [None]:
>>> e.delete()
    (1, {'weblog.Entry': 1})

You can also delete objects in bulk.
Every QuerySet has a delete() method, which deletes all members of that QuerySet.

For example, this deletes all Entry objects with a pub_date year of 2005:



In [None]:
 >>> Entry.objects.filter(pub_date__year=2005).delete()
        (5, {'webapp.Entry': 5})

Keep in mind that this will, whenever possible, be executed purely in SQL,
and so the delete() methods of individual object instances will not necessarily be called during the process.
If you’ve provided a custom delete() method on a model class and want to ensure that it is called,
you will need to “manually” delete instances of that model
(e.g., by iterating over a QuerySet and calling delete() on each object individually) rather than using the bulk delete() method of a QuerySet.

When Django deletes an object, by default it emulates the behavior of the SQL constraint ON DELETE CASCADE –
in other words, any objects which had foreign keys pointing at the object to be deleted will be deleted along with it. For example:


In [None]:
b = Blog.objects.get(pk=1)
# This will delete the Blog and all of its Entry objects.
b.delete()

Note that delete() is the only QuerySet method that is not exposed on a Manager itself.
This is a safety mechanism to prevent you from accidentally requesting Entry.objects.delete(),
and deleting all the entries.
If you do want to delete all the objects, then you have to explicitly request a complete query set:

In [None]:
Entry.objects.all().delete()

## Performing raw SQL queries¶

When the model query APIs don’t go far enough, you can fall back to writing raw SQL.
Django gives you two ways of performing raw SQL queries:
you can use Manager.raw() to perform raw queries and return model instances,
or you can avoid the model layer entirely and execute custom SQL directly.

## Warning
You should be very careful whenever you write raw SQL.
Every time you use it, you should properly escape any parameters that the user can control by using params
in order to protect against SQL injection attacks.



The raw() manager method can be used to perform raw SQL queries that return model instances:


In [None]:
Manager.raw(raw_query, params=None, translations=None)

This method takes a raw SQL query, executes it, and returns a django.db.models.query.RawQuerySet instance.
This RawQuerySet instance can be iterated over just like a normal QuerySet to provide object instances.

This is best illustrated with an example. Suppose you have the following model:

In [None]:
class Person(models.Model):
    first_name = models.CharField(...)
    last_name = models.CharField(...)
    birth_date = models.DateField(...)

You could then execute custom SQL like so:

In [None]:
>>> for p in Person.objects.raw('SELECT * FROM myapp_person'):
...     print(p)
John Smith
Jane Jones