Skip to main content

Blog Route


This page is part of the documentation for release V1.0. This documentation is outdated and V1.0 is no longer maintained. See index for the latest information.

The blog route interfaces with the blog database model and dynamically renders blog articles.


The blog route is defined in /routes/blog.js and operates on the /api/blog API path.

Bulk Retrieve Posts: (GET) /api/blog/

To index posts in the /blog and /admin pages, it was necessary to implement a route which returned an index of the most recent posts. Unlike the GET: /api/blog/:id route, which returns an HTML render of the blog, the GET: /api/blog/ route returns the underlying JSON objects.

Although authentication is optional, non-authenticated users can only retrieve posts that are marked status: published.

Request Parameters

JWT (cookie)(Optional) Auth cookie

Sample Response

Content-Type: application/json

Content-Type: application/json
"title":"post has been modified",
"content":"my modified article",
"subtitle":"my draft",

Empty response:

Content-Type: application/json

Content-Type: application/json


curl -XGET ''

Fetch Article Page: (GET) api/blog/:id

This route fetches articles by the specified URL ID parameter and returns them as rendered HTML. An error article is rendered if the ID is invalid or non-existent.

Articles whose status is not 'published' (e.g 'draft') are only visible to authenticated users. They do not render on the /blog page, but may be accessed by authenticated users if their ID is known. Generally, authenticated users may access these posts by clicking on the 'preview' button alongside their table entries in the admin dashboard.

Request Parameters

:id (path)ID of the requested blog post.
JWT (cookie)(Optional) Auth cookie for accessing restricted posts.



Create Article: (POST) /api/blog/

This route consumes a JSON body and produces a new blog article. This route requires authentication.

Request Parameters

Request body: Content-Type: application/json

JWT (cookie)(Required) Auth cookie
title (body)(Required) Article title
status (body)(Required) Article status
previewImg (body)(Optional) Article banner image URL
content (body)(Optional) Article body text
subtitle (body)(Optional) Article subtitle
author (body)(Optional) JSON string array of author names


The server responds with the newly created JSON blog object.

Content-Type: application/json

"title":"new post",
"content":"my new article",

If the request body is missing the required title or status keys, the following error will be returned:

{ "error": "Missing field(s) in request body" }

If the client attempts to manually assign an ID, by including an _id or id key in the request body, the following error will be returned:

{ "error": "Setting custom blog ID is prohibited" }


curl -XPOST --cookie "jwt=<AUTH COOKIE>" -H "Content-type: application/json" -d '{
"title":"my blog title,
}' ''

Modify Article: (PUT) api/blog/:id

Modifies the existing article specified by the path parameter ':id'. This is an authenticated route.

Request Parameters

Request body: Content-Type: application/json

:id (path)ID of the requested blog post.
JWT (cookie)(Required) Auth cookie
title (body)(Optional) Article title
status (body)(Optional) Article status
previewImg (body)(Optional) Article banner image URL
content (body)(Optional) Article body text
subtitle (body)(Optional) Article subtitle
author (body)(Optional) JSON string array of author names


The server responds with the modified JSON blog object

Content-Type: application/json

"title":"modified post",
"content":"my modified article",

If the _id and date keys are omitted, then the above response example may also be used as a sample request body. Note that all schema keys are optional: only the key/values that the client wishes to modify need to be specified.

If the ':id' parameter is invalid, the following JSON object is returned:

{ "error": "Invalid ID" }

If the ID is valid but not longer exists, the following JSON object is returned:

{ "error": "ID does not exist" }

To maintain database collection consistency, and prevent unexpected collision/behavior from renamed article IDs, modifying the ID parameter of an article is prohibited. If a client attempts to send a JSON request body with an id or _id key, the following error will be returned:

{ "error": "Setting custom blog ID is prohibited" }

If a client lacks sufficient authentication, a status 401-Forbidden error will be returned.


curl -XPUT --cookie "jwt=<AUTH COOKIE>" -H "Content-type: application/json" -d '{
"content":"my modified article",

Delete Article: (DELETE) api/blog/:id

Deletes the blog post specified by the path parameter ':id'. This is an authenticated route.

Request Parameters

:id (path)ID of the requested blog post.
JWT (cookie)(Required) Auth cookie


The server responds with the JSON object of the deleted article.

Content-Type: application/json

Content-Type: application/json
"title":"test post",
"content":"my article",

If the ':id' parameter is invalid, the following JSON object is returned:

{ "error": "Invalid ID" }

If the ID is valid but not longer exists, the following JSON object is returned:

{ "error": "Blog not found" }

If a client lacks sufficient authentication, a status 401-Forbidden error will be returned.


curl -XDELETE --cookie "jwt=<AUTH COOKIE>" '<BLOG ID HERE>'