Leanpub Header

Skip to main content

DMVCFramework - the official guide (2nd edition)

Build REST APIs, web apps and real-time services with the most popular framework for Delphi

DMVCFramework - the official guide (2nd edition)
This book is 90% completeLast updated on 2026-08-23

Six years after the first edition, the official guide to DelphiMVCFramework is back, rewritten for 3.5.0-silicon. Thirty chapters, more than 550 pages, and 46 Delphi projects that compile and run. You build one real API, the Municipal Library, and grow it from a wizard-generated project into a deployed server with authentication, OpenID Connect, WebSockets and HTTPS.

Minimum price

$45.00

$79.00

You pay

Author earns

$

Also available for 2 book credits with a Reader Membership

PDF
1 Previous Editionwith 598 Readers
New edition of DelphiMVCFramework
About

About

About the Book

DelphiMVCFramework is the most popular open source project for web applications in the Delphi world, and one of the fastest ways to put a Delphi codebase on the web. This is its official guide, written by the person who created and maintains it.

The book is built around one example rather than a tour of features. You start with the project the IDE wizard generates, and by the last chapter the same Municipal Library API authenticates users, signs them in through an external identity provider, streams over WebSockets, documents itself with OpenAPI and runs behind TLS. Every chapter adds one thing to a system you already understand.

What changed since the first edition. The first edition covered 3.2.1-carbon. This one targets 3.5.0-silicon, and the framework did not stand still: functional actions, the validation framework, WebSocket support, dependency injection, the repository pattern, HTMX and TemplatePro views, and in 3.5.0 itself a pluggable server architecture with built-in HTTPS and a streaming JSON serializer. Fifteen of the thirty chapters are new, and the rest were rewritten rather than patched. There is a full chapter on MVCActiveRecord in depth, one on OpenID Connect against a real Keycloak, and one on the new Minimal API.

Every example is a real project. Nothing here was written by inspection: all 46 example projects compile against 3.5.0-silicon and every endpoint printed in the book was run and its output captured. The code is on GitHub at github.com/danieleteti/dmvcframeworktheofficialguideexamples, one folder per chapter, Apache 2.0.

Who it is for. If you have never built a web service, the early chapters explain HTTP, REST and what a controller actually does; no web experience is assumed. If you already ship Delphi services, the second half is the reference you have been missing: engines, TLS, deployment on Windows and Linux, logging and metrics, the RESTful client, and a chapter of things the framework can do that almost nobody knows about.

About this pre-release. All thirty chapters are written, verified and included. The book targets 3.5.0-silicon while that version is still a release candidate, so a revised edition follows once 3.5.0 is frozen, and buying now gets you every future revision at no extra cost. The front matter says plainly what is finished and what is not.

Author

About the Author

DANIELE TETI

Daniele Teti is a software architect, trainer, books author and consultant with over 20 years of experience. Daniele is a well-known Delphi and programming expert in the developer community and is a regular speaker for italian and international conferences. Daniele is the author of the best-selling "Delphi Cookbook" books serie published by PacktPub. He's the main developer and drives the development of the most popular Delphi open source project on github: DelphiMVCFramework. Among DelphiMVCFramework Daniele is the lead developer for other well know OS projects like ColumbusEgg4Delphi, DelphiREDISClient, DelphiSTOMPClient and many others. He is also a huge fan of design patterns, machine learning and AI. Daniele is the CEO of bit Time Professionals, an Italian company specializing in high-level consultancy, training, development and machine learning systems.

Contents

Table of Contents

  • 0. Foreword and Introduction
    • 0.1 Foreword
    • 0.2 About the Second Edition
    • 0.3 What's New in the Second Edition
    • 0.4 Notes for Readers Upgrading
    • 0.5 How This Book Is Organized
    • 0.6 Conventions Used in This Book
  • 1. Getting Started with DelphiMVCFramework
    • 1.1 What Makes DMVCFramework Special
    • 1.2 Installing DMVCFramework 3.5.0-silicon
    • 1.3 Setting Up the Library Paths
    • 1.4 Creating Your First Project with the IDE Wizard
    • 1.5 Anatomy of the Generated Project
    • 1.6 The Entry Point, Step by Step
    • 1.7 The Indy Direct Backend and the Others
    • 1.8 Writing Your First Action
    • 1.9 Building and Running the Server
    • 1.10 Your First Requests
    • 1.11 Environment Configuration with DotEnv
  • 2. Controllers and Routing
    • 2.1 How a URL Becomes a Method Call
    • 2.2 Controllers and Actions
    • 2.3 Mapping Routes
    • 2.4 Typed Route Parameters
    • 2.5 Binding Inputs with MVCFrom* Attributes
    • 2.6 Shortcut Responses
    • 2.7 Accessing Request Headers
    • 2.8 The Per-Engine Route Table
  • 3. Functional Actions
    • 3.1 The Problem with Manual Render and Free
    • 3.2 Functional Actions
    • 3.3 Supported Return Types
    • 3.4 When You Still Need a Procedure
    • 3.5 Mixing Functional and Procedural
    • 3.6 Functional Actions with Dependency Injection
  • 4. Renders
    • 4.1 Serializing Objects, DataSets, and Streams
    • 4.2 CSV Output
    • 4.3 Nested Entities with MVCOwned
    • 4.4 Lists of Simple Types as Root
    • 4.5 Controlling Nulls and Naming
    • 4.6 The Streaming JSON Serializer
    • 4.7 Streaming the Response Body to the Socket
    • 4.8 Breaking Change: TGUID Serialization
    • 4.9 Breaking Change: Zero TDateTime Is No Longer null
  • 5. Validation
    • 5.1 The Cost of Trusting Input
    • 5.2 Your First Validated Entity
    • 5.3 The Validator Toolbox
    • 5.4 Cross-Field Rules
    • 5.5 Object-Level Validation
    • 5.6 Nested Objects and Collections
    • 5.7 Shaping the Error Response
  • 6. Municipal Library: The Database
    • 6.1 The Domain
    • 6.2 The Entity-Relationship Model
    • 6.3 Choosing the Database
    • 6.4 Creating the Schema
    • 6.5 Seeding Sample Data
    • 6.6 Setting Up to Follow Along
  • 7. Municipal Library: The APIs
    • 7.1 Resources, Not Procedures
    • 7.2 Verbs and Status Codes
    • 7.3 Idempotency
    • 7.4 Versioning the API
    • 7.5 One Consistent Error Shape
    • 7.6 The Endpoint Map
  • 8. Municipal Library: Creating APIs using Datasets
    • 8.1 Connecting to the Library
    • 8.2 Returning a Dataset
    • 8.3 CRUD over Datasets
    • 8.4 Working with TDataSetHelper
    • 8.5 Exporting as CSV
    • 8.6 Higher-Order Functions on Datasets
  • 9. Municipal Library: MVCActiveRecord Introduction
    • 9.1 Mapping an Entity to a Table
    • 9.2 Field Options
    • 9.3 Primary Keys with More Than One Column
    • 9.4 Optimistic Locking with foVersion
    • 9.5 Transactions with UseTransactionContext
    • 9.6 Refreshing an Entity
    • 9.7 Nullable Types
    • 9.8 Table Filtering and Partitioning
  • 10. Municipal Library: Complete APIs with MVCActiveRecord
    • 10.1 From Entities to a Finished API
    • 10.2 The Required Middleware
    • 10.3 CRUD by Hand
    • 10.4 CRUD for Free with TMVCActiveRecordController
    • 10.5 Validating Writes
    • 10.6 Master-Detail
  • 11. ActiveRecord in Depth
    • 11.1 The Connection Is Per Thread
    • 11.2 What the Field Options Really Do
    • 11.3 Reading, and Who Owns What Comes Back
    • 11.4 RQL, Precisely
    • 11.5 Named Queries, One per Database
    • 11.6 Hooks, and Two Kinds of Validation
    • 11.7 Audit Columns
    • 11.8 Change Tracking
    • 11.9 Soft Delete
    • 11.10 What a Request Body Is Allowed to Touch
    • 11.11 Input Models and Output Models
    • 11.12 One Table, Several Classes
    • 11.13 Composite Keys Beyond the Basics
    • 11.14 Generating Entities from an Existing Schema
    • 11.15 Natural Key or Surrogate
  • 12. Authentication & Authorization
    • 12.1 The Only Place You Can Trust
    • 12.2 The Authentication Handler
    • 12.3 Basic Authentication
    • 12.4 Stateless Auth with JWT
    • 12.5 Custom Authentication
    • 12.6 Hashing Passwords with PBKDF2
    • 12.7 Revoking Tokens: the JWT Blacklist
    • 12.8 Short Access Tokens with a Refresh Token
    • 12.9 Symmetric and Asymmetric Signing
    • 12.10 JWT over an HTTPOnly Cookie
    • 12.11 The Bill That Comes With the Cookie
    • 12.12 A Note on Transport Security
  • 13. OpenID Connect
    • 13.1 Authorization, Authentication, and the Thing in Between
    • 13.2 The Authorization Code Flow
    • 13.3 Discovery: One URL Instead of Five
    • 13.4 What the Middleware Owns
    • 13.5 Wiring It Into a Server
    • 13.6 Watching a Sign-In Happen
    • 13.7 Verifying the Signature
    • 13.8 What the Provider Actually Sends
    • 13.9 When Something Is Wrong
    • 13.10 Keycloak
    • 13.11 Google
    • 13.12 GitHub Is Not an OpenID Provider
  • 14. Middlewares
    • 14.1 The Middleware Lifecycle
    • 14.2 CORS
    • 14.3 Security Headers
    • 14.4 Compression
    • 14.5 Serving Static Files
    • 14.6 Rate Limiting
    • 14.7 The LRU Response Cache
    • 14.8 Logging Requests with DBLogger
    • 14.9 Range Requests and Seekable Media
    • 14.10 Writing Your Own Middleware
  • 15. Municipal Library: Authentication & Authorization Implementation
    • 15.1 Modeling Users and Roles
    • 15.2 Issuing Tokens at Login
    • 15.3 Enforcing Authorization
    • 15.4 Logging Out and Revoking Access
    • 15.5 The Browser Variant: JWT in an HTTPOnly Cookie
    • 15.6 Protecting the Login Endpoint
    • 15.7 Auditing Authentication
  • 16. JSON-RPC
    • 16.1 JSON-RPC 2.0 in a Nutshell
    • 16.2 Publishing Methods
    • 16.3 Returning Objects
    • 16.4 Notifications and Batches
    • 16.5 Allowing GET Calls
    • 16.6 The Strongly-Typed Client
    • 16.7 Authentication
    • 16.8 Error Handling
  • 17. Swagger / OpenAPI Documentation
    • 17.1 Adding the Swagger Middleware
    • 17.2 Documenting Functional Actions
    • 17.3 Records in Parameters and Responses
    • 17.4 Securing the Docs: Bearer and apiKey
    • 17.5 Handling Overloads
    • 17.6 Trying It Out
  • 18. Server-Side Views with TemplatePro
    • 18.1 SSR or JSON: Choosing the Right Tool
    • 18.2 Wiring the View Engine
    • 18.3 Your First Rendered Page
    • 18.4 TemplatePro Syntax
    • 18.5 One Layout to Rule Them All
    • 18.6 Feeding Data: ViewData and ViewDataSet
    • 18.7 Speaking the Reader's Language: Localization
    • 18.8 File Organization and Best Practices
  • 19. Building Modern Web Apps with HTMX
    • 19.1 Hypermedia, Not JavaScript Frameworks
    • 19.2 Setting Up: DMVCFramework + TemplatePro + HTMX
    • 19.3 The Core Attributes
    • 19.4 Returning Fragments: the IsHTMX Pattern
    • 19.5 Forms and Server-Side Validation
    • 19.6 Feedback While You Wait
    • 19.7 Pagination and Infinite Scroll
    • 19.8 Case Study: A Complete Todo App
  • 20. WebSocket Support
    • 20.1 WebSocket, HTTP and SSE
    • 20.2 Setting Up the WebSocket Server
    • 20.3 The Connection Lifecycle
    • 20.4 Groups, Broadcast and Thread Safety
    • 20.5 Pushing on a Timer
    • 20.6 Case Study: A Chat Application
    • 20.7 Case Study: A Live Dashboard
    • 20.8 A WebSocket Client in Delphi
  • 21. Dependency Injection
    • 21.1 Why Dependency Injection
    • 21.2 The DMVCFramework Container
    • 21.3 Service Lifecycles
    • 21.4 Injecting Services with [MVCInject]
    • 21.5 Factories and Parameterized Registration
    • 21.6 Testing with Mocks
  • 22. Repository Pattern
    • 22.1 Repository vs Direct ActiveRecord
    • 22.2 The IMVCRepository<T> Surface
    • 22.3 CRUD with the Repository
    • 22.4 Querying: SQL, RQL, and Named Queries
    • 22.5 Transactions with UseTransactionContext
    • 22.6 Custom Repositories
    • 22.7 Testing with a Mock Repository
  • 23. Server Engines & HTTPS
    • 23.1 The IMVCServer Abstraction
    • 23.2 Indy Direct (the Book Default)
    • 23.3 WebBroker
    • 23.4 HTTP.sys (Windows Kernel-Mode)
    • 23.5 Choosing a Backend
    • 23.6 Built-in HTTPS with TaurusTLS
    • 23.7 Tuning the Server
  • 24. Logging and Monitoring
    • 24.1 LoggerPro in DMVCFramework
    • 24.2 Multiple Sinks
    • 24.3 Request Logging with DBLogger
    • 24.4 Levels, Filtering, and Structured Logging
    • 24.5 Metrics with a Prometheus Middleware
    • 24.6 Custom Metrics
    • 24.7 Best Practices
  • 25. Deployment Scenarios
    • 25.1 The Production Surface Area
    • 25.2 Standalone Console (Windows and Linux)
    • 25.3 Running as a Windows Service
    • 25.4 Running as a Linux systemd Daemon
    • 25.5 Hosting Under Apache and IIS (ISAPI)
    • 25.6 Packaging with Docker
    • 25.7 TLS/HTTPS in Production
    • 25.8 Reverse Proxy: Caddy and nginx
    • 25.9 Graceful Shutdown and Health Checks
    • 25.10 Choosing a Deployment
  • 26. Hidden Gems
    • 26.1 Effortless Parallelism with MVCAsync
    • 26.2 Measuring with Profiler
    • 26.3 Reusing Objects with TObjectPool<T>
    • 26.4 Borrow, use, return ===
    • 26.5 Caching with TTL: TMVCCache
    • 26.6 TTL = 2 seconds ===
    • 26.7 Bounded Caching: TMVCLRUCache
    • 26.8 Insert D: the tail (C, least recent) is evicted ===
    • 26.9 Probe everything ===
    • 26.10 Probabilistic Membership: the Bloom Filter
    • 26.11 Basic membership ===
    • 26.12 No false negatives (1000 items) ===
    • 26.13 False positives on never-added items ===
    • 26.14 Configuration with dotEnv and Expressions
    • 26.15 Higher-Order Functions over TDataSet
    • 26.16 ForEachRecord: walk every row ===
    • 26.17 Project rows, then Map and Filter the array ===
  • 27. RESTful Client
    • 27.1 Meet TMVCRESTClient
    • 27.2 The HTTP Verbs
    • 27.3 GET /api/people ===
    • 27.4 POST /api/people ===
    • 27.5 PATCH /api/people/7 ===
    • 27.6 DELETE /api/people/7 ===
    • 27.7 Configuring the Request
    • 27.8 GET /api/secret without a token (expect 401) ===
    • 27.9 POST /login with Basic credentials ===
    • 27.10 GET /api/secret with Bearer token ===
    • 27.11 Reading the Response
    • 27.12 Files: Upload and Download
    • 27.13 POST /api/upload (multipart file) ===
    • 27.14 GET /api/files/report.txt (download to disk) ===
    • 27.15 Consuming Server-Sent Events
    • 27.16 SSE: subscribe to /api/ticks for a few events ===
    • 27.17 A Typed Client with TRESTAdapter
    • 27.18 TRESTAdapter: the same API as a Delphi interface ===
    • 27.19 Integration Testing a DMVCFramework Server
  • 28. Tips and Tricks
    • 28.1 Tip: Don't Load the System Controllers in Production
    • 28.2 Tip: Quiet the X-Powered-By Header
    • 28.3 Tip: Change or Hide the Server Header
    • 28.4 Tip: Redirect Browsers, Serve JSON to Everyone Else
    • 28.5 Tip: Choosing or Forcing a Server Backend
    • 28.6 Tip: HTTPS Quickstart
    • 28.7 Tip: Serializing Nulls with MVCSerializeNulls
    • 28.8 Tip: Human-Readable Status with HTTP_STATUS.ReasonStringFor
    • 28.9 Tip: Avoiding Mid-Air Collisions with foVersion
    • 28.10 Tip: Serving Static Files
    • 28.11 Tip: Rate Limiting
    • 28.12 Tip: Idempotent Requests
    • 28.13 Tip: API Versioning
    • 28.14 Tip: Scoped CORS
    • 28.15 Tip: DotEnv Expressions
    • 28.16 Tip: Graceful Shutdown
    • 28.17 Tip: Pagination, RQL and SQL
  • 29. Minimal Web API
    • 29.1 The Shape of a Minimal API Server
    • 29.2 Routing
    • 29.3 Type-Driven Parameter Binding
    • 29.4 Route Groups and Typed Group Data
    • 29.5 Endpoint Filters
    • 29.6 HTTP Filters: the Transport Tier
    • 29.7 Per-Endpoint Configuration
    • 29.8 Response Helpers
    • 29.9 Validation
    • 29.10 Native OpenAPI 3.1
    • 29.11 Authentication with Filters
    • 29.12 HTML from the Same Lambdas
    • 29.13 Further Patterns
    • 29.14 Coming from Controllers
  • A. MVCActiveRecord at a Glance
    • A.1 Reading
    • A.2 Writing
    • A.3 The Key
    • A.4 Transactions, Connections and the Current User
    • A.5 State of the Instance

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub