Phase 5 · Data, State & Device CapabilitiesModule 31~54 min read

HTTP, REST & JSON

Build typed, resilient API clients with sound HTTP semantics, serialization, cancellation, pagination, and repository boundaries.

What you'll learn

Build typed, resilient API clients with sound HTTP semantics, serialization, cancellation, pagination, and repository boundaries. The lesson turns the APIs into a repeatable engineering workflow instead of a collection of isolated snippets.

By the end of this lesson, you'll be able to:

  • Apply HTTP semantics in a production-shaped Flutter feature
  • Apply Typed JSON in a production-shaped Flutter feature
  • Apply DTO and domain models in a production-shaped Flutter feature
  • Apply Timeouts and retries in a production-shaped Flutter feature

Core mental model

Connect each API to the decision it supports. Flutter code stays maintainable when state, ownership, lifecycle, and platform boundaries are explicit.

ConceptWhat it meansDecision rule
DTOA type shaped for an external wire contractValidate it and map it to a stable domain model at the boundary
IdempotencyRepeating an operation has the same intended effectRetry only operations whose semantics and server contract make repetition safe
RepositoryThe application's source-of-truth interface for a data domainHide HTTP clients and response shapes behind domain-oriented methods

Professional workflow

Work in small vertical slices and keep behavior observable from the first iteration.

  1. Define the typed resilient API repository boundary: user goal, inputs, visible states, ownership, and expected failures.
  2. Build the smallest working vertical slice with typed data and explicit dependencies.
  3. Represent loading, empty, success, and failure behavior where the feature can encounter them.
  4. Verify logic away from the UI, then exercise the rendered behavior at its public boundary.
  5. Inspect lifecycle, accessibility, performance, security, and platform behavior before widening the feature.
  6. Refactor only after behavior is protected by repeatable evidence.

Protect the frame

Keep build methods predictable, move side effects to explicit owners, and measure before introducing caches, isolates, or architectural layers.

Guided Flutter lab

Build a focused typed resilient API repository slice

This compact example keeps the important ownership and data-flow decisions visible so the behavior is easy to extend and test.

lib/data/course_repository.dart
class CourseRepository {
  CourseRepository(this.client, this.baseUri);
  final http.Client client;
  final Uri baseUri;

  Future<Course> getCourse(String id) async {
    final uri = baseUri.resolve('/courses/$id');
    final response = await client.get(uri).timeout(const Duration(seconds: 10));
    if (response.statusCode != 200) {
      throw CourseRequestException(response.statusCode);
    }
    final json = jsonDecode(response.body);
    if (json case {'id': String id, 'title': String title}) {
      return Course(id: id, title: title);
    }
    throw const FormatException('Invalid course payload');
  }
}

Production practice

Contract

Define the typed resilient API repository inputs, outputs, owner, lifecycle, visible states, and platform assumptions before selecting APIs or packages.

Verification

Protect pure rules with unit tests and the rendered public contract with widget or integration evidence; include one unavailable or failure case.

Operations

Keep dependencies replaceable, log actionable context without user secrets, and measure user-visible behavior before optimizing.

Common failure mode

Treating every non-200 response as an empty list erases authorization, rate-limit, server, and parsing failures the UI and operators need to distinguish.

Independent workshop

Extend the guided lab into a review-ready typed resilient API repository feature that fits the running course portfolio app.

Your finished workshop must include:

  • HTTP semantics
  • Typed JSON
  • DTO and domain models
  • Timeouts and retries
  • Pagination
  • Automated verification and a short design note

Definition of done

Demonstrate the happy path, an empty or unavailable state, and at least one failure path. Add an automated check and a short note explaining one design decision.

Recap & quick check

Key takeaways

  • DTO: Validate it and map it to a stable domain model at the boundary
  • Idempotency: Retry only operations whose semantics and server contract make repetition safe
  • Repository: Hide HTTP clients and response shapes behind domain-oriented methods

Quick check

1. Which rule best applies to DTO?

2. Which rule best applies to Idempotency?

3. Which rule best applies to Repository?

Next: Persistence, SQLite & Offline-First Data