Skip to main content
One idea at a time

Backend terms you can return to

You do not need to memorize these terms. Return when a lesson uses a word you cannot connect to a concrete action.

Requests and identityโ€‹

TermIn Taskboard
HTTP contractThe method, path, input, status, and response the browser can rely on.
MiddlewareAn Express function that handles part of a request before the route runs.
AuthenticationFinding the user from a valid stored session.
AuthorizationChecking whether that user can perform this action in this workspace.
SessionA server record identified by an opaque cookie token.
CSRFA forged request that tries to use someone else's browser session. Taskboard requires a separate token for authenticated mutations.
TenantOne workspace whose data belongs together and stays separate from other workspaces.

Stored dataโ€‹

TermIn Taskboard
MigrationA committed change to the Postgres schema.
ConstraintA database rule that rejects an invalid row, such as a task referencing another tenant's project.
TransactionChanges that commit together or roll back together.
IsolationRules for what concurrent transactions can observe.
Row lockA transaction holds a workspace row while deciding a shared quota or permission change.
Optimistic concurrencyAn edit supplies the version it read. A conflicting version makes the server reject the edit.
Keyset paginationThe next page starts after a stable timestamp and ID pair.
Connection poolReusable database connections shared by requests and jobs.

Work and failuresโ€‹

TermIn Taskboard
IdempotencyRetrying one keyed task creation returns its saved result instead of creating another task.
OutboxThe transaction stores a job beside its domain changes so committed work is not lost before delivery.
LeaseA temporary job claim. Another worker can recover it after expiry.
Fencing tokenA claim identifier checked before renewal or completion. An old worker cannot acknowledge a newer claim.
At-least-once deliveryA job can run more than once after an uncertain failure. SMTP email can be duplicated.
BackoffWait longer between retry attempts, with random jitter to spread retries.
WebhookAn external provider sends an HTTP event to the app.
ReconciliationFetch current provider state and repair the local billing view.
ReadinessWhether the process can serve traffic with its required migrations applied.
LivenessWhether the process is alive enough to respond.
ObservabilityLogs and metrics that show what the running system is doing.
RPOHow much recent data a recovery plan can afford to lose.
RTOHow long that recovery can take.

A term describes a mechanism. The lesson explains why that mechanism matters and what it cannot guarantee.