One idea at a time
Backend terms you can return to
You do not need to memorize these terms. Return when a lesson uses a word you cannot connect to a concrete action.
Requests and identityโ
| Term | In Taskboard |
|---|
| HTTP contract | The method, path, input, status, and response the browser can rely on. |
| Middleware | An Express function that handles part of a request before the route runs. |
| Authentication | Finding the user from a valid stored session. |
| Authorization | Checking whether that user can perform this action in this workspace. |
| Session | A server record identified by an opaque cookie token. |
| CSRF | A forged request that tries to use someone else's browser session. Taskboard requires a separate token for authenticated mutations. |
| Tenant | One workspace whose data belongs together and stays separate from other workspaces. |
Stored dataโ
| Term | In Taskboard |
|---|
| Migration | A committed change to the Postgres schema. |
| Constraint | A database rule that rejects an invalid row, such as a task referencing another tenant's project. |
| Transaction | Changes that commit together or roll back together. |
| Isolation | Rules for what concurrent transactions can observe. |
| Row lock | A transaction holds a workspace row while deciding a shared quota or permission change. |
| Optimistic concurrency | An edit supplies the version it read. A conflicting version makes the server reject the edit. |
| Keyset pagination | The next page starts after a stable timestamp and ID pair. |
| Connection pool | Reusable database connections shared by requests and jobs. |
Work and failuresโ
| Term | In Taskboard |
|---|
| Idempotency | Retrying one keyed task creation returns its saved result instead of creating another task. |
| Outbox | The transaction stores a job beside its domain changes so committed work is not lost before delivery. |
| Lease | A temporary job claim. Another worker can recover it after expiry. |
| Fencing token | A claim identifier checked before renewal or completion. An old worker cannot acknowledge a newer claim. |
| At-least-once delivery | A job can run more than once after an uncertain failure. SMTP email can be duplicated. |
| Backoff | Wait longer between retry attempts, with random jitter to spread retries. |
| Webhook | An external provider sends an HTTP event to the app. |
| Reconciliation | Fetch current provider state and repair the local billing view. |
| Readiness | Whether the process can serve traffic with its required migrations applied. |
| Liveness | Whether the process is alive enough to respond. |
| Observability | Logs and metrics that show what the running system is doing. |
| RPO | How much recent data a recovery plan can afford to lose. |
| RTO | How long that recovery can take. |
A term describes a mechanism. The lesson explains why that mechanism matters and what it cannot guarantee.