FIND THE IDEA YOU NEED
Search the course.
56 pages
Relationships belong in the database
Model users, workspaces, memberships, projects, and tasks as related rows.
dataSQL asks for a set of rows
Read scoped SELECT queries, joins, and parameterized values.
dataConstraints protect every writer
Understand primary keys, uniqueness, checks, and composite foreign keys.
dataDrizzle connects TypeScript to SQL
Understand what the schema and query builder guarantee, and what they do not.
dataA migration changes a running database
Distinguish schema code, migration history, and safe production rollout.
dataCommit related changes together
Use a transaction to keep a task mutation and its activity record consistent.
dataA version prevents silent overwrite
Understand optimistic concurrency through two people editing the same task.
dataBound the work behind a task list
Connect indexes, ordering, pagination, and query plans.
foundationsFollow one task request
Trace a browser request through the API into PostgreSQL and back.
foundationsHTTP is the agreement between client and server
Understand methods, status codes, headers, and resource identifiers.
foundationsNode runs JavaScript outside the browser
Separate the language, runtime, process, and application configuration.
foundationsWaiting and blocking are different
Explain asynchronous database calls and CPU work in the Node event loop.
foundationsMiddleware order changes what a route can trust
Understand the Express request pipeline and the special case for webhook bodies.
foundationsValidate where untrusted data enters
Separate frontend feedback, runtime validation, and database guarantees.
identityVerify a password without storing it
Understand password hashing, salts, verification cost, and account enumeration.
identityA session remembers a successful login
Explain opaque cookies, hashed session tokens, expiry, and revocation.
identityCookies make browser trust a server concern
Distinguish CSRF protection from CORS and ordinary authorization.
identityA workspace is the tenant boundary
Separate global users from the organizations that own application data.
identityScope every tenant-owned operation
Prevent insecure direct object references with membership checks and scoped queries.
identityA role belongs to a membership
Understand workspace-specific permissions and the safety of administrative changes.
identityAn invitation is a limited permission to join
Bind invitation tokens to a workspace, email address, role, and expiry.
identityVerification proves control of an email address
Explain purpose-specific tokens, expiry, and what verification does not establish.
identityPassword reset creates a temporary credential
Understand reset tokens, generic responses, single use, and session revocation.
identityIsolation applies beyond ordinary routes
Find tenant risks in idempotency records, workers, sockets, logs, and caches.
integrationsCheckout starts a payment workflow
Keep price selection and workspace billing authority on the server.
integrationsEntitlements are a server decision
Translate subscription state into workspace capabilities and enforce limits atomically.
integrationsVerify the bytes that Stripe signed
Preserve the raw webhook body and authenticate the provider before accepting an event.
integrationsStore each provider event once
Separate delivery deduplication from the order of subscription changes.
integrationsReconciliation asks what is true now
Fetch canonical subscription state and prevent stale workers from overwriting it.
integrationsA live connection carries notifications
Understand WebSockets and Socket.IO without replacing HTTP mutations.
integrationsA room name does not grant access
Authenticate sockets and recheck workspace membership before delivering tenant events.
integrationsReconnect by reading current state
Recover missed notifications and handle duplicate observations safely.
operationsSecurity checks belong at each boundary
Connect validation, sessions, CSRF, tenant scope, and operational secrets.
operationsFollow a failure across processes
Use request IDs, safe structured logs, and metrics to identify where work stopped.
operationsCapacity has several limits
Connect event-loop work, database pools, pagination, and load-testing evidence.
operationsContainers package processes and their connections
Read the Taskboard Dockerfile and Compose stack without needing to run them.
operationsThe course and backend deploy separately
Distinguish Cloudflare Pages output from long-running API and worker hosting.
operationsShutdown is part of the request lifecycle
Stop new traffic, finish bounded work, and preserve recoverable jobs.
operationsA backup matters when restoration works
Define acceptable data loss and rehearse recovery, including external side effects.
operationsTest the guarantee and its failure case
Read integration tests as evidence of behavior, with explicit limits on what they prove.
referenceFind the idea in the code
Where each Taskboard concept lives and how a request crosses the modules.
referenceThe HTTP route inventory
Actual methods and paths generated from the working Express app.
referenceBackend terms you can return to
Short definitions tied to the Taskboard example.
referenceWhat this app proves
Implemented guarantees, executed verification, and limits that need deployment evidence.
referenceRun the reference app when you want to
Optional local startup and verified demo accounts, separate from the reading path.
reliabilityA database commit cannot send an email
Why external side effects create a second failure boundary.
reliabilityThe outbox records unfinished work
Save a domain change and its delivery obligation atomically.
reliabilityA worker claims one available job
Why concurrent workers need a database claim rather than a shared array.
reliabilityA lease expires when a worker disappears
Recover abandoned jobs and reject completion by an outdated claimant.
reliabilityRetry a temporary failure with a limit
Separate retryable failures from invalid work and avoid retry storms.
reliabilityA retry can represent the same operation
Persist an operation key and result so lost responses do not create duplicate work.
reliabilityOne idempotency key has one meaning
Reject changed input instead of returning an unrelated cached response.
reliabilitySMTP acceptance is not inbox delivery
Understand what the email worker can prove and where duplicates arise.
reliabilityExhausted jobs need a recovery decision
Preserve failed work, inspect the cause, and replay without losing ownership rules.
reliabilityTwo systems can disagree temporarily
Use durable intent, stable provider keys, and reconciliation across external boundaries.
startYour frontend experience is the starting point
How to read this course and follow one working SaaS backend without running anything.