Skip to main content

FIND THE IDEA YOU NEED

Search the course.

56 pages

data

Relationships belong in the database

Model users, workspaces, memberships, projects, and tasks as related rows.

data

SQL asks for a set of rows

Read scoped SELECT queries, joins, and parameterized values.

data

Constraints protect every writer

Understand primary keys, uniqueness, checks, and composite foreign keys.

data

Drizzle connects TypeScript to SQL

Understand what the schema and query builder guarantee, and what they do not.

data

A migration changes a running database

Distinguish schema code, migration history, and safe production rollout.

data

Commit related changes together

Use a transaction to keep a task mutation and its activity record consistent.

data

A version prevents silent overwrite

Understand optimistic concurrency through two people editing the same task.

data

Bound the work behind a task list

Connect indexes, ordering, pagination, and query plans.

foundations

Follow one task request

Trace a browser request through the API into PostgreSQL and back.

foundations

HTTP is the agreement between client and server

Understand methods, status codes, headers, and resource identifiers.

foundations

Node runs JavaScript outside the browser

Separate the language, runtime, process, and application configuration.

foundations

Waiting and blocking are different

Explain asynchronous database calls and CPU work in the Node event loop.

foundations

Middleware order changes what a route can trust

Understand the Express request pipeline and the special case for webhook bodies.

foundations

Validate where untrusted data enters

Separate frontend feedback, runtime validation, and database guarantees.

identity

Verify a password without storing it

Understand password hashing, salts, verification cost, and account enumeration.

identity

A session remembers a successful login

Explain opaque cookies, hashed session tokens, expiry, and revocation.

identity

Cookies make browser trust a server concern

Distinguish CSRF protection from CORS and ordinary authorization.

identity

A workspace is the tenant boundary

Separate global users from the organizations that own application data.

identity

Scope every tenant-owned operation

Prevent insecure direct object references with membership checks and scoped queries.

identity

A role belongs to a membership

Understand workspace-specific permissions and the safety of administrative changes.

identity

An invitation is a limited permission to join

Bind invitation tokens to a workspace, email address, role, and expiry.

identity

Verification proves control of an email address

Explain purpose-specific tokens, expiry, and what verification does not establish.

identity

Password reset creates a temporary credential

Understand reset tokens, generic responses, single use, and session revocation.

identity

Isolation applies beyond ordinary routes

Find tenant risks in idempotency records, workers, sockets, logs, and caches.

integrations

Checkout starts a payment workflow

Keep price selection and workspace billing authority on the server.

integrations

Entitlements are a server decision

Translate subscription state into workspace capabilities and enforce limits atomically.

integrations

Verify the bytes that Stripe signed

Preserve the raw webhook body and authenticate the provider before accepting an event.

integrations

Store each provider event once

Separate delivery deduplication from the order of subscription changes.

integrations

Reconciliation asks what is true now

Fetch canonical subscription state and prevent stale workers from overwriting it.

integrations

A live connection carries notifications

Understand WebSockets and Socket.IO without replacing HTTP mutations.

integrations

A room name does not grant access

Authenticate sockets and recheck workspace membership before delivering tenant events.

integrations

Reconnect by reading current state

Recover missed notifications and handle duplicate observations safely.

operations

Security checks belong at each boundary

Connect validation, sessions, CSRF, tenant scope, and operational secrets.

operations

Follow a failure across processes

Use request IDs, safe structured logs, and metrics to identify where work stopped.

operations

Capacity has several limits

Connect event-loop work, database pools, pagination, and load-testing evidence.

operations

Containers package processes and their connections

Read the Taskboard Dockerfile and Compose stack without needing to run them.

operations

The course and backend deploy separately

Distinguish Cloudflare Pages output from long-running API and worker hosting.

operations

Shutdown is part of the request lifecycle

Stop new traffic, finish bounded work, and preserve recoverable jobs.

operations

A backup matters when restoration works

Define acceptable data loss and rehearse recovery, including external side effects.

operations

Test the guarantee and its failure case

Read integration tests as evidence of behavior, with explicit limits on what they prove.

reference

Find the idea in the code

Where each Taskboard concept lives and how a request crosses the modules.

reference

The HTTP route inventory

Actual methods and paths generated from the working Express app.

reference

Backend terms you can return to

Short definitions tied to the Taskboard example.

reference

What this app proves

Implemented guarantees, executed verification, and limits that need deployment evidence.

reference

Run the reference app when you want to

Optional local startup and verified demo accounts, separate from the reading path.

reliability

A database commit cannot send an email

Why external side effects create a second failure boundary.

reliability

The outbox records unfinished work

Save a domain change and its delivery obligation atomically.

reliability

A worker claims one available job

Why concurrent workers need a database claim rather than a shared array.

reliability

A lease expires when a worker disappears

Recover abandoned jobs and reject completion by an outdated claimant.

reliability

Retry a temporary failure with a limit

Separate retryable failures from invalid work and avoid retry storms.

reliability

A retry can represent the same operation

Persist an operation key and result so lost responses do not create duplicate work.

reliability

One idempotency key has one meaning

Reject changed input instead of returning an unrelated cached response.

reliability

SMTP acceptance is not inbox delivery

Understand what the email worker can prove and where duplicates arise.

reliability

Exhausted jobs need a recovery decision

Preserve failed work, inspect the cause, and replay without losing ownership rules.

reliability

Two systems can disagree temporarily

Use durable intent, stable provider keys, and reconciliation across external boundaries.

start

Your frontend experience is the starting point

How to read this course and follow one working SaaS backend without running anything.