REST APIs with Express
Build real REST APIs with Express 5: routing, middleware, validation, errors, security and tests, running in every lesson.
31 lessons across 8 units: routing, middleware, REST design, validation, error handling, app structure, security and testing with Express 5, with 38 runnable examples, quizzes and 31 coding problems that build real APIs.
- Units
- 8
- Lessons
- 31
- Coding problems
- 31
- Examples
- 38
Free: units 1 to 2 (8 lessons). Units 3 to 8 with DevArcade Pro.
What you'll learn
- Hello, ExpressWhat Express adds to node:http, routes and methods, parameters and query strings, and every kind of response.
- MiddlewareThe middleware chain and next(), reading request bodies, routers and mounting, static files and SPAs.
- Designing REST APIsResources and status codes, a complete CRUD API, pagination, filtering and sorting, ETags and lost updates.
- ValidationValidating at the boundary, a schema validator, and validation middleware for body, query and params.
- Error HandlingError-handling middleware, async errors in Express 5 and 4, error classes and Problem Details.
- Structuring an AppApp factories and injected dependencies, routes, services and repositories, a JSON file store, response caching.
- Security and Production MiddlewareCORS and preflight, rate limiting, security headers and limits, API keys and bearer tokens.
- Testing and ShippingTesting apps over HTTP, request logging, health checks and shutdown, then the bookmarks API boss.
Course outline
8 units and 31 lessons. Each lesson has a short read with examples you run, a quiz, and coding problems tested in your browser; most have a step-through visualizer.
- Free
Unit 1:Hello, Express
What Express adds to node:http, routes and methods, parameters and query strings, and every kind of response.
- What Express Adds Express is a thin layer over node:http: routing, middleware and response helpers. An app is just a request handler.1 problem
- Routes and HTTP Methods app.get, post, put, patch, delete and all; app.route for one path with several methods; first match wins; why Express does not send 405 for you.1 problem
- Route Parameters and Query Strings req.params from :name segments, Express 5's path syntax ({optional}, *splat), and req.query: strings, arrays and validation.1 problem
- Sending Responses res.send for strings, Buffers and objects, res.json, status and sendStatus, headers, redirects, downloads, cookies, and the automatic ETag.1 problem
-
- Free
Unit 2:Middleware
The middleware chain and next(), reading request bodies, routers and mounting, static files and SPAs.
- Middleware and next() Functions that run in order for every request: app.use, calling next(), ending early, path-scoped middleware and res.locals.1 problem
- Reading Request Bodies express.json, urlencoded and text, why req.body is undefined without them, size limits, and the 400 and 413 errors parsers produce.1 problem
- Routers and Mounting express.Router as a mini app, mounting it under a path, req.baseUrl, mergeParams, router-level middleware and next('router').1 problem
- Static Files and a SPA Fallback express.static: index files, dotfiles, directory redirects, caching headers, and serving a single-page app with a fallback to index.html.1 problem
-
- Pro
Unit 3:Designing REST APIs
Resources and status codes, a complete CRUD API, pagination, filtering and sorting, ETags and lost updates.
- Resources, URLs and Status Codes Design an API around resources: plural nouns in URLs, methods as verbs, nesting, the status codes clients rely on, and the Location header.1 problem
- A Complete CRUD API Create, read, update and delete over HTTP: ids, 201 with Location, PUT versus PATCH, 204 on delete, 404s, and ignoring fields clients must not set.1 problem
- Pagination Never return everything: page and limit parameters with caps, a response envelope with totals, Link headers, and when cursors beat page numbers.1 problem
- Filtering and Sorting Query parameters for filters, a sort syntax like ?sort=-year,title, allowlists for fields, and 400s for anything you do not support.1 problem
- ETags and Lost Updates Two clients editing the same resource: the lost update problem, versions as ETags, If-Match with 412 Precondition Failed, and 428 when the header is missing.1 problem
-
- Pro
Unit 4:Validation
Validating at the boundary, a schema validator, and validation middleware for body, query and params.
- Validate at the Boundary Everything from a request is untrusted: check types, presence, lengths and ranges once, at the edge, and answer with errors clients can act on.1 problem
- Describe Shapes with a Schema Write the rules down once as data: types, required fields, lengths, ranges, enums and patterns, with nested objects and a cleaned value out.1 problem
- Validation Middleware One reusable middleware per route: validate body, query and params, convert query strings to numbers, store the clean values, and send consistent 400s.1 problem
-
- Pro
Unit 5:Error Handling
Error-handling middleware, async errors in Express 5 and 4, error classes and Problem Details.
- Error-handling Middleware Four parameters make an error handler: how next(err) and thrown errors reach it, where to put it, a JSON 404, and handing off when headers are sent.1 problem
- Async Errors: Express 5 and 4 Express 5 forwards rejected promises from async handlers to your error handler; Express 4 did not, which is why asyncHandler wrappers exist.1 problem
- Error Classes and Problem Details An HttpError class with status, expose and details, small helpers to throw it, and RFC 9457 Problem Details as a standard JSON error format.1 problem
-
- Pro
Unit 6:Structuring an App
App factories and injected dependencies, routes, services and repositories, a JSON file store, response caching.
- The App Factory Build the app in createApp(deps) and start it elsewhere: tests get a fresh app with fake dependencies, and nothing listens on import.1 problem
- Routes, Services and Repositories Keep HTTP in the routes, business rules in services and storage in repositories, so each part can change and be tested on its own.1 problem
- A Repository on a JSON File Persist to a JSON file behind a repository interface, and serialize writes so concurrent requests cannot overwrite each other.1 problem
- Caching Responses Cache-Control for clients and CDNs, an in-memory TTL cache for expensive GETs, cache keys, and invalidating on writes.1 problem
-
- Pro
Unit 7:Security and Production Middleware
CORS and preflight, rate limiting, security headers and limits, API keys and bearer tokens.
- CORS and Preflight Requests Why browsers block cross-origin calls, the Access-Control headers that allow them, preflight OPTIONS requests, credentials and an origin allowlist.1 problem
- Rate Limiting Protect the API from floods and brute force: a fixed-window counter per client, 429 with Retry-After, RateLimit headers, and choosing the key.1 problem
- Security Headers and Limits The headers helmet sets and why, dropping X-Powered-By, small body limits, and the defaults that make an API harder to abuse.1 problem
- API Keys and Bearer Tokens Authenticate API clients with the Authorization header: 401 versus 403, WWW-Authenticate, scopes, and comparing secrets in constant time.1 problem
-
- Pro
Unit 8:Testing and Shipping
Testing apps over HTTP, request logging, health checks and shutdown, then the bookmarks API boss.
- Testing an Express App Start the real app on port 0 and call it with fetch, from node:test with assert; what to cover; and how to know your tests catch bugs.1 problem
- Request Logging One structured log line per request when it finishes: method, path, status, duration and request id, with the level chosen by status.1 problem
- Health Checks and Shutdown Liveness versus readiness endpoints, checking dependencies with a timeout, and draining traffic before a graceful shutdown.1 problem
- Boss: A Bookmarks API Everything together: an Express API with auth for writes, validation, conflicts, pagination and filtering, 405s, JSON errors and a file that survives restarts.1 problem
-
Start REST APIs with Express for free
Enroll for free and units 1 and 2 are yours. DevArcade Pro opens every unit of every course, including new ones as they launch, monthly or yearly.