Web development connects a browser request to a server decision and a result a person can use. Start with the request contract, then follow one inspection workflow through the DOM, validation, state, accessibility, performance, and release. Each lesson names the layer that owns a rule, gives a concrete case, and links to the next boundary.
Starting points
Web Development: follow one request through the stack; Web Development: assign authority to the right layer; Practice project: trace a case page across the stack.
Requests and Browser Foundations
From a URL and request to a parsed page.
- HTTP requests: keep method, status, and body contracts separate — Route a read and a write through explicit request and response rules.
- URLs and origins: separate location, query, and fragment — Read a browser location without confusing navigation state with server input.
- Page loading: keep content available while CSS and scripts arrive — Separate parsed HTML, styles, deferred behavior, and optional images.
- First connection: separate name resolution, TLS, and HTTP — Locate a service, protect the connection, then interpret its response.
- Routing: validate path parameters and return a stable error shape — Distinguish a malformed case ID from an absent case and a forbidden one.
Browser Interactions
Events, fetch, and real form submission contracts.
- DOM events: enhance a working control without losing its baseline — Attach one handler to a form that already submits a useful request.
- Fetch requests: separate HTTP failure, transport failure, and cancellation — Check response status, bound waiting time, and discard obsolete results.
- Form submission: validate on the server and return field errors — Preserve submitted values while rejecting records that break the stored contract.
- Cross-origin requests: read CORS as a browser access policy — Allow only intended browser origins without mistaking CORS for authentication.
- Responsive interaction: preserve content and control order — Change layout across widths without hiding the only path to an action.
State and Trust
Sessions, local storage, and cache validation boundaries.
- Sessions and CSRF: keep identity on the server — Model a session cookie and a separate write token without trusting browser storage.
- Browser storage: save convenience data without storing credentials — Treat local storage as untrusted, optional, and visible to page scripts.
- HTTP caching: validate a changed representation with an ETag — Return 304 only when the client's validator matches the current representation.
- Untrusted output: escape by context and constrain scripts — Keep user text as text, then add a script policy as another boundary.
- Authorization: check permission for this record on every request — Distinguish a signed-in identity from authority over case 47.
Quality and Release
Accessibility, performance, and deploy verification.
- Accessible forms: connect labels, errors, and focus — Make a failed submission understandable without relying on color or pointer input.
- Page performance: budget the critical path and reserve layout space — Measure loading, interaction, and visual stability as separate user costs.
- Release checks: prove the critical route and prepare a rollback — Check a public page and API contract after deployment, then stop on evidence of regression.
- Tests across boundaries: assert behavior, not implementation text — Keep a small suite for route status, validation, and unauthorized mutation.
- Observability: connect user failure to a safe request trace — Record status, route, duration, and a correlation ID without logging secrets.
Build and test
Web Technology: Projects; Web Development: Quizzes.
Go deeper by language
HTML Tutorial; CSS Tutorial; JavaScript Tutorial.
Broader Web Development tracks
These tracks extend the browser-to-service path into application structure, durable data, live and offline behavior, deployment, and public content architecture. Each hub provides four specific decisions to study and connects back to the earlier lessons.
Frontend Application Architecture
Organize page state, navigation, rendering, and locale behavior without losing the HTML baseline.
- Component Boundaries and State Ownership — Keep source records, temporary input, and derived display values in distinct places.
- Browser Routing and History State — Keep client navigation aligned with a route the server can open directly.
- Static, Server-Rendered, and Client-Rendered Pages — Choose a rendering boundary from data freshness, interaction, and failure needs.
- Locale and Time-Zone Boundaries — Store an unambiguous instant and format it for the reader at the edge.
Backend and API Systems
Shape read and write endpoints for growing collections and unreliable networks.
- Cursor Pagination for Changing Collections — Page through records with a stable order and a bounded response size.
- Idempotent Write Requests and Lost Responses — Make a retry return the first result instead of repeating a side effect.
- Background Jobs and the Outbox Boundary — Record a business change and its follow-up work together.
- Rate Limits and Request Budgets — Bound work per caller while keeping response behavior predictable.
Data Persistence
Model records, preserve invariants under concurrent writes, and change schemas safely.
- Relational Records and Database Constraints — Express case ownership and inspection identity in the schema, not only in forms.
- Transactions and Concurrent Writes — Keep a multi-step update atomic and reject stale edits deliberately.
- Indexes and Query Plans for Case Feeds — Match an index to the actual filter and sort used by a route.
- Expand-and-Contract Schema Migrations — Change stored data while old and new application versions overlap.
Media and Live Updates
Accept files, serve useful image sizes, and deliver ordered changes to active pages.
- Safe File Upload Pipeline — Accept an inspection photo only after bounded parsing, permission, and type checks.
- Image Variants and Delivery Budgets — Serve pixels suited to the display box while reserving stable layout space.
- Server-Sent Events or WebSocket for Live Views — Choose one-way events or two-way messages from the actual interaction contract.
- Live Update Reconnect and Event Ordering — Reject older status events and reconcile gaps after a stream restarts.
Offline and Device Capabilities
Cache a useful shell, keep local drafts, and reconcile changes after reconnecting.
- Service Worker Offline Fallback — Cache an intentional public shell without caching private case responses.
- IndexedDB for Local Drafts — Keep an unsent inspection draft separate from an accepted server record.
- Web App Manifest and Optional Installation — Describe a useful launch surface while keeping the website usable in a tab.
- Offline Sync and Conflict Policy — Tell the user when a local edit conflicts with a newer server version.
Deployment and Scale
Configure releases, gate changes, share state, and prove recovery from data loss.
- Environment Configuration and Secret Boundaries — Validate required settings at startup and keep credentials out of client bundles.
- Continuous Integration and Release Gates — Run fast content and code checks before a candidate becomes a release.
- Horizontal Scale and Shared State — Keep case requests correct when successive calls reach different workers.
- Backup and Restore Drills — Prove a protected copy can recover a case record within a stated window.
Content Discovery and Structure
Give public pages stable identities, navigable paths, and machine-readable meaning.
- Canonical Route Identity — Choose one stable public path for a page and handle alternate paths deliberately.
- Structured Data from Visible Facts — Describe a public article using facts already present in its page content.
- Sitemap and Index Control — List only canonical public routes and keep drafts out of the published set.
- Internal Link Architecture for Technical Guides — Connect prerequisites, adjacent decisions, and practical projects with real routes.
Integrated practice
Use Web Development Projects to apply the track, then check decisions in Web Development: Quizzes.
Identity and Application Security
Protect account access, recovery, federated callbacks, and server-side outbound requests.
- Password Verification and Login Budgets — Store slow salted verifiers and bound repeated attempts without revealing account existence.
- Account Recovery and Session Revocation — Make recovery tokens single-use, short-lived, and separate from an active session.
- Federated Login Callback Boundary — Bind an external sign-in response to the browser that began it and verify the identity token.
- Outbound URL Requests and SSRF Boundaries — Keep user-supplied destinations away from private networks and privileged credentials.
Integration and Verification
Keep external events, API changes, browser journeys, and performance measurements honest.
- Signed Webhook Delivery and Replay Control — Verify raw event bytes, reject old deliveries, and process duplicates safely.
- API Evolution and Compatibility Windows — Change a response contract without breaking clients that still use the old shape.
- Browser Journey and Fault-Injection Tests — Test a user task through navigation, request, response, and visible recovery.
- Field and Lab Performance Evidence — Separate controlled diagnosis from the conditions real visitors experience.
Advanced practice
Apply account and integration contracts with Project: account access and recovery boundary and Project: webhook contract and browser verification.
Inclusive Interface Engineering
Design named controls, predictable focus, recoverable forms, and layouts that survive zoom and motion preferences.
- Accessible Names and Native Controls — Keep a control's visible purpose aligned with its programmatic name and native behavior.
- Dialog Focus and Interruption Boundary — Open a modal task with a clear name, contained focus, and a reliable return path.
- Form Errors and Recovery Paths — Keep rejected submissions understandable, located, and recoverable without discarding good input.
- Reflow, Zoom, and Motion Preferences — Keep the task available when text grows, the viewport narrows, or motion is reduced.
Internationalization and Content Delivery
Keep messages, locale-sensitive values, mixed-direction text, and localized routes consistent.
- Message Catalog Contracts and Fallback — Treat translated strings as versioned interface data with stable keys and visible missing-message behavior.
- Currency, Date, and Time-Zone Presentation — Keep canonical values separate from locale-sensitive display and explicit time-zone policy.
- Right-to-Left and Mixed-Direction Content — Declare page direction and isolate unknown text so identifiers and prose remain legible together.
- Localized Routes and Translation Release — Publish language-specific pages without losing identity, old links, or editorial readiness.
Inclusive and global practice
Apply the interface and publication contracts with Project: inclusive case review and Project: localized guide release.
Typed Frontend and Component Platform
Validate external data, tame async UI work, choose component boundaries, and budget loaded code.
- TypeScript and Runtime API Boundaries — Treat parsed network data as unknown until its required shape is checked at runtime.
- React Effects and Request Races — Tie asynchronous work to the current route and stop stale results from replacing new state.
- Web Components and Shadow Boundaries — Use custom elements for stable reuse while planning styling, focus, events, and form behavior.
- Module Splitting and Interaction Budget — Load optional code near the task that needs it without making the first interaction wait blindly.
Browser Security and Data Stewardship
Set embedding and capability limits, guard DOM sinks, pin dependencies, and keep telemetry lean.
- Embedding and Browser Capability Headers — Constrain framing, referrer disclosure, and browser features with response policy that matches the route.
- DOM Sinks and Trusted Content — Render untrusted strings as text and tightly control the rare path that needs authored HTML.
- Dependency Integrity and Update Window — Keep browser dependencies reproducible and review the code that changes between releases.
- Telemetry Minimization and Retention — Record operational signals without turning logs into a second store of private case content.
Platform and trust practice
Apply frontend and data-stewardship boundaries with Project: typed review console and Project: private page trust review.
Application Search and Retrieval
Build searchable case records without losing freshness, stable ordering, or access control.
- Search Index Freshness and Rebuilds — Define when committed case changes become searchable and how a new index replaces an old one.
- Search Query Normalization and Ranking — Interpret query text deliberately, rank useful results, and keep a stable tie-breaker.
- Search Filters and Result Cursors — Bind filters and sort order to a cursor so moving through results stays coherent.
- Search Permissions and Private Results — Apply record authorization inside retrieval and prevent snippets, counts, and suggestions from leaking.
Quality and Capacity Engineering
Choose test boundaries, inject failures, check usable screens, and measure load against a budget.
- Test Boundaries and Evidence Selection — Place checks where each failure can be observed rather than repeating one assertion at every layer.
- Deterministic Test Doubles and Fault Injection — Control failure timing without erasing the integration behavior the product depends on.
- Accessibility and Visual Regression Checks — Check task usability, keyboard behavior, and stable layout with evidence beyond a screenshot.
- Load Tests and Capacity Budgets — Model a realistic request mix and stop a release when latency or errors cross agreed limits.
Search and quality practice
Apply retrieval and release evidence with Project: private case search and Project: release evidence and capacity.
CSS Layout and Interface Systems
Choose layout constraints, component queries, cascade ownership, typography, and motion from real content.
- Grid, Flex, and Intrinsic Size Contracts — Use layout primitives according to the relationship between regions, then test long content and minimum sizes.
- Container Queries for Reusable Panels — Adapt a panel to its own space instead of assuming the viewport predicts its width.
- Cascade Layers and Design Token Ownership — Make style precedence explicit and separate shared decisions from component exceptions.
- Font Loading and Motion Fallbacks — Keep text usable during font loading and preserve meaning when animation is reduced.
Browser Execution and Resource Lifecycle
Keep interaction work responsive by understanding tasks, workers, yielding, and resource ownership.
- Event Loop Tasks, Microtasks, and Paint — Know which queued work runs before the browser can respond and paint a changed state.
- Workers, Messages, Transfer, and Cancellation — Move expensive computation off the main thread while keeping messages versioned and route-owned.
- Cooperative Main-Thread Scheduling — Split bounded work into tasks so input and rendering can proceed without losing result integrity.
- Browser Memory and Resource Lifecycles — Pair every route-owned listener, observer, URL, timer, and worker with a clear disposal path.
Layout and runtime practice
Apply browser layout and execution decisions with Project: adaptive review interface and Project: responsive import worker.
API Mutation and Failure Contracts
Prevent lost writes, bound retries, expose long-running work, and make errors usable by clients.
- Conditional Writes and Lost-Update Prevention — Require a current representation version before applying a case mutation.
- Request Deadlines, Retries, and Backoff — Spend one bounded time budget and retry only operations whose effects are safe to repeat.
- Accepted Operations and Status Resources — Represent work that continues after the request as a durable operation with a readable outcome.
- Structured API Errors and Recovery — Give clients stable error classes without exposing private internals or confusing status codes.
API mutation practice
Apply conditional writes, retry budgets, and status resources with Project: conflict-safe case API.
Server Rendering and Client Data Flow
Keep the first render deterministic, then give client-held records clear freshness and mutation rules.
- Hydration and Deterministic First Render — Make server HTML and the browser's initial component tree agree before reading browser-only state.
- Server Data Bootstrap and Freshness — Pass request data to the client without cross-request leaks or a pointless immediate refetch.
- Client Cache Keys and Invalidation — Give each cached view a complete identity and refresh the views affected by a write.
- Optimistic Mutations and Rollback — Show immediate feedback without turning a failed write into a false success.
Forms and Data Entry Workflows
Make submission, validation, autosave, and large uploads recoverable under real browser conditions.
- Native Form Submission and Progressive Enhancement — Keep a working server submission path, then add client behavior without bypassing browser form rules.
- Asynchronous Field Validation Races — Ignore obsolete field responses and keep server validation authoritative at final submission.
- Autosave, Draft Recovery, and Conflicts — Persist edits without disguising local storage as a confirmed server save.
- Multipart Upload Progress and Retry Boundaries — Separate file selection, transfer, and server acceptance; retry from a defined upload protocol.
Rendering and form practice
Apply the data-flow and submission contracts with Project: server-rendered case queue and Project: recoverable case intake form.
Navigation, History, and Page Lifecycle
Preserve URL state, focus, scroll, and fresh data across route transitions and browser restoration.
- URL State and History Entry Contracts — Put shareable state in the URL and choose push or replace according to user intent.
- Back-Forward Cache and Restored State — Recheck volatile or private data when a suspended page resumes from browser history.
- Route Scroll and Focus Restoration — Restore reading position and keyboard context after client-side navigation and delayed content.
- Navigation Prefetch and Private Data Budget — Warm likely next routes without preloading private content or starving current work.
HTTP Delivery and Cache Ownership
Match response reuse, variants, and resource priority to public and private content.
- Shared Cache Keys and Private Response Boundaries — Choose cache ownership and variant keys before putting response bytes at an edge.
- Stale Revalidation and Versioned Purges — Use stale responses only where delayed freshness is acceptable and invalidation is observable.
- Content Negotiation and Compression Contracts — Serve the right representation and keep caches aware of language and content encoding.
- Critical Resource Discovery and Priority — Make the first important image or text resource discoverable early without flooding the network.
Navigation and delivery practice
Apply route and response ownership with Project: history-safe review journey and Project: edge cache and critical resource release.
Streaming and Large Data Interfaces
Process large responses incrementally with bounded memory, cancellation, and honest completion states.
- Incremental Response Framing and UTF-8 — Decode and frame streamed records without assuming network chunks match lines or characters.
- Stream Backpressure and Bounded Work — Match reading speed to processing capacity instead of accumulating an unbounded queue.
- Stream Cancellation and Partial-Result Contract — Separate a completed feed from an aborted or truncated one, and make retry position explicit.
- Large Export Download and Integrity — Keep large exports out of browser memory when possible and verify a resumed artifact's identity.
Complex Accessible Interactions
Choose native semantics where possible and define focus, keyboard, and pointer alternatives for custom controls.
- Data Table Versus Interactive Grid — Use native table relationships for reading and add grid keyboard behavior only when cells are truly interactive.
- Combobox Suggestions and Active Option — Keep input editing intact while suggestions announce a stable active option and commit path.
- Reorder Controls Without Dragging — Give priority changes a keyboard and single-pointer path that uses the same ordered mutation.
- Async Status Announcements and Focus — Report background results without stealing focus or repeatedly announcing an entire region.
Streams and interaction practice
Apply the large-data and complex-control contracts with Project: streamed case activity and export and Project: accessible operations workspace.
Production Signals and Incident Decisions
Connect a failed user action to bounded telemetry, service objectives, and a tested containment decision.
- Trace Context Across Requests and Jobs — Follow one user action through HTTP and queued work without treating trace IDs as authorization.
- User Journey SLOs and Burn Alerts — Measure whether people can finish an operation and alert on meaningful error-budget loss.
- Telemetry Shapes, Redaction, and Cardinality — Keep event records useful for diagnosis while controlling data exposure and metric-series growth.
- Incident Containment and Evidence Timeline — Choose a reversible containment action from a coherent timeline of user impact and releases.
Cross-Tab and Offline Data Coordination
Reconcile browser contexts and disconnected edits without mistaking local state for server truth.
- Cross-Tab Invalidation and Version Checks — Use same-origin tab messages to prompt a server read rather than as a durable source of truth.
- Offline Outbox, Idempotency, and Replay — Queue bounded mutations with stable keys and explicit accepted, conflicted, and rejected outcomes.
- Snapshot, Delta Cursor, and Gap Recovery — Combine a consistent snapshot with ordered changes and restart when a replay window is lost.
- Collaborative Conflicts and Presence Expiry — Separate editing presence from durable ownership and resolve concurrent changes at field scope.
Operations and sync practice
Apply the production and data-coordination contracts with Project: case-save incident evidence and Project: multi-tab offline case review.
Authorization and Tenant Boundaries
Enforce each action on its actual record and carry tenant scope through caches, workers, and exports.
- Object-Level Authorization for Reads and Writes — Check actor, action, and current record scope for every read or mutation, including list membership.
- Tenant Scope in Cache and Background Work — Carry verified tenant identity into caches, messages, and workers without accepting a client claim as authority.
- Permission Revocation and Active Sessions — Make role and assignment changes take effect across sessions, caches, live streams, and queued work.
- Private Export Authorization and Artifact Scope — Keep export jobs and download artifacts bound to requester, tenant, filter, and expiry.
Data Retention, Export, and Erasure
Track where private data persists and make export, expiry, and deletion outcomes verifiable.
- Retention Inventory and Expiry Workflows — Map every copy of a private record and make expiry observable across primary and derived stores.
- Export and Erasure Job State — Represent data requests as authorized jobs with terminal evidence and recoverable failure states.
- Backup Restore with Deletion Tombstones — Prevent old snapshots from reviving data that was removed after the backup was taken.
- Browser Storage Cleanup on Account Change — Clear private browser state when identity changes without making client cleanup the only security control.
Authorization and lifecycle practice
Apply the access and data-retention contracts with Project: tenant-safe case export and Project: verified data expiry.
Browser Capabilities and Permission Lifecycle
Request device and sharing capabilities only when a user needs them, then end their use predictably.
- Permission Request Timing and Manual Fallback — Ask for browser access at the point of use and preserve a useful manual path after denial.
- Camera and Microphone Capture and Track Cleanup — Start media capture after intent, stop every track, and separate preview from trusted upload.
- Geolocation Accuracy, Cancellation, and Retention — Use location with a stated purpose, bounded waiting, accuracy context, and minimal retention.
- Clipboard and Share Activation Fallbacks — Handle user activation, capability gaps, and rejected share actions without losing the content.
Overlays, Scroll, and Mobile Viewport
Keep focused controls visible and usable across stacking, nested scrolling, gestures, and keyboards.
- Stacking Context, Top Layer, and Overlay Contract — Choose modal, popover, or inline UI deliberately and avoid z-index fights across ancestors.
- Scroll Containers, Anchoring, and Chaining — Keep content stable and reachable when nested regions scroll or load new material.
- Pointer Gesture, Touch Action, and Alternate Control — Keep custom gestures compatible with browser panning and equivalent button or keyboard actions.
- Visual Viewport, Keyboard, and Focused Input — Keep active inputs and actions reachable when the on-screen keyboard changes visible space.
Capability and viewport practice
Apply the device and mobile interaction contracts with Project: field intake with capability fallbacks and Project: mobile review overlay and scroll.
Accessible Content and Media
Carry image, chart, audio, video, and page structure meaning into equivalent readable paths.
- Image Alternatives by Purpose — Write image alternatives for the task the image performs, including decorative and functional cases.
- Chart and Diagram Text Equivalents — Expose chart values and conclusions as structured text without making color or position the only signal.
- Captions, Transcripts, and Media Controls — Match speech, meaningful sound, and visual action to accessible tracks and usable playback controls.
- Landmarks, Headings, and Skip Paths — Preserve page orientation and bypass routes as client navigation changes content.
Privacy-Aware External Integrations
Inventory third-party requests, gate optional services, minimize events, and honor preference changes.
- Third-Party Request and Script Inventory — Record what external code and embeds receive before deciding whether they belong on a page.
- Optional Analytics Event Boundaries — Separate operational signals from optional measurement and constrain event fields before collection.
- Embedded Widget Storage and Fallback — Design embeds that work when third-party storage is partitioned or unavailable.
- Preference Change Propagation and Audit — Make optional-data choices take effect across tabs, queues, server events, and later sessions.
Accessible content and privacy practice
Apply the content and external-data contracts with Project: accessible inspection report and Project: privacy-safe support and measurement.
Web Push and Notification Delivery
Make opt-in alerts useful, private, revocable, and honest about delivery limits.
- Notification Opt-In and Channel Preference — Ask for alert permission only after a relevant action and keep a usable in-app path after denial.
- Push Subscription Account Binding and Rotation — Bind each endpoint to a verified account and device lifecycle without exposing it as a public identifier.
- Private Notification Payload and Click Routing — Keep lock-screen text minimal and reauthorize the destination when a notification is opened.
- Push Delivery Retries, Expiry, and Inbox Fallback — Model accepted sends separately from device display and keep an authorized durable inbox.
Notification delivery practice
Apply the opt-in and delivery contract with Project: private urgent assignment alerts.
Passkeys and Account Assurance
Register and verify public-key credentials while preserving account recovery and session boundaries.
- Passkey Registration Challenge and Credential Binding — Issue a fresh server challenge and bind the returned public key to the intended signed-in account.
- Passkey Assertion, Origin, and Signature Verification — Verify an assertion against a stored public key and a one-use sign-in challenge before creating a session.
- Passkey Conditional Sign-In and Fallback — Offer passkeys without trapping users whose browser, authenticator, or credential is unavailable.
- Passkey Management, Recovery, and Step-Up — Let users remove lost credentials and require fresh assurance for sensitive account changes.
Checkout and Payment State
Keep amounts server-owned and reconcile provider events before fulfilling an order.
- Server-Priced Order Snapshots and Money Units — Build an immutable order total from trusted catalog data and currency-specific integer units.
- Hosted Checkout Sessions and Browser Returns — Bind a hosted payment attempt to a server order while treating the return page as a status view.
- Payment Webhook Reconciliation and Idempotent Fulfillment — Verify provider events and make order fulfillment safe under retries and out-of-order delivery.
- Refunds, Reversals, and Payment Ledger State — Track partial refunds and disputes as separate money movements with bounded, reconcilable state.
Passkey and checkout practice
Apply the account and payment contracts with Project: passkey account lifecycle and Project: checkout reconciliation.
File Ingestion and Private Asset Lifecycle
Accept files through bounded sessions, verify bytes before release, and recheck access at download.
- Upload Intake Budgets and Storage Ownership — Bound each upload before receiving bytes and keep untrusted objects outside public serving paths.
- Resumable Transfer Parts and Integrity — Track part ownership and verify the completed object rather than trusting a progress bar.
- File Quarantine, Inspection, and Derived Previews — Keep raw uploads private until type checks, scanning, and bounded processing finish.
- Private Asset Downloads, Revocation, and Expiry — Authorize every original and derivative read, then expire grants and storage on policy.
Outbound Email and Delivery State
Queue purpose-limited messages, handle provider feedback, and keep account links short-lived.
- Email Intent, Outbox, and Idempotent Send — Record one message intent with the business event and handle uncertain provider responses.
- Email Template Data and Account Link Boundaries — Render limited message data and keep action links short-lived, single-purpose, and server-verified.
- Email Provider Events, Bounces, and Suppression — Reconcile accepted, delivered, bounced, and complained-about messages without unsafe repeated sends.
- Sender Identity, Reputation, and Message Observability — Configure authenticated sending domains and measure delivery without exposing message content.
File and email practice
Apply the private-asset and delivery contracts with Project: private evidence file lifecycle and Project: account email delivery.
Feature Release and Experiment Controls
Separate deployment, exposure, permission, and measured outcome in controlled web releases.
- Feature Flag Evaluation Scope and Safe Default — Evaluate a named release decision consistently without using it as a data-permission check.
- Gradual Rollout, Kill Switch, and State Compatibility — Expose a release in stages and prove disabling it leaves stored data and sessions usable.
- Experiment Assignment, Exposure, and Metric Integrity — Keep variant assignment, actual exposure, and outcome measurement separate and comparable.
- Flag Telemetry, Audit, and Retirement — Record enough decision evidence to debug a release, then remove temporary branches and rules.
GraphQL Query and Resolver Boundaries
Design typed query contracts while bounding work and checking access in every resolver path.
- GraphQL Schema Nullability and Evolution — Design fields whose absence and failure behavior can change without breaking existing clients.
- GraphQL Resolver Batching and Tenant Scope — Prevent nested field fan-out while keeping request-local caches inside one actor and tenant boundary.
- GraphQL Operation Cost and Admission — Bound depth, breadth, list sizes, and resolver work before executing a client-selected query.
- GraphQL Mutation Errors and Pagination Contracts — Make writes idempotent where needed and distinguish expected outcomes from execution failures.
Release and GraphQL practice
Apply the rollout and query contracts with Project: assignment panel release experiment and Project: tenant-safe GraphQL case API.
WebAssembly and Browser Compute
Ship bounded client-side compute with explicit loading, memory, worker, and fallback contracts.
- Wasm Loading, Artifact, and Fallback Contract — Load a versioned module only when the workflow needs it and retain a usable fallback.
- Wasm Linear Memory, Ownership, and Copy Cost — Make byte ownership, allocation limits, and view invalidation visible at the JavaScript boundary.
- Wasm Worker Jobs, Cancellation, and Result Order — Run expensive modules off the main thread with bounded queues and stale-result protection.
- Wasm Capabilities, Isolation, and Performance Budget — Keep module authority narrow and require measured benefit before adding shared-memory complexity.
WebRTC and Peer Media Sessions
Establish authorized peer sessions while controlling capture, signaling, transport, and teardown.
- Media Capture Consent and Track Lifecycle — Request the minimum camera or microphone capability and release every track on exit.
- WebRTC Signaling, Room Authorization, and Offer Order — Exchange descriptions and candidates through an authorized, ordered room protocol.
- WebRTC ICE, TURN Fallback, and Session Recovery — Budget relay paths, observe connection state, and recover without implying direct connectivity.
- Data Channel Backpressure and Peer State — Bound annotation messages and keep durable case state outside the peer transport.
Browser compute and peer practice
Apply the two tracks with Project: bounded local scan analysis and Project: private peer consultation.
Motion and View Change Contracts
Make animation follow application state, preserve focus, and fit a measured rendering budget.
- CSS Motion State and Interruption — Tie transitions to semantic state and make interruption settle on the current state.
- Web Animations Lifecycle and Cancellation — Own scripted animation handles so retries and component disposal cannot leave stale effects.
- View Transition Navigation, Focus, and Fallback — Treat visual route continuity as an enhancement while preserving navigation and reading position.
- Reduced Motion and Rendering Budget — Replace nonessential travel with stable state cues and verify frame cost on real screens.
Multi-Region Web State and Recovery
Place work across regions without hiding read staleness, write ownership, or recovery loss.
- Regional Routing, Static and Private Cache Boundaries — Serve public assets broadly while keeping authenticated responses tied to their correct owner and region.
- Replica Lag, Read-Your-Write, and Version Cursors — Give recent writes a freshness path instead of pretending all regional replicas are current.
- Regional Failover, Fencing, and Replay — Promote a recovery writer only after old write authority is contained and uncertain work is reconciled.
- Regional Data Location and Operational Evidence — Inventory every place private data, logs, backups, and derived artifacts can reside.
Motion and regional recovery practice
Apply the tracks with Project: case board motion and route continuity and Project: two-region case service recovery.
Interactive Graphics and Canvas Boundaries
Choose a scene model, map coordinates, protect export, and expose graphic meaning beyond pixels.
- SVG, Canvas, Scene Model, and Hit Testing — Choose DOM-backed shapes or a redrawn bitmap from interaction density and semantic needs.
- Canvas Pixel Ratio and Pointer Coordinates — Separate CSS size, backing pixels, and scene space so drawing and hit testing agree.
- Canvas Origin-Clean Export and Private Assets — Prove an image can be read or exported before promising annotated downloads.
- Accessible Graphic Controls and Text Equivalents — Expose graphic relationships and actions through labeled controls and a synchronized text representation.
Rich Document Editing and Safe Content
Keep editable content in a versioned model while handling composition, selection, paste, and undo.
- Editable Input, Composition, and Document Model — Accept browser edits and IME composition without treating the live DOM as the authoritative document.
- Selection Bookmarks and Transaction Mapping — Represent caret and range positions in model coordinates that survive DOM replacement.
- Paste Import, Sanitization, and Link Policy — Convert clipboard fragments into a narrow document schema before they can reach storage or rendered HTML.
- Undo History, Autosave, and Revision Conflicts — Bound local edit history and save a document through conditional revisions without erasing newer work.
Graphic and editor practice
Apply the tracks with Project: accessible inspection map and export and Project: versioned case note editor.
Embedded Interfaces and Cross-Window Contracts
Constrain frames and popups, then exchange small typed messages across explicit origins and lifetimes.
- Frame Sandbox, Capabilities, and Fallback — Give an embedded document only the browser powers its task requires and preserve a non-frame path.
- Cross-Window Messages: Origin, Source, Schema, and Replay — Accept a frame message only from the expected document and only for the current interaction.
- MessageChannel Lifetime and Request Correlation — Use a dedicated port for a bounded conversation and close it when the frame changes or the task ends.
- Popup Handoff, Return, and Window Ownership — Separate a user-initiated external handoff from the server-confirmed result and its fallback route.
Frontend Build and Artifact Integrity
Pin dependency resolution, review install behavior, and deploy a coherent set of hashed assets.
- Locked Dependency Resolution and Clean Installs — Make the reviewed source tree resolve the same package graph in continuous integration.
- Dependency Admission, Install Scripts, and Provenance — Review new package authority and build-time code before it enters the release graph.
- External Asset Integrity and Module Resolution — Pin the browser bytes of external scripts and keep module resolution tied to a reviewed release.
- Artifact Manifest, Rollout, and Rollback Coherence — Promote an immutable frontend artifact with its asset list and keep older documents loadable.
Embedded and build practice
Apply the tracks with Project: embedded attachment viewer contract and Project: frontend artifact promotion and rollback.
Offline Storage and Upgrade Safety
Upgrade workers and local data without discarding unsent work or relying on permanent browser storage.
- Service Worker Activation and Unsent Work — Coordinate a waiting worker with open pages and unsent drafts before changing the fetch controller.
- IndexedDB Version Changes and Blocked Tabs — Migrate local schema only after older connections release it and preserve queued records across the change.
- Browser Storage Quota, Eviction, and Recovery — Budget local data, handle failed writes, and give unsent work an export or server path.
- Private Offline Cache and Account Switch — Keep account-scoped drafts and responses apart, then clear every local view on identity change.
Browser Cryptography and Key Custody
Use browser cryptography only with a stated threat model, unique nonces, and a workable key-recovery policy.
- Browser Encryption Threat Model and Key Custody — Decide what copied storage bytes should resist and who can still use the decryption key.
- Authenticated Encryption, Nonce, and Record Binding — Encrypt a draft with a fresh nonce and bind its ciphertext to the intended record metadata.
- Password Unlock, Derivation, and Recovery — Derive an unlock key with recorded parameters and make forgotten-secret behavior explicit.
- Key Rotation, Envelopes, and Device Loss — Re-encrypt local records under a new key without losing drafts or overstating revocation.
Offline and key custody practice
Apply the tracks with Project: offline case review across upgrades and Project: encrypted local draft lifecycle.
Web Component Contracts and Interoperability
Ship custom elements whose lifecycle, projected content, forms, and styling remain usable across host applications.
- Custom Element Upgrade and Reconnection — Handle pre-definition markup, observed attributes, repeated connection, and host-driven moves without duplicate side effects.
- Shadow Slots, Events, and Focus Contracts — Define projected content ownership, event crossing, and focus behavior at a shadow boundary.
- Form-Associated Custom Controls and Native Fallback — Make a shared decision control submit, validate, reset, and recover with a plain-form path.
- Shadow Style Tokens, Parts, and Shared Sheets — Expose deliberate theme hooks while keeping internal selectors and stylesheet ownership stable.
Progressive Browser Compatibility
Keep a useful task path while adding newer browser capabilities under a measured support policy.
- Feature Probes and Functional Fallbacks — Gate enhancements on actual capabilities while preserving a server-owned completion path.
- Polyfill Cost and Target Browser Policy — Choose supported environments, optional code, and fallback behavior without shipping unused weight to everyone.
- Cross-Browser Input and Device Contracts — Test task completion through keyboard, touch, composition, assistive technology, and low-end hardware.
- Capability Rollout and Fallback Retirement — Release optional browser paths gradually and remove old branches only after task-level evidence.
Component and compatibility practice
Apply the tracks with Project: interoperable case-decision control and Project: progressive case export release.
Background Workflow Reliability
Admit jobs, survive duplicate delivery, isolate poison work, and define cancellation and schedule ownership.
- Job Admission, Idempotency, and Status Resources — Return a durable operation identity and a truthful state when asynchronous work is accepted.
- Worker Leases, Retries, and Duplicate Effects — Assume a queued message can reappear, and protect the business effect before acknowledging it.
- Poison Job Quarantine and Replay Control — Stop a permanently failing job from cycling forever and make repair or replay auditable.
- Scheduled Job Overlap, Cancellation, and Compensation — Define what happens when runs overlap, users cancel, or effects already escaped the system.
Abuse-Resistant Public Endpoints
Bound identity and resource-heavy requests while preserving legitimate access and reviewable decisions.
- Account Recovery Enumeration and Throttle Policy — Bound recovery requests without exposing which identities exist or locking out legitimate owners.
- Expensive Request Work Budgets and Load Shedding — Bound CPU, bytes, fan-out, provider spend, and concurrency before costly work begins.
- Human Challenges, Accessible Alternatives, and Signal Retention — Escalate suspicious actions without making visual puzzles the only route or retaining excessive signals.
- Abuse Decision Telemetry and False-Positive Rollback — Measure defense outcomes and recover legitimate users when a rule blocks the wrong traffic.
Background work and abuse practice
Apply the tracks with Project: permit report job recovery and Project: public permit endpoint abuse controls.
Model-Backed Web Application Boundaries
Control model requests, streamed output, retrieved text, tool actions, and release evidence in web products.
- Model Gateway Identity and Request Budgets — Keep provider credentials on the server and charge model work to an authorized user action.
- Generated Response Streaming and Cancel State — Frame partial output, bound buffers, and make interrupted answers visibly incomplete.
- Retrieved Content, Instructions, and Tool Permission — Keep retrieved text as evidence, not authority to call tools or change permissions.
- Model Output Evaluation and Release Control — Test factual and workflow outcomes before exposing a new model path to everyone.
Model-backed application practice
Apply this track with Project: permission-bound maintenance summary.
On-Demand Media Playback and Delivery
Serve and play large media with coherent seeks, bounded buffers, private asset access, and matching timed text.
- Media Player Source and Load State — Choose a usable source, expose playback failures, and budget eager media loading.
- Media Byte Ranges, Seeking, and Version Identity — Return coherent partial responses so a player can seek without mixing asset revisions.
- Adaptive Media Buffer and Fallback Policy — Bound segment buffering and choose a playable rendition without blocking the whole page.
- Private Media Session, Cache, and Timed Text — Keep clips, segments, captions, and transcripts under one permission and revision policy.
Media playback practice
Apply this track with Project: private inspection clip playback.
Browser Extension Trust and Lifecycle
Build browser helpers with narrow host access, safe page adapters, recoverable events, and checked messages.
- Extension Host Permissions and User Invocation — Give an extension access only to the site and action its user requested.
- Content Script Isolation and DOM Mutation — Read page data as untrusted input and keep extension UI stable as the document changes.
- Extension Background Events and Durable State — Persist task state across worker shutdown and browser restart without replaying effects.
- Extension Message Contracts and Page Data Boundary — Validate messages between the page, content script, background worker, and server.
Browser extension practice
Apply this track with Project: permit checklist browser helper.
Geospatial Web Interfaces and Spatial Queries
Handle coordinate units, viewport tiles, indexed nearby search, and location alternatives in web maps.
- Coordinate Validation, Projection, and the Antimeridian — Keep latitude, longitude, map projection, and geographic distance in their own units.
- Map Viewport Tiles and Request Lifecycle — Load only visible map work and stop stale requests when the viewport changes.
- Nearby Spatial Search and Tenant Filter — Use indexed candidate selection, exact distance checks, and authorization in one query contract.
- Location Consent, Precision, and Map Alternatives — Ask for device location only when useful and keep a keyboard-ready list route.
Geospatial practice
Apply this track with Project: authorized facility map and nearby search.
Federated Identity and Session Lifecycle
Bind provider callbacks, verify identity, renew sessions, and control account links and logout.
- Authorization Code, PKCE, and Callback Binding — Bind each authorization response to its initiating browser session and one-use code verifier.
- ID Token Verification and Stable Account Identity — Verify signed identity claims and key local accounts by issuer plus subject, not mutable email.
- Refresh Token Rotation and App Session Boundary — Keep external token renewal separate from revocable browser sessions and handle rotation races.
- Federated Account Linking, Logout, and Revocation — Require an explicit signed-in linking ceremony and distinguish local logout from provider logout.
Federated identity practice
Project: federated permit reviewer sign-in; Web Development: federated identity and session contracts quiz.
API Contract Evolution and Client Migration
Change wire shapes, select versions, retire old routes, and test every supported client across rollout phases.
- Response Shape Evolution and Unknown Values — Change response fields and enums while old clients, cached bundles, and offline requests still exist.
- API Version Selection and Representation Scope — Version incompatible representations explicitly and keep selection consistent across caches and links.
- Deprecation, Sunset, and Consumer Evidence — Retire an API only after identifying consumers, communicating dates, and testing a safe shutdown.
- Consumer Contract Matrix and Expand-Contract Release — Run old and new clients against intermediate server states before deleting old fields or routes.
API migration practice
Project: permit API client migration; Web Development: API contract migration quiz.
Edge Runtime and Origin Boundaries
Control request trust, runtime budgets, cache locality, and write consistency between edge and origin.
- Edge Request Normalization and Origin Trust — Define which request metadata an edge layer may trust before forwarding to the application origin.
- Edge Compute Budgets and Upstream Fanout — Bound CPU, memory, upstream calls, and deadlines before moving request work closer to users.
- Edge Cache Locality, Invalidation, and Private Scope — Treat cache entries as location-bound copies with explicit key dimensions and invalidation limits.
- Edge-to-Origin Write Routing and Consistency — Keep writes authoritative and define read-after-write behavior when edge locations and replicas lag.
Edge and origin practice
Project: edge permit case delivery; Web Development: edge and origin contracts quiz.
Realtime Connection and Event Delivery
Operate authorized live channels with replay, bounded fanout, presence expiry, and deploy-safe reconnects.
- WebSocket Handshake, Session, and Channel Authorization — Check browser origin, session identity, and each private channel throughout a long-lived connection.
- Event Sequence, Replay, and Gap Reconciliation — Use durable event identity and snapshots to recover after reconnects without double-applying case changes.
- Socket Fanout, Backpressure, and Slow Consumers — Bound queued bytes and per-connection work when one client cannot keep up with a busy channel.
- Presence Expiry, Heartbeats, and Connection Drain — Treat online status as expiring evidence and release sockets cleanly during idle periods and deployments.
Realtime delivery practice
Project: live permit case board; Web Development: realtime delivery contracts quiz.
Network Transport and Domain Operations
Plan DNS changes, rotate TLS safely, verify HTTP/3 fallback, and reject replayable state changes.
- DNS TTL, Negative Cache, and Cutover Planning — Plan domain changes around cached positive and negative answers, not a single control-plane update.
- TLS Certificate Rotation and HSTS Scope — Renew certificates before expiry and apply HTTPS-only policy only across hosts that can sustain it.
- HTTP/2, HTTP/3 Negotiation, and Fallback Testing — Measure protocol choice and graceful fallback across browsers, proxies, and blocked network paths.
- Early Data Replay and Safe Request Admission — Keep state-changing requests out of replayable early data and bind retries to idempotent operations.
Network transport practice
Project: permit domain cutover and transport recovery; Web Development: network transport operations quiz.
Database Capacity and Online Change Operations
Budget database connections, retry conflicts safely, backfill live data, and release indexes with measured gates.
- Connection Pool Budgets and Queue Admission — Budget connections across application instances and bound waiting before the database reaches its limit.
- Transaction Retry, Deadlock, and Side-Effect Boundaries — Retry the complete database transaction after a retryable conflict without repeating external effects.
- Resumable Data Backfills and Reconciliation — Move old rows to a new representation in bounded chunks while concurrent writes continue.
- Online Index Builds and Query Plan Release Gates — Stage large index changes with write-availability checks, validity checks, and measured query plans.
Database operations practice
Project: permit data change under live traffic; Web Development: database online operations quiz.
Application Cache Consistency and Capacity
Keep application-data caches useful without stale overwrites, miss storms, memory collapse, or false absence.
- Cache-Aside Fill Races and Version Guards — Prevent an old cache fill from replacing a newer database result after a concurrent write.
- Cache Stampede, Singleflight, and Hot-Key Budgets — Bound source load when a popular cache entry expires or vanishes across many application instances.
- Cache Memory, Eviction, and Degraded Read Paths — Treat cache capacity and eviction policy as load-control decisions with a tested source fallback.
- Negative Cache Entries and Stale-Read Contracts — Cache absence and old values only when their user-visible meaning and maximum age are explicit.
Application cache practice
Project: permit cache recovery and consistency; Web Development: application cache contracts quiz.
Ingress Proxy and Upstream Contracts
Trust proxy metadata narrowly, route only known hosts, drain healthy nodes safely, and bound body and retry work.
- Trusted Proxy Hops and Forwarded Client Identity — Accept client address and scheme metadata only from an authenticated, known proxy path.
- Host Authority Routing and Default Deny — Bind hostnames, TLS names, and application routes without sending unknown authorities to a privileged default.
- Ingress Health, Readiness, and Connection Drain — Distinguish process liveness from traffic readiness and drain long-lived requests during rollout.
- Proxy Body Budgets, Timeouts, and Retry Ownership — Align ingress limits with application deadlines and prevent ambiguous retries of side-effecting requests.
Ingress rollout practice
Project: permit ingress cutover and safe retry; Web Development: ingress and upstream contracts quiz.
Browser Performance Diagnosis and Measurement
Measure browser timing, slow interactions, retained views, and render cost with explicit evidence.
- Field Performance Observation and Sample Contracts — Collect browser timing entries with explicit support, sampling, privacy, and interpretation rules.
- Interaction Latency Traces and Main-Thread Contention — Break a slow interaction into queueing, handler, and presentation time before changing code.
- Retained DOM Memory and Lifecycle Investigation — Find roots retaining removed views and verify that cleanup survives repeated route cycles.
- Layout, Paint Regressions, and Containment Decisions — Measure render work caused by DOM changes before applying containment or batching reads and writes.
Browser diagnosis practice
Project: permit browser regression investigation; Web Development: browser performance diagnosis quiz.
React State and Rendering Boundaries
Own component state by entity, derive render data, schedule slow updates, and keep hydration stable.
- React Component Identity and Keyed Draft Lifetime — Choose stable component keys according to the lifetime of a user's draft, not list position.
- React Derived State and Event Ownership — Calculate render data from current inputs and put user-command effects in their event path.
- React Urgent Input and Transition Work — Keep the input controlled with an urgent update while allowing an expensive result view to lag safely.
- React Hydration and Stable First Render — Make server markup and the first client render agree before using browser-only data.
React rendering practice
Project: React permit review queue state; Web Development: React state and rendering quiz.
Vue Reactivity and Component Boundaries
Own reactive sources, cancel stale work, protect component contracts, and preserve server/client agreement.
- Vue Source State, Computed Views, and Large Snapshots — Keep one reactive source of truth, derive views with computed values, and bound large immutable data costs.
- Vue Watch Cleanup and Stale Request Ownership — Attach each fetch to the watched identity and cancel or reject work when that identity changes.
- Vue Props, Emits, and Keyed Editor Ownership — Keep parent-owned records immutable to children and make draft lifetime follow a case identity.
- Vue Server Rendering and Hydration Stability — Keep per-request state isolated and make the first browser render agree with server HTML.
Vue state practice
Project: Vue permit review queue; Web Development: Vue reactivity and boundaries quiz.
Angular Signals and Delivery Boundaries
Use signal state, stable component identity, safe HTTP streams, and request-scoped hydration contracts.
- Angular Signal Sources, Computed Views, and Effect Scope — Derive queue views from source signals and reserve effects for external systems with cleanup.
- Angular Component Input, Output, and Row Identity — Keep records parent-owned, emit commands from children, and track repeated rows by immutable identity.
- Angular HttpClient Streams and Stale Detail Requests — Switch detail reads with selection identity and keep mutation retries out of a broad interceptor.
- Angular SSR Hydration and Private Transfer State — Preserve server/client DOM agreement while isolating user-specific data and transfer caches.
Angular operations practice
Project: Angular permit operations queue; Web Development: Angular signals and delivery quiz.
Svelte Reactivity and Server Boundaries
Use Svelte runes, stable component identity, server form actions, and request-owned page data.
- Svelte Runes: Source State, Derived Views, and Effect Cleanup — Keep editable state distinct from derived queue views and reserve effects for external work.
- Svelte Props, Callbacks, and Keyed Editor Ownership — Declare component commands as callbacks and keep private drafts attached to stable records.
- SvelteKit Form Actions, Validation, and Mutation Replay — Keep a normal POST form usable without script and bind approval to server-side identity and operation rules.
- SvelteKit Request-Scoped Load and Hydration State — Pass authorized server data through a request-owned load result and preserve a stable first browser view.
Svelte review practice
Project: Svelte permit review and approval action; Web Development: Svelte reactivity and server boundaries quiz.
Next.js App Router Delivery Boundaries
Own client transfer, private cache freshness, mutation replay, and streamed failure boundaries.
- Next.js Server and Client Component Data Boundary — Keep private reads on the server and send a small, serializable interaction model to the browser.
- Next.js Cache Scope and Private Read Invalidation — Separate public reusable data from viewer-specific reads and verify freshness after a mutation.
- Next.js Server Functions, Validation, and Operation Identity — Treat a server function as a public mutation entry point with permission and replay controls.
- Next.js Streaming, Suspense, and Error Recovery — Place slow data behind a meaningful fallback while keeping failures and private payloads within scope.
Next.js delivery practice
Project: Next.js permit delivery and cache boundary; Web Development: Next.js App Router boundaries quiz.
Express Request and Process Boundaries
Build Express 5 APIs with ordered trust checks, honest errors, bounded request work, and drain behavior.
- Express Middleware Order and Request Identity — Place parsing, authentication, authorization, routing, and errors in an intentional request sequence.
- Express 5 Async Errors and Response Contracts — Route rejected promises once and distinguish validation, conflict, and internal failures.
- Node Request Budgets, Abort, and Event Loop Fairness — Bound input and work so one slow or hostile request does not stall unrelated traffic.
- Node HTTP Drain, Readiness, and Graceful Shutdown — Stop admitting new work, finish bounded requests, and close resources under a shutdown deadline.
Express request practice
Project: Express permit API lifecycle; Web Development: Express request and process quiz.
Django Request and Persistence Boundaries
Build Django request paths with exact permissions, bounded ORM reads, safe browser commands, and async boundaries.
- Django Middleware, Sessions, and Object Permissions — Separate request-wide identity setup from the permission decision for one database row.
- Django QuerySet Shape, Prefetch, and Page Cost — Bound query count, transferred columns, page width, and relation loading for a case list.
- Django Forms, CSRF, Atomic Approval, and On-Commit Work — Validate a browser command, commit one state change, and dispatch side effects after commit.
- Django ASGI, Async Views, and the Sync ORM Boundary — Use asynchronous views where waiting overlaps, while keeping transactional database work synchronous.
Django request practice
Project: Django permit review service; Web Development: Django request and persistence quiz.
FastAPI Contract and Resource Boundaries
Build FastAPI services with explicit object permission, narrow contracts, bounded sessions, and recoverable delivery.
- FastAPI Dependencies and Object Authorization — Resolve identity once, then authorize the exact resource at the service boundary.
- FastAPI Input, Output, and Error Contracts — Give commands strict input models and return only fields admitted by a public response model.
- FastAPI Async Sessions and Transaction Ownership — Give each request a bounded session and keep one command inside one explicit transaction.
- FastAPI Lifespan, Background Work, and Delivery State — Own shared clients during application lifespan and record critical jobs before returning success.
FastAPI service practice
Project: FastAPI permit service boundaries; Web Development: FastAPI contract and resource quiz.
Laravel Policy, Query, and Queue Boundaries
Build Laravel permit services with model policy checks, bounded Eloquent reads, replay-safe writes, and recoverable jobs.
- Laravel Route Binding, Policy, and Private Resource Scope — Treat route binding as lookup, then evaluate permission for the resolved case and every write.
- Laravel Eloquent Loading and Cursor Page Cost — Shape a reviewer queue with scoped SQL, needed relations, stable order, and bounded pages.
- Laravel Form Requests, Transactions, and Approval Replay — Validate a browser command, lock current state, commit once, and recover an ambiguous retry.
- Laravel After-Commit Jobs and Outbox Recovery — Dispatch after database commit while retaining durable intent when a queue hint is lost.
Laravel workflow practice
Project: Laravel permit review workflow; Web Development: Laravel policy, query, and queue quiz.
Flask Context and Service Boundaries
Build Flask permit services with explicit request context, bounded SQL, replay-safe writes, and durable background work.
- Flask Request Context and Object Authorization — Extract a caller identity during the request, then check the exact permit before returning fields.
- Flask-SQLAlchemy Session and Query Lifetime — Bound queue reads, avoid relation N+1 work, and return plain values before the app context ends.
- Flask Command Validation and Transaction Replay — Separate HTTP parsing, browser CSRF, case permission, and one committed approval outcome.
- Flask Async Views and Durable Background Work — Use async for awaited I/O inside a request, then persist work that must survive the response.
Flask service practice
Project: Flask permit service boundaries; Web Development: Flask context and service boundaries quiz.
Rails Request, Record, and Job Boundaries
Build Rails permit services with scoped controllers, bounded Active Record reads, replay-safe transactions, and recoverable jobs.
- Rails Controller Parameters and Object Permission — Permit command fields narrowly, then authorize the exact case before projecting a response.
- Rails Active Record Scope, Eager Load, and Page Cost — Scope and bound a review queue, load only displayed relations, and preserve a deterministic order.
- Rails Locking, Transaction, and Command Replay — Lock current case state, commit one approval result, and recover a lost response by operation ID.
- Rails Active Job After-Commit and Outbox Recovery — Delay worker visibility until commit and retain intent when the enqueue handoff fails.
Rails workflow practice
Project: Rails permit review workflow; Web Development: Rails request, record, and job quiz.
CMS Content, Publication, and Preview Boundaries
Keep public content, editor previews, media versions, and publication projections on explicit boundaries.
- CMS Public Projections and Route Identity — Expose only published fields through stable route identities and explicit response contracts.
- CMS Draft Preview Authorization and Cache Isolation — Bind preview access to a caller and revision while preventing private responses from reaching shared caches.
- CMS Media Variants, Alt Text, and Asset Ownership — Publish bounded media metadata with stable assets, useful alternatives, and deliberate retention.
- CMS Publish Events, Cache, Search, and Rollback — Reconcile a publication revision across routes, caches, search, and linked navigation.
CMS publication practice
Project: CMS Publication Reconciliation; Web Development: CMS publication contracts.
Spring Boot Web Service Boundaries
Build Spring Boot permit services with precise permission, validated contracts, bounded JPA reads, and recoverable writes.
- Spring Boot Security Chain and Object Permission — Authenticate at the request boundary and authorize the exact permit again at the service boundary.
- Spring Boot MVC Validation and Problem Contracts — Validate an approval command at the HTTP edge and return stable, bounded error information.
- Spring Boot JPA Scope, Fetch, and Page Cost — Constrain reviewer visibility in SQL, fetch displayed relations, and bound each page.
- Spring Boot Transaction Replay and Outbox Handoff — Commit an approval once, recover ambiguous retries, and retain notification intent after a lost enqueue.
Spring Boot service practice
Project: Spring Boot Permit Service Boundaries; Web Development: Spring Boot service contracts.
Native Node HTTP and Runtime Boundaries
Bound request bytes, response flow, CPU work, and outbound calls beneath server frameworks.
- Node Incoming Body Limits and Abort State — Enforce wire-byte and parse budgets before an HTTP request becomes a domain command.
- Node Response Backpressure and Export Aborts — Couple export production to a slow response consumer and stop work when the client disconnects.
- Node CPU Work, Worker Pools, and Event Loop Delay — Move bounded CPU tasks off the request loop without creating an unbounded worker queue.
- Node Outbound Fetch Deadlines and Response Ownership — Give each upstream call a deadline, size budget, and response owner before composing an API reply.
Native Node HTTP and Runtime Boundaries practice
Project: Native Node Permit Gateway; Web Development: Native Node Runtime Contracts.
PHP Request, Session, and Persistence Boundaries
Control PHP input, session identity, database writes, and upload ownership under any framework.
- PHP Superglobal Input and Output Trust — Convert request globals into typed commands and escape only at the output context.
- PHP Session Rotation, Locking, and Logout — Treat the session cookie as an identity pointer with explicit rotation, release, and revocation.
- PHP PDO Transactions, Replay, and Query Identity — Bind query values and keep a replay key, version check, and outbox intent in one transaction.
- PHP Upload Tempfiles, Private Storage, and Lifecycle — Validate the upload error and actual bytes before moving a temporary file into private ownership.
PHP Request, Session, and Persistence Boundaries practice
Project: PHP Permit Review Intake; Web Development: PHP Request Contracts.
