Phase 5Days 52-63

Node + Express + REST APIs

Build production-shaped backends

Phase Goal

Build a production-shaped REST API with validation, file uploads, caching, rate limiting, structured logging, proper error handling — and both manual (Postman) and automated (Vitest + Supertest) tests.

Progress
Notes

Open the written lectures for this course before checking off the phase topics.

Projects
Museum Collection API (rehearsal)
Food-Safety Inspection API — DEPLOYED & TESTED

Day 52: Node, Modules, Package Managers

Day 53: Env, CLI, Dev Loops

Day 54: Express Basics

Day 55: Middleware & Error Handling

Day 56: REST API Design

Day 57: Validation with Zod

Day 58: File Uploads

Day 59: Security Baseline

Day 60: Structured Logging — Pino

Day 61: API Testing — Manual + Automated

Day 62: Production API Design Review

Project
Museum Collection API (rehearsal)

Production-shaped Express rehearsal build. Zod-validated, rate-limited, cached, logged, and structured for attachment uploads. Day 63 transfers the architecture to the different users, resources, states, and disclosure rules of food-safety inspections.

Day 63: Project — Food-Safety Inspection API

Capstone
Food-Safety Inspection API — DEPLOYED & TESTED

Build an API for registering establishments, recording checklist findings and evidence, and moving inspections through explicit review states. Use Node, Express, TypeScript, Zod, Pino, and Vitest/Supertest; expose separate public/internal views, structured audit events, rate limits, and OpenAPI-backed documentation.

  • Public incident feed with severity, affected service, timeline entries, and clear status transitions.
  • Internal authenticated update endpoint with Zod validation, request IDs, structured logs, and rate limits.
  • OpenAPI documentation, integration tests, and a deployed health endpoint.

Phase Complete!

After this phase, you'll be able to:

  • Express + TypeScript with proper middleware patterns
  • REST API design: status codes, pagination, caching (ETag/Cache-Control), versioning
  • Zod validation everywhere
  • File uploads via Multer + Cloudinary
  • Helmet, CORS, rate limiting, OWASP awareness
  • Pino structured logs with request IDs
  • Manual (Postman/Newman) AND automated (Vitest + Supertest) API tests

You can ship a real, tested API to production. Time to give it a database — two of them.