Knowledgebase

Backend Development: Everything That Matters, Briefly Print

  • backenddevelopment, backend, performance, errors, permissions, guide, howto, solution
  • 0

The whole category in one page.

THE CLIENT IS UNDER THE USER'S CONTROL

Prices, permissions, validation and secrets belong on the server. Never trust identifiers, totals or hidden fields from a request.

THE COMMONEST SERIOUS VULNERABILITY IN CUSTOM APPLICATIONS

Authentication checked, authorisation not. A valid session used to request another user's record by changing an identifier.

Verify entitlement to the specific record on every action.

THE COMMONEST PERFORMANCE FAULT, IN EVERY LANGUAGE AND EVERY ORM

A query per item inside a loop. Fetch related data in advance, and monitor query count per request during development.

Nothing else reveals it.

MOVE ANYTHING SLOW OUT OF THE REQUEST, AND MAKE IT SAFE TO RUN TWICE

Retries happen, and duplicates otherwise result. Alert when a scheduled job does not run, or it fails silently for months.

SET TIMEOUTS ON EVERYTHING EXTERNAL

A hanging dependency otherwise exhausts your capacity.

VALIDATE CONFIGURATION AT STARTUP AND FAIL CLEARLY

And rotate any secret that was ever committed — it remains in history.

DISTRIBUTED ARCHITECTURE IS A COST, NOT A GOAL

Start with a well-structured single application. Boundaries are discovered by building, and splitting on the wrong ones is far worse than not splitting.

WHATEVER THE STACK, THE PRINCIPLES TRANSFER

Syntax and tooling differ. Validation, authorisation, error handling, logging and deployment discipline do not.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot