What Express is actually for
Routing, middleware and a response helper. Once you have written the raw version you can see exactly which three problems the framework solves.
Express is three ideas. A router that turns a method and a path pattern into a function call with params extracted. A middleware chain, where each function gets the request, the response and a next() it may or may not call. And a set of response helpers so you stop hand-writing content-type headers.
The middleware chain is the one worth understanding properly, because it is the shape most backend frameworks converge on regardless of language. Every request walks the same list in order: log it, parse the body, authenticate, authorise, handle. Anything that does not call next() ends the request there, which is exactly how auth rejection works, not a special mechanism, just a function that responds instead of continuing.
Order is therefore semantic. Auth middleware registered after the route it protects does nothing at all, and the route will happily serve strangers while looking correct in review. This is a real bug class, it is invisible in a diff that only shows the new route, and it is the reason mounting order deserves a comment.
You should now be able to
- Explain middleware as a chain of functions over one request
- Identify which parts of Express are convenience and which are structure
- Order middleware deliberately rather than by accident
Loading…