Node.js Backend Basics · Course lab · about 300 minutes · 6 tasks · marked out of 100, pass at 60
A students API with a database, auth and a public URL
The situation
Build the API a small academy's app would talk to: students and their enrolments, designed on paper first, stored in MongoDB, protected by JWT auth with an admin role, deployed to a free host, and documented so a front-end developer could use it without asking you anything. Every status code is tested by hand.
What you'll be able to show
- Design endpoints on paper with methods, paths, inputs, outputs and status codes
- Replace an in-memory array with a real database and let the schema reject bad data
- Add registration, login, a JWT and role-based protection
- Deploy with secrets in environment variables and document every endpoint
What you need
- Node, Express, Mongoose, bcrypt, jsonwebtoken
- A MongoDB Atlas free cluster
- Postman or curl, and a free host (Render or Railway)
Tasks
-
1Design on paperWrite every endpoint for students and enrolments: method, path, what it accepts, what it returns, which status codes it can produce. Check against the rules: nouns not verbs, one error shape, pagination on lists, validation on every input.A correct result: A table of endpoints that passes the four rules.
-
2In memory firstImplement the students routes against an array: GET list, GET one (404 if absent), POST create (201; 400 on missing name), PUT, DELETE. Test every route and every status code with Postman or curl and record the results.A correct result: A results table: every route, every status code, observed.
-
3The databaseReplace the array with MongoDB: Atlas cluster, connection string in .env (gitignored), a Mongoose Student schema with required fields and a unique regNo. Break it deliberately: POST a student with no name and confirm the schema rejects it before the database is touched.A correct result: The five routes working against Atlas; the no-name POST refused with a 400.
-
4Auth and rolesPOST /register (bcrypt, duplicate emails refused), POST /login (a JWT that expires), a requireAuth middleware, and protection so listing students needs a login and deleting one needs an admin role. Paste your token into jwt.io and read its payload.A correct result: 401 without a token, 403 for a non-admin delete, and the payload you read from the token.
-
5DeployDeploy to a free host with the database on Atlas and every secret set in the host's environment variables. Point a small page at it that logs in and lists students.A correct result: A public URL where login and list work from a browser page.
-
6Document, and what brokeWrite the README documenting every endpoint with an example request and response. Then list everything that broke during deployment and how you fixed each — that list is what interviews ask about.A correct result: A README a stranger could use, and the what-broke list.
What to hand in
The repo URL, the live API URL, the status-code test table, the jwt.io payload screenshot, and the README with the what-broke list.
How it is marked
| Criterion | Points |
|---|---|
| Paper design passes the four rules | 15 |
| Every route and status code tested and recorded | 15 |
| Database in place and the schema rejects bad data | 20 |
| Auth, JWT expiry and role protection work with 401/403 observed | 25 |
| Deployed with secrets in environment variables | 15 |
| README usable by a stranger, with the what-broke list | 10 |
| Total · pass at 60 | 100 |
صورتحال
وہ API بنائیں جس سے ایک چھوٹی academy کی app بات کرے: students اور ان کے enrolments، پہلے کاغذ پر design کیے ہوئے، MongoDB میں محفوظ، admin role کے ساتھ JWT auth سے محفوظ، ایک مفت host پر deploy شدہ، اور اس طرح documented کہ کوئی front-end developer آپ سے کچھ پوچھے بغیر استعمال کر سکے۔ ہر status code ہاتھ سے آزمایا ہوا۔
آپ کیا دکھا سکیں گے
- کاغذ پر methods، paths، inputs، outputs اور status codes کے ساتھ endpoints design کرنا
- in-memory array کی جگہ حقیقی database لانا اور schema کو غلط data رد کرنے دینا
- registration، login، ایک JWT اور role پر مبنی حفاظت شامل کرنا
- environment variables میں secrets کے ساتھ deploy کرنا اور ہر endpoint document کرنا
آپ کو کیا چاہیے
- Node، Express، Mongoose، bcrypt، jsonwebtoken
- ایک MongoDB Atlas free cluster
- Postman یا curl، اور ایک مفت host (Render یا Railway)
کام
-
1کاغذ پر designstudents اور enrolments کا ہر endpoint لکھیں: method، path، کیا قبول کرتا ہے، کیا واپس کرتا ہے، کون سے status codes دے سکتا ہے۔ اصولوں پر پرکھیں: nouns نہ کہ verbs، error کی ایک شکل، فہرستوں پر pagination، ہر input پر validation۔درست نتیجہ: endpoints کی ایسی table جو چاروں اصولوں پر پوری اترے۔
-
2پہلے memory میںstudents کے routes ایک array پر implement کریں: GET list، GET one (غائب ہو تو 404)، POST create (201؛ نام غائب ہو تو 400)، PUT، DELETE۔ ہر route اور ہر status code Postman یا curl سے آزمائیں اور نتائج لکھیں۔درست نتیجہ: نتائج کی table: ہر route، ہر status code، مشاہدہ شدہ۔
-
3databasearray کی جگہ MongoDB لگائیں: Atlas cluster، .env میں connection string (gitignore میں)، required fields اور unique regNo والا Mongoose Student schema۔ جان بوجھ کر توڑیں: بغیر نام کے student POST کریں اور تصدیق کریں کہ database کو چھونے سے پہلے schema اسے رد کرتا ہے۔درست نتیجہ: پانچوں routes Atlas پر کام کریں؛ بغیر نام کا POST 400 سے رد ہو۔
-
4auth اور rolesPOST /register (bcrypt، duplicate emails رد)، POST /login (ایک JWT جو expire ہو)، ایک requireAuth middleware، اور ایسی حفاظت کہ students کی فہرست کے لیے login چاہیے اور delete کے لیے admin role۔ اپنا token jwt.io میں paste کر کے اس کا payload پڑھیں۔درست نتیجہ: token کے بغیر 401، غیر-admin delete پر 403، اور token سے پڑھا ہوا payload۔
-
5deployکسی مفت host پر deploy کریں، database Atlas پر اور ہر secret host کے environment variables میں۔ ایک چھوٹا page اس کی طرف کریں جو login کرے اور students کی فہرست دکھائے۔درست نتیجہ: ایک public URL جہاں browser page سے login اور فہرست کام کریں۔
-
6document کریں، اور کیا ٹوٹاہر endpoint کو مثالی request اور response کے ساتھ document کرتا README لکھیں۔ پھر وہ سب کچھ لکھیں جو deployment کے دوران ٹوٹا اور آپ نے ہر ایک کو کیسے ٹھیک کیا — یہی فہرست interviews میں پوچھی جاتی ہے۔درست نتیجہ: ایسا README جو اجنبی استعمال کر سکے، اور کیا-ٹوٹا کی فہرست۔
کیا جمع کروانا ہے
repo کا URL، live API کا URL، status-code کے test کی table، jwt.io payload کا screenshot، اور کیا-ٹوٹا کی فہرست کے ساتھ README۔
نمبر کیسے ملیں گے
| معیار | نمبر |
|---|---|
| کاغذی design چاروں اصولوں پر پورا اترتا ہے | 15 |
| ہر route اور status code آزمایا اور درج کیا گیا | 15 |
| database موجود اور schema غلط data رد کرتا ہے | 20 |
| auth، JWT expiry اور role کی حفاظت 401/403 کے مشاہدے کے ساتھ کام کرتی ہے | 25 |
| environment variables میں secrets کے ساتھ deploy ہوا | 15 |
| README اجنبی کے استعمال کے قابل، کیا-ٹوٹا کی فہرست کے ساتھ | 10 |
| کل · پاس 60 | 100 |
Hand in your lab
Create a free BvLogic ID to hand in your lab, get it marked, and have it on your certificate.
Create your BvLogic IDAlready have one? Sign in and this course will be added to it.