Node.js Backend Basics · Course lab · about 300 minutes · 6 tasks · marked out of 100, pass at 60

A students API with a database, auth and a public URL

The situation

Build the API a small academy's app would talk to: students and their enrolments, designed on paper first, stored in MongoDB, protected by JWT auth with an admin role, deployed to a free host, and documented so a front-end developer could use it without asking you anything. Every status code is tested by hand.

What you'll be able to show

  • Design endpoints on paper with methods, paths, inputs, outputs and status codes
  • Replace an in-memory array with a real database and let the schema reject bad data
  • Add registration, login, a JWT and role-based protection
  • Deploy with secrets in environment variables and document every endpoint

What you need

  • Node, Express, Mongoose, bcrypt, jsonwebtoken
  • A MongoDB Atlas free cluster
  • Postman or curl, and a free host (Render or Railway)

Tasks

  1. 1Design on paper
    Write every endpoint for students and enrolments: method, path, what it accepts, what it returns, which status codes it can produce. Check against the rules: nouns not verbs, one error shape, pagination on lists, validation on every input.
    A correct result: A table of endpoints that passes the four rules.
  2. 2In memory first
    Implement the students routes against an array: GET list, GET one (404 if absent), POST create (201; 400 on missing name), PUT, DELETE. Test every route and every status code with Postman or curl and record the results.
    A correct result: A results table: every route, every status code, observed.
  3. 3The database
    Replace the array with MongoDB: Atlas cluster, connection string in .env (gitignored), a Mongoose Student schema with required fields and a unique regNo. Break it deliberately: POST a student with no name and confirm the schema rejects it before the database is touched.
    A correct result: The five routes working against Atlas; the no-name POST refused with a 400.
  4. 4Auth and roles
    POST /register (bcrypt, duplicate emails refused), POST /login (a JWT that expires), a requireAuth middleware, and protection so listing students needs a login and deleting one needs an admin role. Paste your token into jwt.io and read its payload.
    A correct result: 401 without a token, 403 for a non-admin delete, and the payload you read from the token.
  5. 5Deploy
    Deploy to a free host with the database on Atlas and every secret set in the host's environment variables. Point a small page at it that logs in and lists students.
    A correct result: A public URL where login and list work from a browser page.
  6. 6Document, and what broke
    Write the README documenting every endpoint with an example request and response. Then list everything that broke during deployment and how you fixed each — that list is what interviews ask about.
    A correct result: A README a stranger could use, and the what-broke list.

What to hand in

The repo URL, the live API URL, the status-code test table, the jwt.io payload screenshot, and the README with the what-broke list.

How it is marked

CriterionPoints
Paper design passes the four rules 15
Every route and status code tested and recorded 15
Database in place and the schema rejects bad data 20
Auth, JWT expiry and role protection work with 401/403 observed 25
Deployed with secrets in environment variables 15
README usable by a stranger, with the what-broke list 10
Total · pass at 60 100

Hand in your lab

Create a free BvLogic ID to hand in your lab, get it marked, and have it on your certificate.

Create your BvLogic ID

Already have one? Sign in and this course will be added to it.