Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Milecia McGregor

Rating No ratings yet

As a working software developer, you know how to complete your tasks with solid code, whether it's on the frontend or backend. Now you're ready to move to the next level in your career, and you need to understand the subtle yet deep skills it takes to become a senior developer. This practical book shows you everything it takes to create a full-stack web application hosted on a cloud platform. Senior staff engineer Milecia McGregor helps you see how the whole system works and how senior developers arrive at technical decisions. You'll learn about design and development principles and when to apply them. You'll also discover strategies for working with different teams and understand how the product team makes its decisions. In four parts, this book shows you how to: Translate designs into tasks and learn the questions you'll need to ask the product team Walk through development considerations for the backend like overall architecture, security, and...

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# Full Stack JavaScript Strategies ## 【One-Line Pitch】 A practical, senior-level guide to building and shipping full-stack JavaScript applications on cloud platforms—covering everything from translating product designs into engineering tasks to handling incidents in production. Ideal for mid-level developers ready to level up their architectural thinking and cross-team collaboration skills. ## 【Book Arc】 - **Opening (~0%–10%)**: Sets the stage for what it means to be a senior full-stack developer, starting with the critical skill of translating product designs into actionable engineering tasks—including the long list of clarifying questions you need to ask the product team before writing any code. - **Early (~10%–23%)**: Walks through backend development fundamentals: choosing between REST and GraphQL, setting up a NestJS backend with Prisma for database schema management, and understanding how to structure data boundaries and security enforcement on the server side. - **Early (~23%–32%)**: Covers backend testing with Jest, the importance of mock data, and then pivots to security—including the OWASP Top 10 vulnerabilities, threat modeling, and why keeping packages updated is a security practice, not just maintenance. - **Middle (~32%–42%)**: Moves into operational concerns: logging for debugging, caching strategies (including cache poisoning risks), and a detailed walkthrough of incident response—from determining impact and severity to notifying users and delegating responsibilities across teams. - **Middle (~42%–48%)**: Shifts to frontend architecture: modular component design, separation of concerns, single responsibility principles, and working with design teams to establish shared component standards and terminology. - **Late (~48%+)**: Covers project documentation practices like READMEs and CHANGELOGs, then dives into React fundamentals—starting with the useState hook and component state management. ## 【Key Takeaways】 - **Asking the right questions before coding is a senior skill** (Opening): The book provides an extensive checklist—user permissions, data display ranges, input validation, error handling, mobile responsiveness, compliance requirements—and emphasizes prioritizing these questions per feature rather than trying to answer everything at once. - **The backend must enforce security, not the frontend** (Early): Users can bypass the UI and hit endpoints directly, so data boundaries and security checks belong on the server. The frontend can add some protection, but it's never the source of truth for security. - **Background jobs and cron jobs solve different problems** (Early): Background jobs run alongside your app and are triggered by endpoint calls (like sending emails after updates), while cron jobs run on schedules (like syncing third-party data). Cron jobs are better hosted outside your main application to avoid consuming app resources. - **Tests are a collaboration tool with the Product team** (Early): Writing tests surfaces detailed questions about expected functionality, making them a way to clarify requirements—not just a code quality practice. Mock data should mirror your database seed data and stay updated with schema changes. - **Threat modeling follows a simple four-step process** (Early): For any feature, ask: What are we building? What can go wrong? How will we handle it? Did we address concerns well enough? This structured approach catches design-level vulnerabilities before they ship. - **Incident response has a clear staging process** (Middle): From assessing impact and severity, to notifying users and support teams, to delegating responsibilities on an incident call—having a defined sequence prevents chaos and ensures stakeholders aren't blindsided. - **Cache is a security surface, not just a performance tool** (Middle): Never store PII in caches because attackers can target the cache directly. Cache poisoning—forcing malicious content into the cache—is a real vulnerability that senior developers must design against. - **Component architecture follows principles, not preferences** (Middle): Keep business logic separated from components, use custom hooks or files for API calls instead of doing them inline, and align terminology with the Design team so everyone refers to the same elements consistently. ## 【Reading Tips】 - **Deep-read the opening question lists**: The clarifying questions for product teams are gold—skim them once, then return when you're starting a new feature to use as a checklist. - **Skim the code-heavy setup sections**: The NestJS and Prisma setup is practical but follows standard patterns; focus on the reasoning behind architecture choices (REST vs. GraphQL, containerization) rather than memorizing commands. - **Pay special attention to the incident response stages**: This is rare, practical content that most books skip—worth reading carefully even if you're not currently on-call. - **The security chapter deserves a full read**: The OWASP Top 10 discussion and threat modeling framework apply to any stack, not just JavaScript. - **Use the frontend section as a refresher**: If you're already comfortable with React, skim the component principles and focus on the collaboration advice with Design teams. ## 【Coverage Limits】 The excerpts cover roughly the first half of the book (backend, testing, security, operations, and early frontend architecture). Later sections on advanced React patterns, deployment specifics, and team collaboration strategies are not fully represented in this guide. ##
Excerpt 1
us on LinkedIn: https://linkedin.com/company/oreilly-media. Watch us on YouTube: https://youtube.com/oreillymedia. What permissions do users need to take act...
View in text
Excerpt 2
e engineers understand the expectations of the frontend and backend, let’s work on the conventions doc for the backend. Creating a Document for Conventions Y...
View in text
Excerpt 3
s/@nestjs/core/router/ router-execution-context.js:46:28 at /Users/milecia/Repos/dashboard-server/node_modules/@nestjs/core/router/ router-proxy.js:9:17 Figu...
View in text
Excerpt 4
ay. Figure 13-1 shows what the skeleton of the architecture might look like based on the designs you got at the beginning of the project. Chapter 14. Buildin...
View in text
Excerpt 5
mponents' … const App = () => { // Do some stuff here return ( <ErrorBoundary FallbackComponent={ErrorFallback} onError={logError} onReset={() => window.loca...
View in text
Excerpt 6
data: orderResponseData, mocks.useQuery.mockReturnValue({ isLoading: false, One of the first things you need to do is become aware that a bug exists. Someone...
View in text
Excerpt 7
ur logs and alerts are so important. They’ll help you track down those unexpected changes. Some third-party services are better than others at letting you kn...
View in text
Excerpt 8
git bisect comes in. This is a tool that does this for you, allowing you to go through commits and mark them as good or bad until you narrow down to the comm...
View in text
Tags
AI categories
JavaScriptBackendWeb Technology
javascriptfull stack
Publisher: O'Reilly Media
Publish Year: 2024
Language: English
File Format: PDF
File Size: 11.9 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…