Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Windows Tipps & SecurityNighthawk M7 Pro im Test: Flexibler, aber teurer 5G-Router(21.09.2026 um 10:30 Uhr)
Sichere ProgrammierungNeue Gmail-Funktion: So sparst du jetzt Zeit bei Einmalcodes(21.09.2026 um 10:00 Uhr)
Sichere ProgrammierungYour GIF exporter is fine — the container is the problem(21.09.2026 um 10:01 Uhr)
Sichere ProgrammierungCSS, Motion, or GSAP? I Choose by Who Owns the Animation(21.09.2026 um 10:12 Uhr)
Windows Tipps & SecurityNighthawk M7 Pro im Test: Flexibler, aber teurer 5G-Router(21.09.2026 um 10:30 Uhr)
Sichere ProgrammierungNeue Gmail-Funktion: So sparst du jetzt Zeit bei Einmalcodes(21.09.2026 um 10:00 Uhr)
Sichere ProgrammierungYour GIF exporter is fine — the container is the problem(21.09.2026 um 10:01 Uhr)
Sichere ProgrammierungCSS, Motion, or GSAP? I Choose by Who Owns the Animation(21.09.2026 um 10:12 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

The Backend Setup Every Developer Should Follow

Before you write your backend code, it is very important to have a clean and organized setup — one that helps you scale, debug, and collaborate better. There are 6 major layers of i…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

Before you write your backend code, it is very important to have a clean and organized setup — one that helps you scale, debug, and collaborate better.



There are 6 major layers of it.




  1. Routes

  2. Controllers

  3. Middleware

  4. Services

  5. Repositary

  6. Database






Routes – The Entry Points



Routes define which function should run when a specific request hits your server.



They map HTTP methods and URLs to controllers.




router.post("/signup", userController.signup);
router.get("/profile", authMiddleware, userController.getProfile);






Routes should be thin and clean.

They don’t contain logic.

They only decide where the request goes.



Think of Routes as:

The road map of your backend.





Controllers – The Request Handlers



Controllers handle:




  • Reading request data (req.body, req.params, req.query)

  • Sending response (res.json, res.status)

  • Calling the service layer



They should NOT:




  • Contain business logic

  • Talk directly to the database

  • Hash passwords

  • Calculate business rules



Think of Controllers as:

The receptionist. They receive and respond.





Middleware – The Gatekeepers



Middleware runs before the controller.



It is used for:




  • Authentication (JWT verification)

  • Logging

  • Input validation

  • Rate limiting

  • Error handling



router.get("/profile", authMiddleware, userController.getProfile);





The request must pass through middleware before reaching the controller.



Think of Middleware as:

The security check at the airport.





Services – The Brain of the Application



This is where your real logic lives.



Services handle:




  • Business rules

  • Data transformations

  • Workflow decisions



Orchestration of multiple repositories.




exports.signup = async ({ email, password }) => {
const existingUser = await userRepository.findByEmail(email);

if (existingUser) {
throw new Error("User already exists");
}

const hashedPassword = await bcrypt.hash(password, 10);

return await userRepository.createUser(email, hashedPassword);
};






Think of Services as:

The decision-maker.






Repository – The Data Access Layer



The repository is responsible for:




  • Communicating with the database

  • Executing queries

  • Returning raw data



It does NOT:




  • Decide business rules

  • Validate logic

  • Handle HTTP




exports.findByEmail = async (email) => {
return db("users").where({ email }).first();
};






Repository is:



An abstraction over the database.

If tomorrow you switch from PostgreSQL to MongoDB,

only the repository layer should change.



Think of Repository as:

The translator between your app and the database.






Database – The Storage Engine



This is your:




  • PostgreSQL

  • MySQL

  • MongoDB

  • Supabase



Its job is simple:




  • Store data

  • Retrieve data

  • Maintain integrity



It does not care about:




  • HTTP

  • Business logic

  • Application rules

  • It only stores information






Full Request Flow




  • Let’s say a user signs up.

  • Request hits Route

  • Middleware validates token/input

  • Controller receives request

  • Controller calls Service

  • Service applies business logic

  • Service calls Repository

  • Repository talks to Database

  • Response travels back up the chain



Database → Repository → Service → Controller → Client



Clean. Predictable. Scalable.






🧠 Simple Mental Model



If you're ever confused where something belongs, ask:



Does it handle HTTP? → Controller



Does it validate/authenticate/log? → Middleware



Is it business logic? → Service



Is it database query? → Repository



Is it storage? → Database



Does it map endpoint to controller? → Route



This structure is inspired by architectural principles popularized in

Clean Architecture by Robert C. Martin — but simplified for practical backend applications.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten The Backend Setup Every Developer Should Follow

Thematisch verwandte Begriffe: Backend, Setup, Every, Developer · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94030 | A security vulnerability has been detected in SerenityOS up to 3d83e4509…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick