The API between them
The two halves talk through a contract. Understanding the contract is understanding the app.
The frontend and backend do not share memory, variables, or functions. They share messages. The agreed shape of those messages is the API, and it is the single most important document about your system even when nobody has written it down.
This is why "just change the backend" is rarely just changing the backend. If you rename a field the frontend reads, you have changed the menu, and something out there ordered the old dish. That problem has a name, a breaking change, and a whole lesson later in the Backend track.
- The frontend asks by sending a request to an agreed path.
- The backend answers with an agreed shape, usually JSON.
- Both sides can be rewritten independently as long as the shape holds.
- When the shape changes without agreement, things break in production, not at build time.
What to remember
- The two halves share messages, not memory.
- The message shape is a contract, whether or not it is written down.
- Shared types turn contract breaks into build errors instead of outages.
Terms in this lesson
Field notes
Loaded from a deliberately slow source. The lesson above was already readable while this was still travelling. That is streaming, and it is the same trick a chat interface uses.
The URL that read everyone’s invoices
An invoice page checked that you were logged in and then loaded whatever id was in the address. Changing the number showed somebody else’s invoice. It was found by a customer who mistyped, not by a review.
Classic IDOR, still extremely common
The key in the client bundle
An API key was placed behind the public environment prefix so it would be readable from the frontend. It worked. It was also visible to every visitor, and was being used by strangers within a week.
Scraped from a public bundle
resolved in 900ms · region iad1
Hide field notes toggles a search param the loader reads. With it off, the slow promise is never created, so nothing streams.