BackendLesson 2 of 48 min

What belongs where

Three questions that settle almost every "which side does this go on" argument.

When you are unsure where a piece of logic lives, run it through three questions in order. The first one that gives a clear answer wins.

The decision order
  1. 1. Can lying about it hurt anyone?
    If yes, it is backend. Stop here.
  2. 2. Does it need something only the server has?
    Secrets, the database, other people’s data. If yes, backend.
  3. 3. Does it need something only the browser has?
    The mouse, the screen size, local storage. If yes, frontend.

Most real features end up split across the line, and that is correct rather than a compromise. A checkout form checks the card number format in the browser so the user gets instant feedback, and charges the card on the server because that is where the payment secret lives and where lying about the price would matter.

Modern frameworks blur where code physically sits: the same file can contain both sides, and the build tool splits them apart. That is convenient and slightly dangerous: the boundary still exists exactly as before, it is just no longer visible as a folder. Knowing the rule matters more, not less.

If I move this check to the server, what does the user lose?

Usually speed. That is the actual trade you are making, and it is why the answer is often "do it in both places".

What to remember

  • Ask "can lying about this hurt anyone" first. It settles most cases.
  • Duplicating a check on both sides is normal and correct.
  • Frameworks hide where code runs, but the boundary is unchanged.

Terms in this lesson

Field notes

Loaded from a deliberately slow source. The lesson above was already readable while this was still travelling. That is streaming, and it is the same trick a chat interface uses.

The URL that read everyone’s invoices

An invoice page checked that you were logged in and then loaded whatever id was in the address. Changing the number showed somebody else’s invoice. It was found by a customer who mistyped, not by a review.

Classic IDOR, still extremely common

The key in the client bundle

An API key was placed behind the public environment prefix so it would be readable from the frontend. It worked. It was also visible to every visitor, and was being used by strangers within a week.

Scraped from a public bundle

resolved in 901ms · region iad1

Hide field notes toggles a search param the loader reads. With it off, the slow promise is never created, so nothing streams.