Quick recap · Cheat sheet ☷ Flashcards
Quick recap

All 103 questions, one line each

Filter to one category, collapse what you already know, and print the rest. Click any question to open the full explanation.


The 26 things to be sure of

If you remember nothing else, remember these.

1Node is a runtime, not a language or a framework: JavaScript is the language, Express is the framework.
2V8 runs the JavaScript; libuv provides the event loop, async I/O and the thread pool.
3Commit package-lock.json, never node_modules. Use npm ci on build servers.
4const by default, let when it must change, never var — var in a loop shares one variable.
5A promise is pending → fulfilled or rejected, once and permanently. await is just nicer syntax for it.
6try/catch catches await, never a plain callback — the callback runs on a later turn.
7ESM can import CommonJS; CommonJS cannot require ESM. No __dirname in ESM.
8A required file runs once and is cached — which is why a module can act as a singleton.
9Status codes are the contract: 201 created · 204 deleted · 400 bad input · 401 who are you · 403 not allowed · 409 conflict.
10Non-blocking I/O: Node hands the work to the OS and serves other requests while it waits. Anything ending in Sync undoes that.
11Express = routing + middleware + req.body + res.json on top of the http module. It still uses http underneath.
12req.params from the path · req.query after the ? · req.body needs express.json(). params and query are strings.
13await in a loop is sequential. Independent calls → Promise.all: 600 ms becomes 200 ms.
14Promise.all fails on the first rejection; allSettled never fails. Don't fire thousands at once — batch them.
15await does not block the server — it pauses one function. A long loop or a *Sync call blocks everything.
16Loop order: sync → nextTick → promises → setTimeout → setImmediate. Microtasks beat macrotasks.
17"Single-threaded" means your JavaScript. The process also has libuv's 4-thread pool for file work, DNS and zlib.
18A blocked loop shows up as latency rising on every endpoint at once with one core at 100%. Measure event-loop lag.
19In Express, registration order is execution order: helmet → cors → json → routes → 404 → error handler last.
20The error middleware is recognised by having 4 arguments. Express 4 needs next(err) from async routes; Express 5 doesn't.
21Structure it like a Web API: route → controller → service → repository. No SQL in a controller, no req in a service.
22Always use SQL parameters (request.input(...)). A template literal in a query is an injection hole.
23A JWT is signed, not encrypted — anyone can read the payload. Id and role only; short expiry; secret from the environment.
24Take the user id from req.user (the verified token), never from req.body.
25Secrets live in environment variables, never in code — Git remembers forever. Validate config at startup and exit if it's missing.
26Validate every request at the edge, reject unknown fields, return 400 with field errors. The React form's validation is only for UX.

Translating from .NET

Thread pool + awaitOne JS thread + the event loop
Middleware pipelineExactly the same idea — app.use(fn)
UseExceptionHandlerA 4-argument error middleware, registered last
Controllers + DIRouters + modules (a cached module acts as a singleton)
DTOs / over-posting guardszod schemas with .strict()
EF CorePrisma / Knex / raw SQL — less mature, so more discipline needed
IHostedService workerA separate process consuming a queue

Words that signal seniority

event-loop lag · microtask queue · backpressure · blocking the loop · graceful shutdown · correlation id · BFF · trust boundary · idempotent · structured logging · reproducible build · measure first · trade-off

How to answer, whatever they ask

What it is → why it matters → what you'd do in practice, then tie it to something you've actually built. If you don't know, say so and say how you'd find out.