Backend Development

Back-end development usersને દેખાતું નથી, પરંતુ તે applicationનું engine બનાવે છે: server-side code business logic રાખે છે, front end માટે APIs આપે છે, rules અને security enforce કરે છે અને database સાથે વાત કરે છે.

9 min read · 6 cards · 2 checks

Read in: English · हिन्दी · ગુજરાતી


Theory

Screens પાછળનું engine

Usersને front end દેખાય છે, પરંતુ actual work back endમાં થાય છે, એટલે કે તેઓ જોઈ શકતા નથી તે server-side codeમાં. Student event માટે register કરે ત્યારે back end request validate કરે છે, rules check કરે છે, data save કરે છે અને response આપે છે. તે applicationનું engine છે.

Back-end development આ engine બનાવે છે: business logic, front end call કરે તેવી APIs, security અને database connection. તમને degreeમાંથી Node/Express, PHP, .NET, Python અને RESTનો પરિચય છે. આ lessonનું focus back endને organised, correct અને secure રીતે build કરવા પર છે, જેથી interface પાછળ આખી system reliably કામ કરે.

Theory

Back end શું કરે છે

Back endના અનેક responsibilities છે.

Business logic: actual rules અને processing, જેમ કે event full હોય તો registration અટકાવવી, totals calculate કરવાં અને allowed actions enforce કરવાં. APIs (endpoints): front end call કરે તે interface, clean REST endpoints તરીકે design કરવું: GET read માટે, POST create માટે વગેરે. Validation અને security: client input પર ક્યારેય blind trust ન કરવો, server પર validate કરવું, users authenticate કરવાં અને sensitive data protect કરવું. Database communication: ER diagramના design પ્રમાણે data read અને write કરવું.

Code વધે ત્યારે clear રહે તે માટે તેને organised રાખો: routes, controllers અને data models અલગ રાખો, જેમ તમે full-stack developmentમાં શીખ્યા છો. High-level designમાં બતાવેલા modules પ્રમાણે back end build કરો.

Formula

Correctness અને security back endની જવાબદારી

મુખ્ય principle છે: correctness, data integrity અને security back endમાં enforce થવા જોઈએ, કારણ કે front end bypass અથવા tamper થઈ શકે છે. Web coursesનો rule યાદ રાખો: never trust the client.

Malicious user કોઈ પણ request મોકલી શકે છે, તેથી serverએ દરેક input validate કરવો, permissions check કરવી અને data protect કરવું જોઈએ. Important rules માત્ર front endમાં ન મૂકો. Front end userને guide કરી શકે છે, button hide કરી શકે છે અથવા error બતાવી શકે છે, પરંતુ rulesને સાચી રીતે enforce માત્ર back end કરી શકે છે. Projectની trustworthiness back endની correctness અને security પર આધારિત છે.

Quiz

Projectના important rules અને validation ક્યાં enforce થવા જોઈએ અને શા માટે?

  1. માત્ર front endમાં, કારણ કે usersને તે જ દેખાય છે
  2. Back end એટલે serverમાં, કારણ કે client bypass અથવા tamper થઈ શકે છે; serverએ input validate અને rules તથા security enforce કરવી જોઈએ
  3. ક્યાંય નહીં; rules પોતે enforce થાય છે
  4. માત્ર databaseમાં, codeમાં નહીં
Show the answer

Back end એટલે serverમાં, કારણ કે client bypass અથવા tamper થઈ શકે છે; serverએ input validate અને rules તથા security enforce કરવી જોઈએ

Important rules, validation અને security back end serverમાં enforce થવા જોઈએ, કારણ કે client bypass અથવા tamper થઈ શકે છે. Malicious user કોઈ પણ request મોકલી શકે છે; તેથી માત્ર server-side checks rulesને સાચી રીતે enforce અને dataને protect કરી શકે છે. Option A unsafe છે: front-end validation user experience સુધારે છે, પરંતુ bypass થઈ શકે છે. Option C ખોટું છે: rules પોતે enforce થતા નથી; codeમાં checks લખવા પડે છે. Option D incomplete છે: database કેટલીક constraints enforce કરી શકે છે, પરંતુ business logic અને overall security server-side codeમાં પણ જરૂરી છે. Back end correctness અને securityનો સાચો guardian છે.

Think first

Front endને એકલું security માટે trust કેમ ન કરી શકાય?

તમે front endમાં input validate કર્યું છે. તે પૂરતું કેમ નથી અને back endએ બધું ફરી check કેમ કરવું જોઈએ? પછી tap.

Show the answer

કારણ કે front end USERના device પર ચાલે છે, જ્યાં user તેને inspect, modify અથવા bypass કરી શકે છે. Front endમાં જ કરેલી કોઈ પણ check defeat થઈ શકે છે, તેથી serverએ independently દરેક request validate અને enforce કરવી જરૂરી છે.

Front end HTML, JavaScript અથવા mobile app code હોઈ શકે છે અને તે userના controlમાં ચાલે છે. User developer toolsથી code બદલી શકે છે, validation disable કરી શકે છે અથવા front endને સંપૂર્ણ ignore કરીને raw request સીધી serverને મોકલી શકે છે. એટલે 'full eventમાં register ન થવું' જેવી front-end check honest usersને અટકાવે છે, પરંતુ crafted request મોકલનાર attackerને નહીં.

જો server 'front endએ validate કરી લીધું હશે' માનીને request blindly trust કરે, તો attacker full eventમાં registration કરી શકે, invalid અથવા malicious data મોકલી શકે, unauthorized data access કરી શકે અથવા records tamper કરી શકે. તેથી golden rule છે: never trust the client. Serverએ દરેક incoming requestને potentially hostile માનીને input validate કરવું, permissions check કરવી, business rules enforce કરવાં અને data protect કરવું.

Front-end validation હજી પણ valuable છે: તે userને fast અને friendly feedback આપે છે અને unnecessary server load ઘટાડે છે. પરંતુ તે convenience છે, security boundary નહીં. સાચી security boundary server છે, કારણ કે તે તમારા controlમાં છે. Projectના real checks back endમાં મૂકો.

Summary

Key takeaways

  • Back end usersને ન દેખાતું server-side engine છે, જે દરેક screen પાછળનું actual work કરે છે.
  • તેના મુખ્ય jobs business logic, APIs/endpoints, validation અને security, તથા database communication છે.
  • Routes, controllers અને data models અલગ રાખીને code organised રાખો.
  • High-level designના modules અને ER diagramના data design પ્રમાણે back end build કરો.
  • Correctness, data integrity અને security back endમાં enforce થવા જોઈએ, કારણ કે client bypass અથવા tamper થઈ શકે છે.
  • Never trust the client: front-end validation userને મદદ કરે છે, પરંતુ rulesને સાચી રીતે enforce માત્ર server કરી શકે છે.
  • Memory hook: back end logic રાખે છે, APIs expose કરે છે, database સાથે વાત કરે છે અને correctness તથા securityનું રક્ષણ કરે છે.

Study this properly

This page is the lesson to read. In Gri-Learn the same topic is a graded deck: the self-checks are scored and your weak topics are tracked. Free to start.

Start this topic

Already have an account? Sign in

More from Project Development

Gri-Learn · syllabus-mapped B.C.A. lessons in English, Hindi and Gujarati

Backend Development · Project (Major-16) · Gri-Learn