CoachnestCoachnest
Sign InGet Started
Back to course

Mastering CRUD: Build Full-Stack Database Applications

…
—
Contents
1

What Is CRUD and Why It Matters

Reading12mFree
2

CRUD, REST, and HTTP Verbs

Reading14mFree
3

The Data Lifecycle of a Record

Reading11m
4

Course Project Tour: TaskFlow

Video9m
5

Chapter 1 — Quiz

Quiz8m
6

Tables, Rows, Columns & Types

Reading14m
7

Primary Keys & IDs (Auto-increment vs UUID)

Reading13m
8

Relationships: One-to-Many & Many-to-Many

Reading16m
9

Normalization & Schema Design Principles

Reading14m
10

Modeling TaskFlow with Prisma

Reading13m
11

Chapter 2 — Quiz

Quiz8m
12

INSERT — Creating Rows

Reading13m
13

SELECT — Reading & Filtering

Reading16m
14

UPDATE — Changing Rows Safely

Reading12m
15

DELETE — Removing Rows

Reading11m
16

Live SQL: A Full CRUD Session

Video15m
17

Chapter 3 — Quiz

Quiz9m
18

REST API Design for CRUD Resources

Reading14m
19

HTTP Status Codes That Tell the Truth

Reading12m
20

Scaffolding the API (Express & Next.js)

Reading16m
21

Connecting an ORM (Prisma) to Your Routes

Reading13m
22

Chapter 4 — Quiz

Quiz8m
23

Building the Create Endpoint End-to-End

Reading15m
24

Reading a Single Resource

Reading11m
25

Listing Collections

Reading13m
26

Live Coding: Create & Read

Video16m
27

Chapter 5 — Quiz

Quiz8m
28

PUT vs PATCH: Full vs Partial Updates

Reading13m
29

Authorization: Who Can Change This Row?

Reading12m
30

Soft Delete, Hard Delete & Restore

Reading14m
31

Idempotency & Concurrency Control

Reading13m
32

Chapter 6 — Quiz

Quiz9m

Input Validation with Zod

Reading14m
34

Mass Assignment & Over-Posting

Reading11m
35

SQL Injection & Safe Queries

Reading13m
36

Consistent Error Handling

Reading12m
37

Chapter 7 — Quiz

Quiz9m
38

Offset vs Cursor Pagination

Reading15m
39

Filtering & Dynamic WHERE Clauses

Reading13m
40

Safe Sorting & Full-Text Search

Reading14m
41

Indexing for Fast Reads

Reading13m
42

Chapter 8 — Quiz

Quiz9m
43

Forms & Creating Records from the UI

Reading14m
44

Fetching & Displaying Data

Reading13m
45

Optimistic Updates & Deletes

Reading14m
46

Building the TaskFlow UI

Video17m
47

Chapter 9 — Quiz

Quiz8m
48

Transactions & Data Integrity

Reading15m
49

Testing Your CRUD Endpoints

Reading14m
50

Caching, N+1 & Performance

Reading13m
51

Deploying & Migrating Safely

Reading14m
52

Chapter 10 — Final Quiz

Quiz10m
←→navigate lessons
Chapter 7 of 10·Chapter 7 — Validation, Errors & Security
Lesson 33 of 52Reading14 min

Input Validation with Zod

Input Validation with Zod¶

Never trust input. Every byte from a client is a guess until you've validated it. Validation is the front door to all your CRUD writes.

Define a Schema Once¶

ts
10 lines
1import { z } from "zod";
2
3export const CreateTask = z.object({
4  title: z.string().trim().min(1, "Title is required").max(200),
5  description: z.string().max(2000).optional(),
6  status: z.enum(["TODO", "IN_PROGRESS", "DONE"]).default("TODO"),
7  dueDate: z.coerce.date().optional(),
8});
9
10export type CreateTaskInput = z.infer<typeof CreateTask>;

One schema gives you runtime validation and a static TypeScript type for free.

safeParse and Report Cleanly¶

ts
8 lines
1const parsed = CreateTask.safeParse(await req.json());
2if (!parsed.success) {
3  return NextResponse.json(
4    { error: "Validation failed", issues: parsed.error.flatten().fieldErrors },
5    { status: 400 },
6  );
7}
8const data = parsed.data; // fully typed & sanitized

Validate at the Boundary, Trust Inside¶

Validate once, at the edge of your system (the route handler). After that, the rest of your code can trust the data's shape. Don't re-validate in every function — validate at the door, type everything behind it.

Coerce and Normalize¶

Schemas can clean data, not just reject it:

ts
3 lines
1email: z.string().email().toLowerCase().trim(),
2page:  z.coerce.number().int().min(1).default(1),
3tags:  z.array(z.string()).max(10),

z.coerce turns the string "2" from a query param into the number 2.

Whitelist, Don't Blacklist¶

Define exactly what you accept and drop everything else. A schema with known keys naturally ignores extra fields a client tries to sneak in — your defense against mass assignment (next lesson).

Previous

Chapter 6 — Quiz

Next

Mass Assignment & Over-Posting

Use ← → arrow keys to navigate between lessons