CoachnestCoachnest
Sign InGet Started
Back to course

Mastering CRUD: Build Full-Stack Database Applications

…
—
Contents
1

What Is CRUD and Why It Matters

Reading12mFree
2

CRUD, REST, and HTTP Verbs

Reading14mFree
3

The Data Lifecycle of a Record

Reading11m
4

Course Project Tour: TaskFlow

Video9m
5

Chapter 1 — Quiz

Quiz8m
6

Tables, Rows, Columns & Types

Reading14m
7

Primary Keys & IDs (Auto-increment vs UUID)

Reading13m
8

Relationships: One-to-Many & Many-to-Many

Reading16m
9

Normalization & Schema Design Principles

Reading14m
10

Modeling TaskFlow with Prisma

Reading13m
11

Chapter 2 — Quiz

Quiz8m
12

INSERT — Creating Rows

Reading13m
13

SELECT — Reading & Filtering

Reading16m
14

UPDATE — Changing Rows Safely

Reading12m
15

DELETE — Removing Rows

Reading11m
16

Live SQL: A Full CRUD Session

Video15m
17

Chapter 3 — Quiz

Quiz9m
18

REST API Design for CRUD Resources

Reading14m
19

HTTP Status Codes That Tell the Truth

Reading12m
20

Scaffolding the API (Express & Next.js)

Reading16m
21

Connecting an ORM (Prisma) to Your Routes

Reading13m
22

Chapter 4 — Quiz

Quiz8m
23

Building the Create Endpoint End-to-End

Reading15m
24

Reading a Single Resource

Reading11m
25

Listing Collections

Reading13m
26

Live Coding: Create & Read

Video16m
27

Chapter 5 — Quiz

Quiz8m
28

PUT vs PATCH: Full vs Partial Updates

Reading13m
29

Authorization: Who Can Change This Row?

Reading12m
30

Soft Delete, Hard Delete & Restore

Reading14m
31

Idempotency & Concurrency Control

Reading13m
32

Chapter 6 — Quiz

Quiz9m
33

Input Validation with Zod

Reading14m
34

Mass Assignment & Over-Posting

Reading11m
35

SQL Injection & Safe Queries

Reading13m
36

Consistent Error Handling

Reading12m
37

Chapter 7 — Quiz

Quiz9m
38

Offset vs Cursor Pagination

Reading15m
39

Filtering & Dynamic WHERE Clauses

Reading13m

Safe Sorting & Full-Text Search

Reading14m
41

Indexing for Fast Reads

Reading13m
42

Chapter 8 — Quiz

Quiz9m
43

Forms & Creating Records from the UI

Reading14m
44

Fetching & Displaying Data

Reading13m
45

Optimistic Updates & Deletes

Reading14m
46

Building the TaskFlow UI

Video17m
47

Chapter 9 — Quiz

Quiz8m
48

Transactions & Data Integrity

Reading15m
49

Testing Your CRUD Endpoints

Reading14m
50

Caching, N+1 & Performance

Reading13m
51

Deploying & Migrating Safely

Reading14m
52

Chapter 10 — Final Quiz

Quiz10m
←→navigate lessons
Chapter 8 of 10·Chapter 8 — Pagination, Filtering, Sorting & Search
Lesson 40 of 52Reading14 min

Safe Sorting & Full-Text Search

Safe Sorting & Full-Text Search¶

Sorting — Whitelist the Columns¶

Sorting takes a column name from the client. As we saw in Chapter 7, you cannot parameterize an identifier, so you must whitelist:

ts
10 lines
1const SORTABLE = {
2  created: "createdAt",
3  due: "dueDate",
4  title: "title",
5} as const;
6
7const sortKey = SORTABLE[req.query.sort] ?? "createdAt";
8const dir = req.query.dir === "asc" ? "asc" : "desc";
9
10prisma.task.findMany({ orderBy: { [sortKey]: dir } });

Anything not in the map falls back to a safe default. Never feed a raw client string into ORDER BY.

Stable Sorts Need a Tiebreaker¶

If two rows share a createdAt, their order is undefined and can flip between requests — breaking pagination. Add a unique tiebreaker:

ts
1 line
1orderBy: [{ createdAt: "desc" }, { id: "desc" }]

Search: LIKE vs Full-Text¶

For simple "contains":

ts
1 line
1where: { title: { contains: q, mode: "insensitive" } } // ILIKE '%q%'

ILIKE '%q%' works but can't use a normal index on big tables. For real search, use PostgreSQL full-text search:

sql
7 lines
1-- one-time: a generated, indexed search column
2ALTER TABLE tasks ADD COLUMN search tsvector
3  GENERATED ALWAYS AS (to_tsvector('english', title || ' ' || coalesce(description,''))) STORED;
4CREATE INDEX tasks_search_idx ON tasks USING GIN (search);
5
6-- query
7SELECT * FROM tasks WHERE search @@ plainto_tsquery('english', $1);

This handles stemming ("running" matches "run"), ranking, and stays fast via the GIN index.

When You Outgrow the Database¶

For fuzzy matching, typo tolerance, and relevance tuning at scale, dedicated engines (Elasticsearch, Meilisearch, Typesense, Postgres + pg_trgm) take over. Start with database search; reach for an engine when search becomes a core feature.

Previous

Filtering & Dynamic WHERE Clauses

Next

Indexing for Fast Reads

Use ← → arrow keys to navigate between lessons