Course Practicalities
Glossary
This glossary gives the meaning of recurring terms as they are used in this course. Chapters introduce the concepts in context; the glossary is a reference rather than a chapter to memorize.
A
- Accessibility — The quality of an interface that people can perceive, understand, navigate, and operate under different sensory, motor, cognitive, and technological conditions.
- API (Application Programming Interface) — A defined boundary through which software components interact. In this course, the main API is the HTTP interface exposed by Hono.
- API Endpoint — A server-side HTTP interface identified by a route and method, such as
GET /listings. - ARIA (Accessible Rich Internet Applications) — Attributes that can supplement the accessibility semantics exposed by HTML. Prefer an appropriate native HTML element when one already provides the required meaning and behavior.
- Authentication — Establishing who a user or client is.
- Authorization — Deciding whether an authenticated or otherwise identified actor may perform an operation.
B
- Backend — The server-side parts of an application, commonly including HTTP handlers, business logic, and persistence access. The term describes a broad area, not one required architecture.
- Backend for the Frontend (BFF) — A server layer serving the needs of a particular browser-facing interface. In Part 9, SvelteKit loads pages and handles forms while Hono retains authoritative business operations and authorization.
- Browser — The client environment that loads the course application, executes client-side JavaScript, renders HTML/CSS, and provides Web platform APIs.
- Browser Developer Tools — Browser-provided panels for inspecting the DOM, CSS, JavaScript console, HTTP requests, storage, accessibility information, and performance.
- Build — Producing application artifacts from source code and configuration. A successful build is evidence that the build process completed; it does not prove every runtime behavior.
C
- Cache — Stored data reused to avoid repeating more expensive work or network access. Caching introduces freshness and invalidation questions.
- Client — Software initiating requests or interactions. In the main course architecture, the Svelte/SvelteKit browser application is the client of the Hono API.
- Component — A reusable unit of user-interface structure and behavior. Svelte components are the primary browser UI units in this course.
- Concurrency — Multiple operations making progress during overlapping periods, potentially interacting with the same state.
- Container — An isolated process environment created from a container image. Docker Compose runs several course services as containers.
- Continuous Delivery — Keeping verified software ready to release through a repeatable delivery process; release may require an explicit decision.
- Continuous Deployment — Automatically releasing changes that pass the delivery process.
- Continuous Integration (CI) — Frequently integrating changes with automated checks that provide shared evidence about the resulting software.
- Contract — An agreement about an interface, including accepted input, response shapes, status codes, and behavior. A generated type describes part of the agreement; runtime checks and tests establish different parts.
- Cookie — A name-value item a browser stores and attaches to matching requests according to domain, path, security, and same-site rules. Cookie scope is not the same as origin scope.
- CORS (Cross-Origin Resource Sharing) — A browser mechanism using HTTP headers to decide whether script may access a cross-origin response, with preflight checks for some requests. It is not API authentication or a general block on non-browser clients.
- CSRF (Cross-Site Request Forgery) — An attack in which a browser is induced to make an unwanted authenticated request.
- CSS (Cascading Style Sheets) — The language used to describe the presentation and layout of HTML documents.
D
- Database — An organized store of data managed by a database system. The course uses a PostgreSQL relational database.
- Database Migration — A versioned change to database schema or managed database state. The course uses dbmate and plain SQL migration files with explicit up and down sections.
- dbmate — The migration command-line tool used by the course. It applies the requested direction from each migration file and records the file’s leading numeric version, but not a checksum of its contents.
- Deno — The JavaScript and TypeScript runtime used by the course API and, in the pinned starter, to run the SvelteKit client toolchain inside Docker.
- Dependency — External software required by a project. Course dependencies are pinned for reproducibility.
- Deployment — Installing and configuring an application revision in a target environment. The target can be a local release-test environment or a hosted environment; deployment is not synonymous with owning a cloud account.
- Derived State — State computed from other authoritative state rather than stored as a competing independent source of truth.
- DNS (Domain Name System) — The distributed naming system used to obtain information such as IP addresses for hostnames.
- Docker — A platform and toolset for building images and running containers. The course uses Docker with Compose to run its local multi-service environment.
- Docker Compose — A tool for defining and running related containers, networks, volumes, environment files, and startup dependencies.
- DOM (Document Object Model) — The browser-accessible representation of a document as objects in a tree.
E
- E2E Test (End-to-End Test) — A test exercising a complete user-visible flow across the running application, commonly through a real browser. The course uses Playwright.
- Environment — The runtime context and configuration in which software executes, such as development, test, or deployment.
- Environment Variable — A named value supplied by the runtime environment instead of being hard-coded in source.
F
- Fake — A lightweight working substitute for a dependency used in tests, such as an in-memory repository.
- Fetch API — A Web API for making HTTP requests and receiving responses through promises. Browser
fetchstill requires code to interpret statuses and validate untrusted response data. - Fixture — Known test data or setup used to place a system into a controlled state.
- Foreign Key — A database constraint linking a value in one table to a row in another table, or sometimes the same table.
- Frontend — The user-facing part of an application running in a browser. In this course it is primarily implemented with Svelte and SvelteKit.
- Full Stack — Work spanning several application layers, commonly the browser interface, server, and database. It does not mean that these layers have identical responsibilities.
G
- Git — A distributed version-control system used to record changes, inspect differences, create recovery points, and collaborate without replacing an understanding of the code.
H
- Handler — Code that receives and responds to a request or event. A Hono route handler is one example.
- Hono — The Web framework used to implement the course HTTP API on Deno.
- HTML — The markup language used to describe the structure and meaning of web documents.
- HTTP (Hypertext Transfer Protocol) — The request-response protocol used by browsers, APIs, and many other Web systems.
- HTTP Header — Metadata attached to an HTTP request or response. Headers describe concerns such as accepted formats, content type, caching, authorization, and cookies.
- HTTP Status Code — A numeric code in an HTTP response indicating the broad result of a request, such as
200,404, or409. Client code must interpret the relevant status rather than assuming every completed request succeeded. - HTTPS — HTTP over a secure transport connection, protecting the communication channel rather than proving that application logic is correct.
- Hydration — Initializing client-side application behavior using HTML already rendered on the server. A client-rendered empty application shell is not the same as server-rendered page content.
I
- Idempotency — The property that repeating the same identified operation has no additional intended effect after the first successful application.
- Image (container image) — Packaged filesystem and metadata used to create containers.
- IndexedDB — An asynchronous browser API for storing structured data locally in object stores and transactions.
- Integration Test — A test that exercises several real components together, such as API code plus a real test database.
- Internet — Interconnected networks through which hosts communicate. The Web is one system of resources and protocols that uses it.
- Invariant — A property that must remain true across the states or operations in its stated scope.
J
- JavaScript — The programming language used in browser code and, with different host APIs, on the server.
- JSON — A text data format commonly used for HTTP API request and response bodies.
- JSR — A JavaScript/TypeScript package registry used by Deno-native dependencies where appropriate.
L
- Layout — Shared page structure in SvelteKit, or more generally the arrangement of UI elements in CSS. Context determines the meaning.
- Lock (database) — A mechanism restricting conflicting concurrent database operations while protected work is performed.
M
- Middleware — Code participating in request processing before or after a route handler, often for shared concerns such as CORS, logging, authentication, or request context.
- Mock — A test double often used to verify interactions with a dependency.
- Module — A source file or unit that explicitly exports and imports values or types. Module boundaries help separate responsibilities and control dependencies.
- Mutation — An operation that changes application state, such as create, update, delete, or bid.
O
- Optimistic UI — Showing an expected successful state before the authoritative server response arrives, then reconciling or rolling back if needed.
- Origin — The combination of URL scheme, host, and port used by browser security rules.
- OWASP — A foundation and community producing application-security resources, including awareness material, verification guidance, and implementation cheat sheets. Part 5 uses these as references rather than a list of items to memorize.
- Ownership Authorization — Authorization based on an actor’s relationship as the owner of a resource.
P
- Pagination — Dividing a collection into bounded pages and providing a way to request another page while preserving a defined order.
- Playwright — The browser automation and end-to-end testing tool used in the course.
- PostgreSQL — The relational database used in the course.
- Progressive Enhancement — Providing useful functionality through basic Web mechanisms first and enhancing it when richer capabilities are available.
- Promise — A JavaScript object representing the eventual completion or failure of asynchronous work.
asyncfunctions return promises, andawaitobserves their settlement. - Prop — Data passed into a Svelte component from its caller.
- PWA (Progressive Web App) — A Web application using capabilities such as an application manifest and service worker to support installability or resilient/offline behavior where available.
R
- Race Condition — A correctness problem where the outcome depends on timing or ordering of concurrent operations.
- Rate Limiting — Restricting how frequently an actor or client may perform an operation within a defined scope and period.
- RBAC (Role-Based Access Control) — Authorization where permissions are associated with roles and users receive permissions through role membership.
- Reactive State — State whose changes update dependent values or interface output.
- Repository — An application layer encapsulating persistence operations and hiding database-specific details from higher layers.
- Representation — A selected form of data sent across a boundary, such as a JSON response. It need not contain all fields from the database row used to produce it.
- Request — A message sent by an HTTP client to a server, including a method, URL, headers, and sometimes a body.
- Response — The HTTP server’s reply, including a status code, headers, and sometimes a body.
- REST — A set of architectural constraints that influenced common resource-oriented HTTP API design. This course treats REST as one useful design style, not as a synonym for HTTP APIs.
- Route — A navigable application location in SvelteKit or an HTTP path handled by Hono. Context distinguishes the meanings.
S
- Scaffold — A supplied or generated starter project containing files and configuration needed to begin a task.
- Schema — A formal description of structure, such as database structure or a validation schema.
- Server — Software that receives requests or connections and provides responses or services.
- Server-Sent Events (SSE) — An HTTP mechanism for keeping a connection open so a server can stream events to a client.
- Service — A separately running process in the Compose environment, or an application-layer module/object containing business logic. Context distinguishes the meanings.
- Service Worker — A browser-managed worker that can intercept network requests and support offline/PWA behavior.
- Session — Server-recognized state associating multiple requests with an authenticated user or interaction context.
- Source of Truth — The authoritative representation of a piece of state from which dependent values should be derived or reconciled.
- SQL (Structured Query Language) — The language used to define, query, and modify relational data in PostgreSQL.
- SSR (Server-Side Rendering) — Producing HTML for a page on a server before the browser executes the client application.
- State Transition — A change from one recognized application state to another according to defined rules.
- Stub — A test double that returns controlled data or behavior.
- Svelte — The component and reactivity framework used for browser-side interfaces.
- SvelteKit — The application framework around Svelte used for routing, layouts, rendering infrastructure, builds, and related Web-application concerns.
T
- Test Double — A substitute used in tests in place of a real dependency. Stubs, fakes, and mocks are common forms.
- Transaction — A database mechanism grouping operations into a unit with guarantees used to protect consistency.
- Type Check — Static analysis of source code against declared and inferred types. It can reveal incompatible code without executing the application, but does not establish runtime validation or authorization.
- Type-only Import — A TypeScript import used for type information and erased from emitted JavaScript. The course passes generated declarations to the client rather than API startup code or database credentials.
- Typed HTTP Client — Client code whose request and response types follow an API contract. Hono’s
hcconstructs ordinary HTTP requests; the separate server remains responsible for handling arbitrary callers. - TypeScript — JavaScript with a static type system used by development tools. Its types are erased before runtime and do not replace validation of untrusted data.
U
- Unit Test — A focused test of a small unit of behavior with unnecessary external dependencies excluded.
- URL (Uniform Resource Locator) — An address identifying a resource, including components such as scheme, host, port, path, query, and fragment where present.
V
- Validation — Checking data against declared requirements. Boundary schemas check input shapes and constraints; services also enforce state-dependent business rules. Neither a TypeScript annotation nor a typed client replaces these runtime checks.
- Vite — The development/build tooling used by SvelteKit in the course.
- Vitest — The testing framework used for client logic and Svelte component tests.
- Volume — Docker-managed persistent storage mounted into a container.
W
- WebSocket — A persistent full-duplex communication channel between client and server.
X
- XSS (Cross-Site Scripting) — A vulnerability where attacker-controlled data is interpreted as executable or active content in another user’s browser.
Y
- YAML — A data-serialization format commonly used for configuration. The course’s
compose.yamldeclares services and related Docker Compose configuration.
Z
- Zod — The validation library used later in the course to define runtime schemas and infer TypeScript types where useful.
Related references
For syntax examples, use the HTML Quick Reference, JavaScript Quick Reference, or TypeScript Quick Reference. For OWASP reference material, start with the OWASP Top 10 project. The numbered chapters explain these terms in context.