Full Stack Web Development: Modern Architecture, REST APIs & Cloud Deployment

Level: Beginner to Intermediate 18 total hours DBERT Platform

Course curriculum

Day 1: Day 1: Modern Web Architecture, Semantic HTML5 & Modern CSS Systems 3 subtopics
▸
Client-Server Architecture & The HTTP Request Lifecycle

Explore the foundational mechanics of the modern internet. Analyze the complete lifecycle of a web request: DNS resolution, TCP three-way handshake, TLS cryptographic negotiation, and HTTP/1.1 vs HTTP/2 multiplexing. Examine REST protocol semantics, distinguishing idempotent idempotent operations (GET, PUT, DELETE) from non-idempotent operations (POST, PATCH), and master HTTP status code families (2xx success, 3xx redirection, 4xx client errors, 5xx server faults).

▸
Semantic HTML5, Accessibility (a11y) & The DOM Tree

Build web interfaces that are universally accessible and search-engine optimized. Replace unsemantic div-soup with semantic landmark tags (<header>, <nav>, <main>, <article>, <aside>, <footer>). Master WCAG 2.1 AA accessibility guidelines, color contrast ratios, keyboard tab navigation, and ARIA attributes (aria-label, aria-live). Understand how the browser parses markup into the Document Object Model (DOM) and accessibility tree.

▸
Modern CSS Layouts, Design Tokens & Tailwind Fundamentals

Architect scalable, maintainable CSS systems. Master one-dimensional layouts with Flexbox and two-dimensional matrix grid systems with CSS Grid. Learn to build custom design systems using CSS Custom Properties (variables) for design tokens (colors, typography, spacing, shadows). Transition from rigid pixel values to fluid responsive units (rem, clamp(), min(), max()). Explore utility-first CSS principles as embodied by modern frameworks like Tailwind CSS.

Day 2: Day 2: Modern JavaScript & Frontend Engineering with React 3 subtopics
▸
Modern JavaScript (ES6+), Event Loop & Asynchronous Control

Deepen your understanding of JavaScript fundamentals. Master ES6+ features: destructuring, rest/spread operators, arrow functions, template literals, and optional chaining (?.), nullish coalescing (??). Explore the V8 engine architecture: call stack, memory heap, microtask queue (Promises), and macrotask queue (setTimeout). Write robust asynchronous code with async/await, handling concurrency with Promise.all and Promise.allSettled.

▸
React Fundamentals, JSX & Component Architecture

Transition from imperative DOM manipulation to declarative user interfaces. Understand how React's Virtual DOM computes diffs to minimize real DOM mutations. Build composable functional components, pass data via unidirectional props, handle synthetic events, and render lists efficiently using stable key attributes. Understand the build-time compilation of JSX to React.createElement using modern bundlers like Vite.

▸
State Management with React Hooks (useState, useEffect, useRef)

Master React's official hook primitives. Manage local state with useState, ensuring state updates are treated immutably. Handle component side effects, asynchronous subscriptions, and DOM lifecycles with useEffect. Understand the role of dependency arrays in preventing infinite re-render loops and stale closures. Use useRef to persist mutable values across renders and interact directly with native DOM nodes.

Day 3: Day 3: Backend Fundamentals & RESTful API Engineering with Python & Flask 3 subtopics
▸
WSGI Applications & The Flask Request/Response Lifecycle

Unpack Python web architectures. Understand the Web Server Gateway Interface (WSGI) standard that bridges production web servers (Nginx/Gunicorn) with Python web applications. Learn how Flask initializes application and request contexts. Explore Flask request objects (headers, form data, JSON payloads, query parameters) and response construction (jsonify, status codes, custom headers).

▸
Designing Idempotent RESTful APIs with JSON Payloads

Design production-grade REST APIs. Implement standard CRUD routing patterns, dynamic URL converters (<int:id>, <string:slug>), and query-string pagination (page, per_page). Enforce input validation, content-type verification (application/json), and handle errors with unified schema formats (e.g. {'status': 'error', 'message': '...'}). Master HTTP semantics for creation (201 Created with Location header) and validation failures (400 Bad Request, 422 Unprocessable Entity).

▸
Modular Architecture with Flask Blueprints & Middleware

Scale web applications from monolithic scripts into organized, maintainable architectures. Structure backend systems using Flask Blueprints to separate authentication, administration, and resource endpoints into discrete modules. Implement application middleware hooks: before_request (authentication checks, rate limits), after_request (security headers, CSP nonces), and teardown_request (database connection cleanup).

Day 4: Day 4: Relational Database Modeling, SQL & Data Integrity 3 subtopics
▸
Schema Normalization & Entity-Relationship Design

Design robust database architectures. Walk through relational normalization rules from First Normal Form (1NF: atomic values) through Third Normal Form (3NF: eliminating transitive dependencies). Define primary keys, composite keys, and foreign key relationships (1:1, 1:N, N:M junction tables). Master integrity constraints: NOT NULL, UNIQUE, CHECK, and cascade behavior (ON DELETE CASCADE, ON DELETE SET NULL).

▸
Query Optimization, Multi-Table Joins & Indexing Strategies

Write high-performance SQL queries. Master relational joins: INNER JOIN, LEFT OUTER JOIN, and cross joins. Understand join cardinality and avoid cartesian explosion traps that duplicate financial data. Learn how B-tree indexes accelerate WHERE and ORDER BY lookups. Use EXPLAIN QUERY PLAN to detect full table scans (SCAN TABLE) and evaluate when covering indexes or composite indexes are warranted.

▸
ACID Transactions, Concurrency & SQLite WAL Mode

Protect data integrity under concurrent traffic. Master ACID guarantees: Atomicity, Consistency, Isolation, and Durability. Implement database transactions with BEGIN, COMMIT, and ROLLBACK blocks. Understand race conditions (dirty reads, non-repeatable reads, lost updates). Configure SQLite Write-Ahead Logging (PRAGMA journal_mode=WAL) to enable simultaneous readers and writers without lock contention.

Day 5: Day 5: Authentication, Authorization & Web Application Security 3 subtopics
▸
Secure Password Hashing & Salted Cryptographic Storage

Defend user credentials against credential stuffing and database dumps. Understand why plain text, MD5, and fast cryptographic hashes (SHA-256) are fundamentally unsafe for password storage due to high-speed GPU dictionary attacks. Master adaptive key-derivation functions (Argon2, bcrypt, PBKDF2). Implement salted hashing using Werkzeug/bcrypt and configure appropriate computational work factors.

▸
Session-Based Auth vs Stateless JWT Tokens & Cookie Security

Architect web authentication mechanisms. Compare stateful server-side sessions stored in databases/Redis against stateless JSON Web Tokens (JWT). Learn the anatomy of a JWT (Header, Payload, Signature) and token verification. Harden web cookies by configuring security flags: HttpOnly (mitigating XSS extraction), Secure (transmitting strictly over HTTPS), and SameSite=Strict/Lax (mitigating CSRF).

▸
Defending the OWASP Top 10 (SQLi, XSS, CSRF & CSP)

Harden full-stack web applications against common web exploits. Eliminate SQL Injection (SQLi) using strictly parameterized database queries. Prevent Cross-Site Scripting (XSS) via context-aware output escaping and Content Security Policy (CSP) headers with cryptographic nonces. Defend against Cross-Site Request Forgery (CSRF) using synchronized anti-CSRF tokens. Secure file upload endpoints against directory traversal and remote code execution.

Day 6: Day 6: Full-Stack Integration, State Management & Asynchronous Data Pipelines 3 subtopics
▸
Frontend-Backend Communication with Fetch/Axios & Error Boundaries

Bridge the gap between frontend clients and backend APIs. Build reusable API client abstractions using Fetch API or Axios with interceptors for token injection and automatic 401 redirect handling. Manage asynchronous loading states, empty collection states, and error toasts. Implement React Error Boundaries to catch unhandled JavaScript runtime exceptions and display graceful recovery interfaces.

▸
Multipart Form Submissions, File Uploads & Asset Storage

Handle file uploads securely and reliably. Understand multipart/form-data encoding and boundary streams. Implement server-side validation: checking file size limits, validating allowed MIME types and file extensions, inspecting magic bytes/signatures, and generating secure random UUID filenames (preventing directory traversal attacks). Serve user-uploaded assets with proper Content-Disposition and security headers.

▸
Optimistic UI Updates & Real-Time State Synchronization

Deliver ultra-responsive user experiences. Implement optimistic UI patterns: immediately updating client-side state when a user triggers an action (e.g. toggling a task checkbox, liking a post), while simultaneously dispatching the asynchronous API mutation. Implement robust rollback handlers to revert UI state if the backend rejects the transaction. Explore real-time synchronization patterns via Server-Sent Events (SSE) and WebSockets.

Day 7: Day 7: Production Deployment, Linux/EC2 Infrastructure & DevOps 3 subtopics
▸
Linux Server Administration & AWS EC2 Instance Hardening

Deploy applications to cloud infrastructure. Navigate Linux servers over SSH. Manage system users, file permissions (chmod, chown), and isolate web app directories (/var/www/apps/). Configure firewall rules using Uncomplicated Firewall (ufw) and AWS Security Groups (exposing ports 22, 80, 443 only). Manage sensitive environment variables securely using isolated .env files with restricted permissions (chmod 600).

▸
Reverse Proxying with Nginx & SSL/TLS Configuration

Configure Nginx as a high-performance reverse proxy and web server. Write robust Nginx server blocks that terminate SSL/TLS encryption, route traffic to internal application servers (http://127.0.0.1:5000), serve static files directly with gzip compression, buffer slow client requests, and enforce HTTP-to-HTTPS redirection. Obtain and automate free SSL/TLS certificates via Let's Encrypt and Certbot.

▸
Process Management with Gunicorn & Systemd Services

Run Python web applications continuously in production. Configure Gunicorn WSGI application servers: calculate worker pools based on CPU cores ((2 * CPU) + 1), handle request timeouts, and configure log file destinations. Write a Linux Systemd service unit (/etc/systemd/system/app.service) to daemonize the application, guarantee automatic restarts on failure or server reboot, and monitor health logs with journalctl.

Enrollment

Access type Free quota
Capstone project Required (DBERT verified)