Skip to content
hardsenior1 min read #backend #express

How do you serve static assets securely? ​

Answer ​

Serve only a dedicated public directory, prevent path traversal through the framework static middleware, set appropriate cache and content-type headers, and never expose uploads or source files without explicit access control.

Context ​

Express is a minimal Node.js HTTP framework. Compose routes from small middleware functions, validate untrusted input at the boundary, and send errors to one consistent error handler.

Example ​

Consider a production Express change: define the expected behavior and failure modes first, implement the smallest observable change, then verify it with a focused test or measurement. The right implementation depends on the system boundary and its constraints.

Practical considerations ​

  1. Choose the approach from the requirement and constraints, not from habit.
  2. Include validation, error handling, and cleanup where the boundary requires them.
  3. Verify the observable result with focused tests or measurement.

Follow-up prompts ​

  • What failure mode would you expect if this were implemented incorrectly?
  • How would you test this behaviour?
  • What changes when the feature must scale to a larger application or team?

In practice ​

For this hard-level topic, make assumptions explicit, choose the smallest safe implementation, and verify the behavior at the relevant boundary.