Skip to main content
CodeOath
← All posts

Architecture & Patterns50 min total · 13 parts

Middleware Pipelines Compared: ASP.NET Core, Express.js, and Django

Part 13 of 13 · ~2 min

Common Mistakes Worth Remembering

  • Putting the CORS-answering layer below the routes that need its protection, so an incoming preflight request never actually reaches anything capable of answering it.
  • Leaving out next() in an Express middleware and expecting some kind of error or timeout to surface the mistake — nothing does; the request simply never resolves.
  • Leaving a costly lookup — a ShiftDesk call, an uncached database round trip — inside middleware that fires on every request, rather than scoping it down to the requests where the answer actually matters.
  • Treating position as irrelevant because "it's just a logger" — a log recorder sitting below auth in the list never gets a look at whatever auth already turned away, and any report built from it will undercount those rejections without anyone noticing.
  • Trusting that Express forwards a failed async call to error handling on its own — true starting with Express 5, false on 4 without an explicit .catch(next) tacked on.
  • Placing something meant to reshape the outgoing response — compression, a timing header — far enough down the list that nothing is left for it to actually wrap.
  • Constructor-injecting a scoped service into ASP.NET Core conventional middleware instead of accepting it as an InvokeAsync parameter — it will throw at startup rather than misbehave quietly, but only because the DI container catches the lifetime mismatch outright.
  • Matching a Django middleware's scope against a raw request.path string instead of the resolved view, via process_view — exactly the mistake that let RequireManagerMiddleware go silent after a URL refactor.
  • Repeating work that only ever needed to happen once — establishing a connection, priming a cache — inside the code path that runs per request, instead of doing it a single time when the process starts up.

Fernwood's ASP.NET Core prototype is built out in full, request handling and all, in Building REST APIs with ASP.NET Core; the Django prototype's surrounding framework concerns are covered in Django Fundamentals. Try wiring up a short pipeline of your own — including the ordering bug that got Marcus in trouble — in the code lab.