Skip to content · ⁨الانتقال إلى المحتوى⁩

GAC017 Computing III: Data Science and Web Apps · ⁨GAC017 الحاسوب III: علوم البيانات وتطبيقات الويب⁩

GAC Computing · ⁨علوم الحاسب (GAC)⁩ · Topic 3 · ⁨الموضوع 3⁩

3.1

What this module is, and how it is marked · ⁨ما هي هذه الوحدة وكيفية تقييمها⁩

English

GAC017 is the Level III computing module: what sits behind a website. Six units cover back-end JavaScript, databases, SQL, connecting the two, and a first look at data science.

Assessment is entirely practical — a database 数据库 you design and build, a web app 网络应用 that talks to it, a data analysis project 数据分析项目, and coursework — usually spread across most of the semester rather than concentrated at the end.

  • The work is judged on whether it runs and answers a question, not on how much code there is.
  • ⚠ Design the database before you write a query. Almost every problem later is a table problem wearing a query's clothes.

Every SQL example here runs in the site's own code playground, and the SQL reference there is the fuller version of these notes.

العربية

GAC017 هو وحدة الحوسبة المستوى الثالث: ما يقع خلف موقع إلكتروني. ست وحدات تغطي الجانب الخلفي لجافاسكريبت، وقواعد البيانات، وSQL، والربط بينهما، ونظرة أولية على علوم البيانات.

التقييم عملي بالكامل — قاعدة بيانات تصممها وتبنيها، وتطبيق ويب يتواصل معها، ومشروع تحليل بيانات، وأعمال الفصل الدراسي — عادةً منتشرة على طول معظم الفصل الدراسي بدلاً من تركيزها في نهايته.

  • يُحكم على العمل بناءً على ما إذا كان يعمل ويجيب عن سؤال، وليس على كمية الكود الموجودة فيه.
  • ⚠ صمم قاعدة البيانات قبل كتابة الاستعلام. كل مشكلة تقريباً لاحقاً هي مشكلة في الجداول. ترتدي ملابس استعلام.

كل مثال SQL هنا يعمل في ملعب الكود الخاص بالموقع، المرجع لـ SQL هناك هو النسخة الأكثر شمولاً لهذه الملاحظات.

Vocabulary · ⁨مفردات⁩ Train · ⁨تدريب⁩
English العربية
SQL/ˌes kjuː ˈel/ SQL
3.1

JavaScript for a web app's back end · ⁨جافا سكريبت للواجهة الخلفية لتطبيق ويب⁩

Syllabus · ⁨المنهج⁩
English

Unit 1 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

Module purpose: On completion of this module, students should be able to create a web app. Students will learn about back- end programming and how to create a dynamic website. They will be able to use SQL to analyze data from multiple tables in order to make informed decisions.

The module outcomes this unit works towards:

Learning Objective GAC017.1: Understand the basic components of a Web Application.

العربية

الوحدة 1 من أصل 6 في GAC017 الحاسوب الثالث: علوم البيانات وتطبيقات الويب (المستوى الثالث). تُدرس الوحدة لمدة 40 ساعة دراسية تقريبًا بالإضافة إلى 20 ساعة من الدراسة المستقلة، وتُقيّم في مركز التعليم وتخضع للمراقبة من قِبل ACT — لا يوجد امتحان خارجي.

غرض الوحدة: عند إتمام هذه الوحدة، يجب أن يكون الطلاب قادرين على إنشاء تطبيق ويب. سيتعلمون عن برمجة الواجهة الخلفية وكيفية إنشاء موقع إلكتروني ديناميكي. كما سيكونون قادرين على استخدام SQL لتحليل البيانات من جداول متعددة من أجل اتخاذ قرارات مستنيرة.

مخرجات الوحدة التي تسهم فيها هذه الوحدة:

هدف التعلم GAC017.1: فهم المكونات الأساسية لتطبيق ويب.

Source: Cambridge International syllabus · ⁨المصدر: منهج كامبريدج الدولي⁩

English
  • The front end 前端 runs in the browser; the back end 后端 runs on a server and holds what the browser must not.
  • A server 服务器 receives a request 请求 and returns a response 响应. That loop is the whole architecture.
  • An API 应用程序接口 is the agreed shape of those requests and responses.
  • ⚠ Anything secret — a password, a key — belongs on the back end only. Code in a browser is readable by everyone who visits.
العربية
  • الواجهة الأمامية تعمل في المتصفح؛ الواجهة الخلفية تعمل على خادم وتحفظ ما يجب ألا يراه المتصفح.
  • الخادم يستقبل طلباً ويعيد استجابة. هذا التكرار هو بنية النظام بأكملها.
  • API هو الشكل المتفق عليه لتلك الطلبات والاستجابات.
  • ⚠ أي شيء سري — كلمة مرور، مفتاح — ينتمي إلى الواجهة الخلفية فقط. الكود في المتصفح مرئي للجميع الذين يزورونه.
Vocabulary · ⁨مفردات⁩ Train · ⁨تدريب⁩
English العربية
database/ˈdeɪtəbeɪs/ قاعدة بيانات
web app/web æp/ تطبيق ويب
data analysis project/ˈdeɪtə əˈnæləsɪs ˈprɒdʒekt/ مشروع تحليل البيانات
front end/frʌnt end/ واجهة أمامية
back end/bæk end/ واجهة خلفية
server/ˈsɜːvə/ الخادم
request/rɪˈkwest/ طلب
response/rɪˈspɒns/ الاستجابة
API/ˌeɪ piː ˈaɪ/ واجهة برمجة التطبيقات
route/ruːt/ طريق
Validate input/ˈvælɪdeɪt ˈɪnpʊt/ التحقق من صحة الإدخال
SQL injection/ˌes kjuː ˈel ɪnˈdʒekʃn/ حقن SQL
relational database/rɪˈleɪʃənl ˈdeɪtəbeɪs/ قاعدة بيانات علائقية
tables/ˈteɪblz/ الجداول
primary key/ˈpraɪməri kiː/ المفتاح الأساسي
foreign key/ˈfɒrən kiː/ المفتاح الأجنبي
Normalisation/ˌnɔːməlaɪˈzeɪʃn/ التعديل
entities/ˈentɪtiz/ الكائنات
3.2

Back-end programming · ⁨البرمجة الخلفية⁩

Syllabus · ⁨المنهج⁩
English

Unit 2 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.2: Adapt a back-end application using scripting languages to interact with databases.

العربية

الوحدة 2 من أصل 6 في GAC017 الحاسوب الثالث: علوم البيانات وتطبيقات الويب (المستوى الثالث). تُدرس الوحدة لمدة 40 ساعة دراسية تقريبًا بالإضافة إلى 20 ساعة من الدراسة المستقلة، وتُقيّم في مركز التعليم وتخضع للمراقبة من قِبل ACT — لا يوجد امتحان خارجي.

مخرجات الوحدة التي تسهم فيها هذه الوحدة:

هدف التعلم GAC017.2: تعديل تطبيق خلفي باستخدام لغات البرمجة للتفاعل مع قواعد البيانات.

Source: Cambridge International syllabus · ⁨المصدر: منهج كامبريدج الدولي⁩

English
  • A route 路由 maps a URL to code that runs when that URL is requested.
  • Validate input 校验输入 on the server. Checking in the browser is a convenience for honest users, not a defence.
  • Never build a query by joining strings with user input. That is how SQL injection SQL 注入 happens, and it is the security failure this unit exists to prevent.
  • Return an honest status: 200 for success, 400 for a bad request, 404 for something that is not there.
العربية
  • المسار يربط عنوان URL بكود يعمل عند طلب ذلك العنوان.
  • تحقق من المدخلات على الخادم. التحقق في المتصفح مجرد راحة للمستخدمين الصادقين، وليس دفاعاً.
  • لا تبني استعلاماً أبداً عن طريق دمج السلاسل النصية مع مدخلات المستخدم. هكذا يحدث إدراج SQL يحدث SQL، وهو الفشل الأمني الذي تم إنشاء هذه الوحدة لمنعهم منه.
  • أعد حالة صادقة: 200 للنجاح، 400 لطلب سيء، 404 لشيء غير موجود. غير موجود.
3.3

Introduction to databases · ⁨مقدمة في قواعد البيانات⁩

Syllabus · ⁨المنهج⁩
English

Unit 3 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.3: Create a database with multiple tables.

العربية

الوحدة 3 من أصل 6 في GAC017 الحاسوب الثالث: علوم البيانات وتطبيقات الويب (المستوى الثالث). تُدرس الوحدة لمدة 40 ساعة دراسية تقريبًا بالإضافة إلى 20 ساعة من الدراسة المستقلة، وتُقيّم في مركز التعليم وتخضع للمراقبة من قِبل ACT — لا يوجد امتحان خارجي.

مخرجات الوحدة التي تسهم فيها هذه الوحدة:

هدف التعلم GAC017.3: إنشاء قاعدة بيانات تحتوي على جداول متعددة.

Source: Cambridge International syllabus · ⁨المصدر: منهج كامبريدج الدولي⁩

English
  • A relational database 关系数据库 stores data in tables 表 of rows and columns.
  • A primary key 主键 identifies a row uniquely. A foreign key 外键 points at another table's primary key, and that pointer is the relationship.
  • Normalisation 规范化 removes duplicated data so one fact lives in one place.
  • Design by asking what the entities 实体 are, then what connects them.

Worked example. A school wants to store students, courses and who takes what.

Two tables cannot do it: a student takes many courses and a course has many students. The many-to-many needs a third table — enrolments — whose rows are (student, course) pairs.

Recognising that this third table is required is the single most useful database idea in the module, and it is where most first designs go wrong.

العربية
  • قاعدة البيانات العلاقية تخزن البيانات في جداول من صفوف وأعمدة.
  • المفتاح الأساسي يحدد صفًا بشكل فريد. المفتاح الأجنبي يشير إلى المفتاح الأساسي لجدول آخر، وهذا المؤشر هو العلاقة.
  • التطبيع يزيل البيانات المكررة بحيث يعيش حقيقة واحدة في مكان واحد.
  • صمم بسؤال ما هي الكائنات، ثم ما الذي يربطها.

مثال محلول. تريد مدرسة تخزين الطلاب والدورات ومن يأخذ ماذا.

لا يمكن لجداول أن تفعل ذلك: الطالب يأخذ دورات عديدة والدورة لها طلاب كثيرون. تحتاج العلاقة Many-to-Many إلى جدول ثالث — التسجيلات — whose rows are (student, course) pairs.

إدراك أن هذا الجدول الثالث مطلوب هو فكرة قاعدة بيانات مفيدة وحيدة في الوحدة، وهو حيث تخطأ معظم التصاميم الأولى.

3.4

SQL for back-end programming · ⁨SQL للبرمجة الخلفية⁩

Syllabus · ⁨المنهج⁩
English

Unit 4 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.4: Analyze data using SQL in order to make decisions.

العربية

الوحدة 4 من أصل 6 في GAC017 الحاسوب الثالث: علوم البيانات وتطبيقات الويب (المستوى الثالث). تُدرس الوحدة لمدة 40 ساعة دراسية تقريبًا بالإضافة إلى 20 ساعة من الدراسة المستقلة، وتُقيّم في مركز التعليم وتخضع للمراقبة من قِبل ACT — لا يوجد امتحان خارجي.

مخرجات الوحدة التي تسهم فيها هذه الوحدة:

هدف التعلم GAC017.4: تحليل البيانات باستخدام SQL لاتخاذ القرارات.

Source: Cambridge International syllabus · ⁨المصدر: منهج كامبريدج الدولي⁩

English
  • SQL 结构化查询语言 asks a database questions. SELECT … FROM … WHERE … is the core.
  • JOIN 连接 combines rows from two tables on a matching key.
  • GROUP BY 分组 with COUNT, SUM or AVG answers "how many per…" questions.
  • ⚠ WHERE filters rows before grouping; HAVING filters groups after. Using the wrong one is the classic SQL error, and it usually returns a plausible wrong answer.

Worked example. Which courses have more than 20 students?

The count is a property of the group, so the filter is HAVING. Written with WHERE it does not run — and when a similar mistake does run, it silently answers a different question.

العربية
  • SQL يطرح أسئلة على قاعدة بيانات. SELECT … FROM … WHERE … هو الأساس.
  • JOIN يدمج صفوفًا من جدولين على مفتاح متطابق.
  • GROUP BY مع COUNT، SUM أو AVG يجيب عن أسئلة
  • ⚠ WHERE يفلتر الصفوف قبل التجميع؛ HAVING يفلتر المجموعات بعد ذلك. استخدام الفلتر الخاطئ هو الخطأ الكلاسيكي في SQL، وعادة ما يعطي إجابة خاطئة تبدو معقولة.

مثال محلول. أي الدورات تحتوي على أكثر من 20 طالب؟

SELECT c.title, COUNT(*) AS students
FROM enrolments e
JOIN courses c ON c.id = e.course_id
GROUP BY c.title
HAVING COUNT(*) > 20;

العدّ خاصية للمجموعة، لذا فإن الفلتر يجب أن يكون HAVING. إذا كُتب باستخدام WHERE فلن يعمل — وعندما يحدث خطأ مشابه ويعمل فعلاً، يجيب بصمت عن سؤال مختلف.

Vocabulary · ⁨مفردات⁩ Train · ⁨تدريب⁩
English العربية
JOIN/dʒɔɪn/ JOIN
GROUP BY/ɡruːp baɪ/ GROUP BY
parameterised query/ˌpærəˈmetəraɪzd ˈkwɪərɪ/ استعلام معياري
3.5

Connecting JavaScript with SQL · ⁨الربط بين جافاسكريبت وSQL⁩

Syllabus · ⁨المنهج⁩
English

Unit 5 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.2: Adapt a back-end application using scripting languages to interact with databases.

Learning Objective GAC017.4: Analyze data using SQL in order to make decisions.

العربية

الوحدة 5 من أصل 6 في GAC017 الحاسوب الثالث: علوم البيانات وتطبيقات الويب (المستوى الثالث). تُدرس الوحدة لمدة 40 ساعة دراسية تقريبًا بالإضافة إلى 20 ساعة من الدراسة المستقلة، وتُقيّم في مركز التعليم وتخضع للمراقبة من قِبل ACT — لا يوجد امتحان خارجي.

مخرجات الوحدة التي تسهم فيها هذه الوحدة:

هدف التعلم GAC017.2: تعديل تطبيق خلفي باستخدام لغات البرمجة للتفاعل مع قواعد البيانات.

هدف التعلم GAC017.4: تحليل البيانات باستخدام SQL لاتخاذ القرارات.

Source: Cambridge International syllabus · ⁨المصدر: منهج كامبريدج الدولي⁩

English
  • The back end takes a request, runs a parameterised query 参数化查询, and returns the rows as data, usually JSON 数据交换格式.
  • Parameterised means the values travel separately from the query text. That is what makes injection impossible rather than unlikely.
  • Handle the empty case. A query that returns no rows is normal, and a page that breaks on it is not finished.
العربية
  • يأخذ الجانب الخلفي الطلب، وينفذ استعلامًا مُعاملًا، ويعيد الصفوف كـ بيانات، عادةً بصيغة JSON.
  • يعني المُعامَل أن القيم تنتقل منفصلة عن نص الاستعلام. وهذا ما يجعل الإدخال غير ممكن بدلاً من مجرد مستبعد.
  • تعامل مع الحالة الفارغة. استعلام لا يُرجع أي صف أمر طبيعي، وصفحة تنهار عند encountering thereof غير مكتملة.
Vocabulary · ⁨مفردات⁩ Train · ⁨تدريب⁩
English العربية
JSON/ˈdʒeɪsn/ JSON
Data science/ˈdeɪtə ˈsaɪəns/ علوم البيانات
Descriptive statistics/dɪˈskrɪptɪv stəˈtɪstɪks/ الإحصاء الوصفي
visualisation/ˌvɪʒuːəlaɪˈzeɪʃn/ التصور البياني
Correlation is not causation/ˌkɒrɪˈleɪʃn ɪz nɒt kɔːˈseɪʃn/ الارتباط لا يعني السببية
3.6

Data science · ⁨علوم البيانات⁩

Syllabus · ⁨المنهج⁩
English

Unit 6 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.5: Applying Data Science to other academic areas.

العربية

الوحدة 6 من أصل 6 في GAC017 الحوسبة III: علوم البيانات والتطبيقات الويب (المستوى الثالث). تُدرَّس الوحدة خلال حوالي 40 ساعة دراسية بالإضافة إلى 20 ساعة من الدراسة المستقلة، وتُقيَّم في مركز التدريس وتخضع لمراجعة ACT — لا يوجد امتحان خارجي.

مخرجات الوحدة التي تسهم فيها هذه الوحدة:

هدف التعلم GAC017.5: تطبيق علوم البيانات على مجالات أكاديمية أخرى.

Source: Cambridge International syllabus · ⁨المصدر: منهج كامبريدج الدولي⁩

English
  • Data science 数据科学 turns data into a decision, and most of the work is before the analysis: cleaning, joining, and checking what the data can support.
  • Descriptive statistics 描述性统计 summarise; a visualisation 可视化 shows shape; neither proves a cause.
  • Correlation is not causation 相关不等于因果 — the sentence every data project needs and most omit.
  • State the limitations of your dataset. A project that names what its data cannot show scores above one that quietly overclaims.
العربية
  • علوم البيانات تحوّل البيانات إلى قرار، ومعظم العمل يتم قبل التحليل: التنظيف، والدمج، والتحقق مما يمكن للبيانات دعمه.
  • الإحصاء الوصفي يُلخّص؛ والتصور البصري يُظهر الشكل؛ ولا شيء منهما يثبت سببية.
  • الارتباط ليس سببية — الجملة التي يحتاجها كل مشروع بيانات ومعظم يتجاهلها.
  • اذكر قيود مجموعة البيانات الخاصة بك. المشروع الذي يحدد ما لا يمكن لبياناته إظهاره يحصل على درجة أعلى من مشروع يتكبر بصمت.
Additional notes PDF

Follow one request from browser to database

A teacher asks which clubs have places left. A spreadsheet can answer once. A web app lets a reader ask again with a different filter.

Our example has four students, four classes and five enrolments. All records are invented. It is a learning project, not a school booking service.

The three parts have different jobs:

Part Job in the example Runs where?
Browser page Collect a minimum and show a table The reader's browser
JavaScript server Check the request and run the query The local server
SQLite database Store related records and calculate course totals Inside this server process

An HTTP request 请求信息 asks for a resource. An HTTP response 响应信息 contains a status and content. The browser sends GET /api/courses?min=2. The server checks the number, then asks SQLite for course totals. It returns a JSON object 数据对象. The browser reads that object and creates table cells. The database does not send HTML to the browser. The browser does not run our server's SQL.

Start the supplied three-file example with node server.mjs. Open the address it prints. Use Node.js 22.13 or newer with the built-in SQLite module available. Keep server.mjs, index.html and courses.sql together in your own working copy. No account or package download is needed. Stop your own server with Ctrl-C.

Get the complete example files from the site's static teaching folder:

  • /static/teaching/gac_computing/database-app/server.mjs
  • /static/teaching/gac_computing/database-app/courses.sql
  • /static/teaching/gac_computing/database-app/index.html.txt
  • /static/teaching/gac_computing/database-app/README.txt

Save the first two with their shown names. Save index.html.txt as index.html. The last file has the full run and adaptation instructions. Use these paths after the site's address. The page file is supplied as text for downloading. It must run through your local example server to reach the matching API.

This example uses an in-memory database 内存数据库. Restarting creates the original records again. A file database could keep changes after restart. That needs a different storage choice.

Design relationships before writing queries

Each student has one row in students. Each class has one row in courses. An enrolment links a student to a class. A student may join several classes. A class may contain several students. This is a many-to-many relationship 多对多关系. The third table stores one student–class pair per row.

Student 1 joins courses 10 and 20. Course 10 contains students 1, 2 and 3. The same student name need not be repeated in each enrolment row. To change Mei's name, change one student record. This avoids conflicting copies.

The following two blocks form one complete script. Run them in order in a new empty practice database. Do not run it against an existing project database.

PRAGMA foreign_keys = ON;
CREATE TABLE students (
  id INTEGER PRIMARY KEY,
  name TEXT NOT NULL
);
CREATE TABLE courses (
  id INTEGER PRIMARY KEY,
  title TEXT NOT NULL,
  capacity INTEGER NOT NULL CHECK (capacity >= 0)
);
CREATE TABLE enrolments (
  student_id INTEGER NOT NULL REFERENCES students(id),
  course_id INTEGER NOT NULL REFERENCES courses(id),
  PRIMARY KEY (student_id, course_id)
);

The tables now exist. Add the fictional records, then query totals for each class.

INSERT INTO students VALUES
  (1, 'Mei'), (2, 'Kai'), (3, 'Lin'), (4, 'Jia');
INSERT INTO courses VALUES
  (10, 'Coding', 3), (20, 'Coding', 2),
  (30, 'Art', 2), (40, 'Music', 3);
INSERT INTO enrolments VALUES
  (1, 10), (2, 10), (3, 10), (1, 20), (4, 30);
SELECT c.id, c.title, c.capacity,
       COUNT(e.student_id) AS enrolled
FROM courses c
LEFT JOIN enrolments e ON c.id = e.course_id
GROUP BY c.id, c.title, c.capacity
ORDER BY enrolled DESC, c.id;

A constraint 约束 rejects data that breaks a rule. NOT NULL requires a value. CHECK (capacity >= 0) rejects negative capacity. The paired primary key rejects a repeated enrolment, such as (1,10) twice. Either ID may appear in many pairs. The pair itself must be unique.

Foreign keys reject missing students or classes when foreign-key checking is enabled. The script enables that checking explicitly. A foreign key does not create the missing row. These rules do not prevent every error. For example, capacity 3 does not itself limit enrolments to 3. A real booking operation would need a capacity check and safe handling of simultaneous bookings.

Count classes without losing empty ones

Courses 10 and 20 both have the title Coding. They are different classes. Group by the course ID as well as its title and capacity. Grouping only by title would merge their enrolments and answer the wrong question.

LEFT JOIN keeps every course, including Music with no enrolments. The unmatched course has an empty enrolment side. COUNT(e.student_id) counts matched student IDs and gives zero for Music. COUNT(*) counts the joined row, including that unmatched row, and would give Music one.

ID Course Capacity Enrolled Places left
10 Coding 3 3 0
20 Coding 2 1 1
30 Art 2 1 1
40 Music 3 0 3

The browser calculates places left as capacity minus enrolled. There are five enrolments but only four students. Mei appears in two enrolment rows. Do not label five as the number of unique students.

To keep classes with at least two enrolments, add this line after GROUP BY:

HAVING COUNT(e.student_id) >= 2

This is a query fragment, added to the complete query. It returns course 10 only. HAVING checks each group total. WHERE checks individual rows before totals are calculated. For example, WHERE c.id = 20 selects one class before grouping; it does not test its total.

Validate and bind the backend input

The route /api/courses accepts a minimum from 0 to 99. The browser number control helps users enter it. Direct requests can skip that control. The server therefore checks the input again.

It rejects negative numbers, decimals, 100, repeated minimum parameters and text. Missing min means zero. A successful query with no courses is still a valid request.

Request Status Meaning
GET /api/courses?min=2 200 One course found
GET /api/courses?min=4 200 Valid query; empty list
GET /api/courses?min=-1 400 Invalid input
GET /missing 404 Route does not exist
POST /api/courses 405 This read-only route accepts GET

A prepared statement 预编译语句 keeps the SQL structure separate from a value. The server prepares its total-by-course query with >= ?, then calls courses.all(minimum). The bound number fills the value position. It is not joined into the SQL text.

Binding values protects this query from injection through that value. It does not prove that every route or operation is secure. SQL keywords and column names cannot be supplied as ordinary bound values. Keep the query structure fixed or choose it from permitted server-owned choices.

The server sends public course totals only. Student names stay out of this response. Real records would also need access rules and permission to use them. An invented example needs no real student information.

Handle loading, empty results and failures

The browser uses fetch to request the data. It must check the response status. A completed network request may still return 400 or 500. The browser's response.ok distinguishes successful HTTP responses from those errors.

The page clears old rows before loading. Otherwise a failed request could leave old results looking current. It displays a loading message and disables the load button during the request. It then shows the result, an empty message, or a failure message. The button becomes available again so the reader can retry.

Each displayed value goes into textContent, not into HTML built from a data string. A course title becomes text inside a cell. It is not treated as page markup.

The sample uses a request number to ignore an older response after a newer request starts. This protects the page from a late response replacing the newest result. It does not change database records or make bookings safe.

Try minimum 0, 2 and 4 in that order. Expect four courses, one course and no courses. Then stop the server and try loading again. The page should explain the failure and allow a retry. Restart the server and load again. The original fictional dataset should return.

Turn results into a supported academic decision

Begin with a question: which classes currently have spare places? State your unit of analysis 分析单位: one class, identified by course ID. Check missing values, repeated enrolment pairs, valid IDs and non-negative capacities before analysis. Name the data date in a real report, because enrolments can change.

The current answer is Coding 20, Art 30 and Music 40. Music has three spare places; the other two have one each. A teacher could first check whether those places are still available before announcing them.

A bar chart could compare enrolled and capacity for each course ID. Keep the two Coding classes separate and label them with their IDs. Show zero enrolments for Music. Do not hide it because its bar is short.

Explain the limitation 局限 of this decision. These records describe four invented classes at one time. They do not measure teaching quality, future demand or why students chose a class. More enrolments do not prove that a class caused better learning. Avoid using a descriptive count as evidence for a causal claim.

A short report can use five parts: question, data and checks, method, result, limits and next action. Include the query or name the calculation so another reader can reproduce the result. Keep student and enrolment counts separate.

Practise with changes and explain your answers

  1. Sketch the three tables. Which keys link them, and why is the third table needed?
  2. Predict minimum 1 and minimum 3 before running either request.
  3. Replace COUNT(e.student_id) with COUNT(*). Which original result becomes wrong, and why?
  4. Group only by title. What happens to the two Coding classes?
  5. Add course 50, Drama, with capacity 2 and no enrolments. Predict its total and free places.
  6. Add enrolment (2,20). What should minimum 2 now return?
  7. Try duplicate pair (1,10) and missing student pair (99,10). Explain each rejection.
  8. Why must the server check a minimum that the browser already checks?
  9. Explain why an empty array gets 200, while a negative minimum gets 400.
  10. Write a two-sentence recommendation and one limitation using the original data.

Explained answers

  1. Student ID and course ID link the paired enrolment table to their parent tables. The third table represents many students in many classes without repeating names or course facts.
  2. Minimum 1 returns 10, 20 and 30. Minimum 3 returns 10 only. Both filters include equality.
  3. Music becomes one instead of zero. COUNT(*) counts the preserved unmatched course row.
  4. Coding totals combine to four. This describes a title group, not either individual class.
  5. Drama has zero enrolments and two places left. A left join keeps it at minimum 0.
  6. Coding 20 now has two enrolments. Minimum 2 returns IDs 10 and 20, with totals three and two.
  7. The paired primary key rejects the duplicate. The enabled foreign key rejects student 99, who does not exist.
  8. A caller can send a request without using the page. Browser checks cannot protect the server by themselves.
  9. No matching rows is a successful query. A negative minimum breaks the API's input rule.
  10. Check remaining places in Coding 20, Art 30 and Music 40 before offering them. Music has most spare places in this example. Invented totals cannot predict actual student demand.

Interactive lessons on this topic · ⁨دروس تفاعلية حول هذا الموضوع⁩

Work through it step by step, with instant-check exercises. · ⁨ا-working عليه خطوة بخطوة، مع تمارين تحقق فوري.⁩

More topics in GAC Computing · ⁨علوم الحاسب (GAC)⁩ · ⁨المزيد من المواضيع في GAC Computing · ⁨علوم الحاسب (GAC)⁩⁩

Log in or create account · ⁨تسجيل الدخول أو إنشاء حساب⁩

IGCSE, A-Level & AP