Skip to content · ⁨דלג לתוכן⁩

GAC017 Computing III: Data Science and Web Apps · ⁨GAC017 מחשוב III: מדע נתונים ואפליקציות רשת⁩

GAC Computing · ⁨גאק מחשבים⁩ · Topic 3 · ⁨נושא 3⁩

3.1

What this module is, and how it is marked · ⁨מהו המודול הזה וכיצד הוא מצומד⁩

English

GAC017 is the Level III computing module: what sits behind a website. Six units cover back-end JavaScript, databases, SQL, connecting the two, and a first look at data science.

Assessment is entirely practical — a database 数据库 you design and build, a web app 网络应用 that talks to it, a data analysis project 数据分析项目, and coursework — usually spread across most of the semester rather than concentrated at the end.

  • The work is judged on whether it runs and answers a question, not on how much code there is.
  • ⚠ Design the database before you write a query. Almost every problem later is a table problem wearing a query's clothes.

Every SQL example here runs in the site's own code playground, and the SQL reference there is the fuller version of these notes.

עברית

GAC017 היא יחידת מחשוב ברמה III: מה שמעומד מאחורי אתר אינטרנט. שש יחידות מכסות JavaScript בצד השרת, מסדי נתונים, SQL, חיבור בין השניים ומבט ראשון למדעי נתונים. JavaScript, בסיסי נתונים, SQL, חיבור השניים, ומבט ראשון למדע נתונים.

ההערכה היא כולה מעשית — מסד נתונים שתעצב ותבנה, **אפליקציית אינטרנט שמדברת איתו, פרויקט ניתוח נתונים, ועבודות בית — לרוב מתפשטות לאורך רוב הסמסטר ולא מתרכזות בסוף.

  • העבודה נבחנת לפי האם היא פועלת ומשיבה שאלה, ולא לפי כמות הקוד.
  • ⚠ עצב את מסד הנתונים לפני שכתוב query. כמעט כל בעיה בעתיד היא בעיית טבלה לבושה בבגדי query.

כל דוגמת SQL כאן פועלת בסביבת הקוד המובנית באתר, והמאגר המיושם שם הוא הגרסה המלאה של הערות אלו.

Vocabulary · ⁨מילון מונחים⁩ Train · ⁨אימון⁩
English עברית
SQL/ˌes kjuː ˈel/ SQL
3.1

JavaScript for a web app's back end · ⁨JavaScript לגב-עולמי של אפליקציית אינטרנט⁩

Syllabus · ⁨סיילבוס⁩
English

Unit 1 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

Module purpose: On completion of this module, students should be able to create a web app. Students will learn about back- end programming and how to create a dynamic website. They will be able to use SQL to analyze data from multiple tables in order to make informed decisions.

The module outcomes this unit works towards:

Learning Objective GAC017.1: Understand the basic components of a Web Application.

עברית

יחידה 1 מתוך 6 ב-GAC017 מחשוב III: מדעי נתונים ואפליקציות רשת (רמה III). המודול מוסר במשך כ-40 שעות לימוד פנים-ביתיות ועוד 20 שעות לימוד עצמאי, וממוסד בכפר הלימודים ומווסת על ידי ACT — אין מבחן חיצוני.

מטרת המודול: בסיום מודול זה, הסטודנטים אמורים להיות מסוגלים ליצור אפליקציית רשת. הם ילמדו על תכנות גבול-אתר וכיצד ליצור אתר דינמי. הם יוכלו להשתמש ב-SQL לניתוח נתונים ממספר טבלאות כדי קבלת החלטות מוצדקות.

תוצאות המודול שהיחידה הזו שואפת להשיג:

מטרות למידה GAC017.1: להבין את המרכיבים הבסיסיים של אפליקציית רשת.

Source: Cambridge International syllabus · ⁨מקור: הסיילבוס הבינלאומי של קמבריד'ג'⁩

English
  • The front end 前端 runs in the browser; the back end 后端 runs on a server and holds what the browser must not.
  • A server 服务器 receives a request 请求 and returns a response 响应. That loop is the whole architecture.
  • An API 应用程序接口 is the agreed shape of those requests and responses.
  • ⚠ Anything secret — a password, a key — belongs on the back end only. Code in a browser is readable by everyone who visits.
עברית
  • חזית (Front End) פועלת בדפדפן; גב-עולמי (Back End) פועל על סדר ומוחזק מה שהדפדפן לא אמור לראות.
  • סדר מקבל בקשה ומשיב עם תשובה. מחזור זה הוא כל הארכיטקטורה. הארכיטקטורה כולה.
  • ⚠ כל דבר סודי — סיסמה, מפתח — נמצא רק בגב-עולמי. קוד בדפדפן נגלה לכל מי שמבקר.
  • ⚠ כל דבר סודי — סיסמה, מפתח — שייך רק לגבול. קוד בדפדפן הוא נגיש לכולם שמבקרים בו.
Vocabulary · ⁨מילון מונחים⁩ Train · ⁨אימון⁩
English עברית
database/ˈdeɪtəbeɪs/ מאגר נתונים
web app/web æp/ אפליקציית אינטרנט
data analysis project/ˈdeɪtə əˈnæləsɪs ˈprɒdʒekt/ פרויקט ניתוח נתונים
front end/frʌnt end/ חזית (Front End)
back end/bæk end/ צד שרת (Back End)
server/ˈsɜːvə/ שרת
request/rɪˈkwest/ בקשה
response/rɪˈspɒns/ תגובה
API/ˌeɪ piː ˈaɪ/ API
route/ruːt/ מסלול
Validate input/ˈvælɪdeɪt ˈɪnpʊt/ אישור תקפות קלט
SQL injection/ˌes kjuː ˈel ɪnˈdʒekʃn/ הזרקת SQL
relational database/rɪˈleɪʃənl ˈdeɪtəbeɪs/ מאגר מידע יחסי
tables/ˈteɪblz/ טבלאות
primary key/ˈpraɪməri kiː/ מפתח ראשי
foreign key/ˈfɒrən kiː/ מפתח זר
Normalisation/ˌnɔːməlaɪˈzeɪʃn/ נורמליזציה
entities/ˈentɪtiz/ אנטיטיות
3.2

Back-end programming · ⁨תכנות גבול⁩

Syllabus · ⁨סיילבוס⁩
English

Unit 2 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.2: Adapt a back-end application using scripting languages to interact with databases.

עברית

יחידה 2 מתוך 6 ב-GAC017 מחשוב III: מדעי נתונים ואפליקציות רשת (רמה III). המודול מוסר במשך כ-40 שעות לימוד פנים-ביתיות ועוד 20 שעות לימוד עצמאי, וממוסד בכפר הלימודים ומווסת על ידי ACT — אין מבחן חיצוני.

תוצאות המודול שהיחידה הזו שואפת להשיג:

מטרות למידה GAC017.2: להתאים אפליקציית גבול-אתר באמצעות שפות סקריפט כדי לתקשר עם מאגרי נתונים.

Source: Cambridge International syllabus · ⁨מקור: הסיילבוס הבינלאומי של קמבריד'ג'⁩

English
  • A route 路由 maps a URL to code that runs when that URL is requested.
  • Validate input 校验输入 on the server. Checking in the browser is a convenience for honest users, not a defence.
  • Never build a query by joining strings with user input. That is how SQL injection SQL 注入 happens, and it is the security failure this unit exists to prevent.
  • Return an honest status: 200 for success, 400 for a bad request, 404 for something that is not there.
עברית
  • אמתנת כניסה על הסדר. בדיקה בדפדפן נועדה לנוחות משתמשים כנים, אך אינה הגנה.
  • לעולם אל תבנה שאלה על ידי חיבור מחרוזות עם כניסת משתמש. כך מתרחשת הצרת SQL, השקעה, והיא הכשל הבטיחותי שיקום זה נוצר למנועתו.
  • לעולם אל תבנה שאלה על ידי הצמדת מחרוזות עם קלט משתמש. כך מתרחשת הזרקת SQL, SQL והיא הכשל הבטיחותי שיעד זה קיים למניעתו.
  • החזר סטטוס כנה: 200 להצלחה, 400 לבקשה שגויה, 404 לדבר שאינו קיים.
3.3

Introduction to databases · ⁨מבוא למאגרי נתונים⁩

Syllabus · ⁨סיילבוס⁩
English

Unit 3 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.3: Create a database with multiple tables.

עברית

יחידה 3 מתוך 6 ב-GAC017 מחשוב III: מדעי נתונים ואפליקציות רשת (רמה III). המודול מוסר במשך כ-40 שעות לימוד פנים-ביתיות ועוד 20 שעות לימוד עצמאי, וממוסד בכפר הלימודים ומווסת על ידי ACT — אין מבחן חיצוני.

תוצאות המודול שהיחידה הזו שואפת להשיג:

מטרות למידה GAC017.3: ליצור בסיס נתונים עם מספר טבלאות.

Source: Cambridge International syllabus · ⁨מקור: הסיילבוס הבינלאומי של קמבריד'ג'⁩

English
  • A relational database 关系数据库 stores data in tables 表 of rows and columns.
  • A primary key 主键 identifies a row uniquely. A foreign key 外键 points at another table's primary key, and that pointer is the relationship.
  • Normalisation 规范化 removes duplicated data so one fact lives in one place.
  • Design by asking what the entities 实体 are, then what connects them.

Worked example. A school wants to store students, courses and who takes what.

Two tables cannot do it: a student takes many courses and a course has many students. The many-to-many needs a third table — enrolments — whose rows are (student, course) pairs.

Recognising that this third table is required is the single most useful database idea in the module, and it is where most first designs go wrong.

עברית
  • בסיס נתונים יחסי מאחסן מידע ב-טבלאות של שורות ועמודות.
  • מפתח ראשי מזהה שורה באופן ייחודי. מפתח זר מצביע על טבלה אחרת. המפתח הראשי של הטבלה, והרמז הוא הקשר.
  • ניקיון מסיר נתונים כפולים כדי שכל עובדה תתועד במקום אחד בלבד.
  • עיצוב על ידי השאלה: מה הן ה-אנטיות, ואילו גורמים מקשרים ביניהן.

דוגמה מפורטת. בית ספר רוצה לאחסן נתוני תלמידים, קורסים ומי לומד מה.

שתי טבלאות אינן יכולות לעשות זאת: תלמיד לומד קורסים רבים וקורס יש לו תלמידים רבים. לכן יחס רב-לרב דורש טבלאה שלישית — הרשמות — שבה כל שורה מייצגת זוג (תלמיד, קורס).

הבנה שהטבלאה השלישייה נדרשת היא הרעיון הבסיסי המועיל ביותר בנתב והיא גם המקום בו רוב העיצובים ההתחלתיים נכשלים.

3.4

SQL for back-end programming · ⁨SQL לתכנות צד שרת⁩

Syllabus · ⁨סיילבוס⁩
English

Unit 4 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.4: Analyze data using SQL in order to make decisions.

עברית

יחידה 4 מתוך 6 ב-GAC017 מחשבים III: מדע נתונים ואפליקציות אתר (רמה III). המודול מיועד ללמידה במשך כ-40 שעות לימוד פנים-ביתיות ועוד 20 שעות למידה עצמאית, והוא מוערך במרכז ההוראה ומטופל על ידי ACT — אין מבחן חיצוני.

תוצאות המודול שהיחידה הזו שואפת להשיג:

מטרות למידה GAC017.4: ניתוח נתונים באמצעות SQL כדי לקבל החלטות.

Source: Cambridge International syllabus · ⁨מקור: הסיילבוס הבינלאומי של קמבריד'ג'⁩

English
  • SQL 结构化查询语言 asks a database questions. SELECT … FROM … WHERE … is the core.
  • JOIN 连接 combines rows from two tables on a matching key.
  • GROUP BY 分组 with COUNT, SUM or AVG answers "how many per…" questions.
  • ⚠ WHERE filters rows before grouping; HAVING filters groups after. Using the wrong one is the classic SQL error, and it usually returns a plausible wrong answer.

Worked example. Which courses have more than 20 students?

The count is a property of the group, so the filter is HAVING. Written with WHERE it does not run — and when a similar mistake does run, it silently answers a different question.

עברית
  • SQL שואל שאלות ממאגר נתונים. SELECT … FROM … WHERE … הוא ליבתו.
  • JOIN משלב שורות משתי טבלאות לפי מפתח תואם.
  • GROUP BY עם COUNT, SUM או AVG מענה לשאלות "כמה בכל…".
  • ⚠ WHERE מסנן שורות לפני הקבוצות; HAVING מסנן קבוצות אחר כך. שימוש באחד מהם בשגוי הוא השגיאה הקלאסית ביותר ב-SQL, והיא בדרך כלל מחזירה תשובה פסולה אך סבירה למראה.

דוגמה מפורטת. אילו קורסים יש בהם יותר מ-20 תלמידים?

SELECT c.title, COUNT(*) AS students
FROM enrolments e
JOIN courses c ON c.id = e.course_id
GROUP BY c.title
HAVING COUNT(*) > 20;

הספירה היא מאפיין של הקבוצה, ולכן הסנן הוא HAVING. אם הכתיב עם WHERE הקוד לא יעבוד — וכשהשגיאה הדומה הזו עדיין מתבצעת, היא משיבה במסתוריות תשובה לשאלה אחרת.

Vocabulary · ⁨מילון מונחים⁩ Train · ⁨אימון⁩
English עברית
JOIN/dʒɔɪn/ הצטרף
GROUP BY/ɡruːp baɪ/ קבץ לפי
parameterised query/ˌpærəˈmetəraɪzd ˈkwɪərɪ/ שאלה מופרמטרית
3.5

Connecting JavaScript with SQL · ⁨חיבור JavaScript עם SQL⁩

Syllabus · ⁨סיילבוס⁩
English

Unit 5 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.2: Adapt a back-end application using scripting languages to interact with databases.

Learning Objective GAC017.4: Analyze data using SQL in order to make decisions.

עברית

יחידה 5 מתוך 6 ב-GAC017 מחשבים III: מדע נתונים ואפליקציות אתר (רמה III). המודול מיועד ללמידה במשך כ-40 שעות לימוד פנים-ביתיות ועוד 20 שעות למידה עצמאית, והוא מוערך במרכז ההוראה ומטופל על ידי ACT — אין מבחן חיצוני.

תוצאות המודול שהיחידה הזו שואפת להשיג:

מטרות למידה GAC017.2: להתאים אפליקציית גבול-אתר באמצעות שפות סקריפט כדי לתקשר עם מאגרי נתונים.

מטרות למידה GAC017.4: ניתוח נתונים באמצעות SQL כדי לקבל החלטות.

Source: Cambridge International syllabus · ⁨מקור: הסיילבוס הבינלאומי של קמבריד'ג'⁩

English
  • The back end takes a request, runs a parameterised query 参数化查询, and returns the rows as data, usually JSON 数据交换格式.
  • Parameterised means the values travel separately from the query text. That is what makes injection impossible rather than unlikely.
  • Handle the empty case. A query that returns no rows is normal, and a page that breaks on it is not finished.
עברית
  • הצד השרתי לוקח בקשה, מבצע שאלה פרמטרית, ומחזיר את השורות כ- נתונים, בדרך כלל בתצורת JSON.
  • משמעות פרמטריזציה היא שהערכים עוברים בנפרד מטקסט השאלה. זה מה שגורם ל- הזרקה להיות בלתי אפשרית ולא רק לא סביר.
  • התמודדות עם המקרה הריק. שאלה שאינה מחזירה שורות היא נורמלית, ועמוד שנשבר בשל כך הוא לא גמור.
Vocabulary · ⁨מילון מונחים⁩ Train · ⁨אימון⁩
English עברית
JSON/ˈdʒeɪsn/ JSON
Data science/ˈdeɪtə ˈsaɪəns/ מדעי נתונים
Descriptive statistics/dɪˈskrɪptɪv stəˈtɪstɪks/ סטטיסתיקה תיאורית
visualisation/ˌvɪʒuːəlaɪˈzeɪʃn/ ויזואליזציה
Correlation is not causation/ˌkɒrɪˈleɪʃn ɪz nɒt kɔːˈseɪʃn/ קורלציה אינה משמעות סיבתיות
3.6

Data science · ⁨מדעי נתונים⁩

Syllabus · ⁨סיילבוס⁩
English

Unit 6 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.5: Applying Data Science to other academic areas.

עברית

יחידה 6 מתוך 6 ב-GAC017 מחשבים III: מדע נתונים ואפליקציות אתר (רמה III). המודול מיועד ללמידה במשך כ-40 שעות לימוד פנים-ביתיות ועוד 20 שעות למידה עצמאית, והוא מוערך במרכז ההוראה ומטופל על ידי ACT — אין מבחן חיצוני.

תוצאות המודול שהיחידה הזו שואפת להשיג:

מטרות למידה GAC017.5: יישום מדע נתונים לתחומים אקדמיים נוספים.

Source: Cambridge International syllabus · ⁨מקור: הסיילבוס הבינלאומי של קמבריד'ג'⁩

English
  • Data science 数据科学 turns data into a decision, and most of the work is before the analysis: cleaning, joining, and checking what the data can support.
  • Descriptive statistics 描述性统计 summarise; a visualisation 可视化 shows shape; neither proves a cause.
  • Correlation is not causation 相关不等于因果 — the sentence every data project needs and most omit.
  • State the limitations of your dataset. A project that names what its data cannot show scores above one that quietly overclaims.
עברית
  • מדעי נתונים ממירים נתונים להחלטה, והרוב מן העבודה מתבצע לפני ה- ניתוח: ניקוי, חיבור ובדיקה מה הנתונים יכולים לתמוך בו.
  • סטטיסתיים תיאורים מסכמים; ויזואליזציה מראה צורה; אף אחד מהם אינו מגדיל סיבתיות.
  • קורלציה אינה סיבתיות — המשפט שכל פרויקט נתונים צריך ורבים מתעלמים ממנו.
  • ציינו את המגבלות של מאגר הנתונים שלכם. פרויקט שמציין מה הנתונים שלו לא יכול להראות זוכה נקודות מעל פני פרויקט המ claiming יתר על המידה בשקט.
Additional notes PDF

Follow one request from browser to database

A teacher asks which clubs have places left. A spreadsheet can answer once. A web app lets a reader ask again with a different filter.

Our example has four students, four classes and five enrolments. All records are invented. It is a learning project, not a school booking service.

The three parts have different jobs:

Part Job in the example Runs where?
Browser page Collect a minimum and show a table The reader's browser
JavaScript server Check the request and run the query The local server
SQLite database Store related records and calculate course totals Inside this server process

An HTTP request 请求信息 asks for a resource. An HTTP response 响应信息 contains a status and content. The browser sends GET /api/courses?min=2. The server checks the number, then asks SQLite for course totals. It returns a JSON object 数据对象. The browser reads that object and creates table cells. The database does not send HTML to the browser. The browser does not run our server's SQL.

Start the supplied three-file example with node server.mjs. Open the address it prints. Use Node.js 22.13 or newer with the built-in SQLite module available. Keep server.mjs, index.html and courses.sql together in your own working copy. No account or package download is needed. Stop your own server with Ctrl-C.

Get the complete example files from the site's static teaching folder:

  • /static/teaching/gac_computing/database-app/server.mjs
  • /static/teaching/gac_computing/database-app/courses.sql
  • /static/teaching/gac_computing/database-app/index.html.txt
  • /static/teaching/gac_computing/database-app/README.txt

Save the first two with their shown names. Save index.html.txt as index.html. The last file has the full run and adaptation instructions. Use these paths after the site's address. The page file is supplied as text for downloading. It must run through your local example server to reach the matching API.

This example uses an in-memory database 内存数据库. Restarting creates the original records again. A file database could keep changes after restart. That needs a different storage choice.

Design relationships before writing queries

Each student has one row in students. Each class has one row in courses. An enrolment links a student to a class. A student may join several classes. A class may contain several students. This is a many-to-many relationship 多对多关系. The third table stores one student–class pair per row.

Student 1 joins courses 10 and 20. Course 10 contains students 1, 2 and 3. The same student name need not be repeated in each enrolment row. To change Mei's name, change one student record. This avoids conflicting copies.

The following two blocks form one complete script. Run them in order in a new empty practice database. Do not run it against an existing project database.

PRAGMA foreign_keys = ON;
CREATE TABLE students (
  id INTEGER PRIMARY KEY,
  name TEXT NOT NULL
);
CREATE TABLE courses (
  id INTEGER PRIMARY KEY,
  title TEXT NOT NULL,
  capacity INTEGER NOT NULL CHECK (capacity >= 0)
);
CREATE TABLE enrolments (
  student_id INTEGER NOT NULL REFERENCES students(id),
  course_id INTEGER NOT NULL REFERENCES courses(id),
  PRIMARY KEY (student_id, course_id)
);

The tables now exist. Add the fictional records, then query totals for each class.

INSERT INTO students VALUES
  (1, 'Mei'), (2, 'Kai'), (3, 'Lin'), (4, 'Jia');
INSERT INTO courses VALUES
  (10, 'Coding', 3), (20, 'Coding', 2),
  (30, 'Art', 2), (40, 'Music', 3);
INSERT INTO enrolments VALUES
  (1, 10), (2, 10), (3, 10), (1, 20), (4, 30);
SELECT c.id, c.title, c.capacity,
       COUNT(e.student_id) AS enrolled
FROM courses c
LEFT JOIN enrolments e ON c.id = e.course_id
GROUP BY c.id, c.title, c.capacity
ORDER BY enrolled DESC, c.id;

A constraint 约束 rejects data that breaks a rule. NOT NULL requires a value. CHECK (capacity >= 0) rejects negative capacity. The paired primary key rejects a repeated enrolment, such as (1,10) twice. Either ID may appear in many pairs. The pair itself must be unique.

Foreign keys reject missing students or classes when foreign-key checking is enabled. The script enables that checking explicitly. A foreign key does not create the missing row. These rules do not prevent every error. For example, capacity 3 does not itself limit enrolments to 3. A real booking operation would need a capacity check and safe handling of simultaneous bookings.

Count classes without losing empty ones

Courses 10 and 20 both have the title Coding. They are different classes. Group by the course ID as well as its title and capacity. Grouping only by title would merge their enrolments and answer the wrong question.

LEFT JOIN keeps every course, including Music with no enrolments. The unmatched course has an empty enrolment side. COUNT(e.student_id) counts matched student IDs and gives zero for Music. COUNT(*) counts the joined row, including that unmatched row, and would give Music one.

ID Course Capacity Enrolled Places left
10 Coding 3 3 0
20 Coding 2 1 1
30 Art 2 1 1
40 Music 3 0 3

The browser calculates places left as capacity minus enrolled. There are five enrolments but only four students. Mei appears in two enrolment rows. Do not label five as the number of unique students.

To keep classes with at least two enrolments, add this line after GROUP BY:

HAVING COUNT(e.student_id) >= 2

This is a query fragment, added to the complete query. It returns course 10 only. HAVING checks each group total. WHERE checks individual rows before totals are calculated. For example, WHERE c.id = 20 selects one class before grouping; it does not test its total.

Validate and bind the backend input

The route /api/courses accepts a minimum from 0 to 99. The browser number control helps users enter it. Direct requests can skip that control. The server therefore checks the input again.

It rejects negative numbers, decimals, 100, repeated minimum parameters and text. Missing min means zero. A successful query with no courses is still a valid request.

Request Status Meaning
GET /api/courses?min=2 200 One course found
GET /api/courses?min=4 200 Valid query; empty list
GET /api/courses?min=-1 400 Invalid input
GET /missing 404 Route does not exist
POST /api/courses 405 This read-only route accepts GET

A prepared statement 预编译语句 keeps the SQL structure separate from a value. The server prepares its total-by-course query with >= ?, then calls courses.all(minimum). The bound number fills the value position. It is not joined into the SQL text.

Binding values protects this query from injection through that value. It does not prove that every route or operation is secure. SQL keywords and column names cannot be supplied as ordinary bound values. Keep the query structure fixed or choose it from permitted server-owned choices.

The server sends public course totals only. Student names stay out of this response. Real records would also need access rules and permission to use them. An invented example needs no real student information.

Handle loading, empty results and failures

The browser uses fetch to request the data. It must check the response status. A completed network request may still return 400 or 500. The browser's response.ok distinguishes successful HTTP responses from those errors.

The page clears old rows before loading. Otherwise a failed request could leave old results looking current. It displays a loading message and disables the load button during the request. It then shows the result, an empty message, or a failure message. The button becomes available again so the reader can retry.

Each displayed value goes into textContent, not into HTML built from a data string. A course title becomes text inside a cell. It is not treated as page markup.

The sample uses a request number to ignore an older response after a newer request starts. This protects the page from a late response replacing the newest result. It does not change database records or make bookings safe.

Try minimum 0, 2 and 4 in that order. Expect four courses, one course and no courses. Then stop the server and try loading again. The page should explain the failure and allow a retry. Restart the server and load again. The original fictional dataset should return.

Turn results into a supported academic decision

Begin with a question: which classes currently have spare places? State your unit of analysis 分析单位: one class, identified by course ID. Check missing values, repeated enrolment pairs, valid IDs and non-negative capacities before analysis. Name the data date in a real report, because enrolments can change.

The current answer is Coding 20, Art 30 and Music 40. Music has three spare places; the other two have one each. A teacher could first check whether those places are still available before announcing them.

A bar chart could compare enrolled and capacity for each course ID. Keep the two Coding classes separate and label them with their IDs. Show zero enrolments for Music. Do not hide it because its bar is short.

Explain the limitation 局限 of this decision. These records describe four invented classes at one time. They do not measure teaching quality, future demand or why students chose a class. More enrolments do not prove that a class caused better learning. Avoid using a descriptive count as evidence for a causal claim.

A short report can use five parts: question, data and checks, method, result, limits and next action. Include the query or name the calculation so another reader can reproduce the result. Keep student and enrolment counts separate.

Practise with changes and explain your answers

  1. Sketch the three tables. Which keys link them, and why is the third table needed?
  2. Predict minimum 1 and minimum 3 before running either request.
  3. Replace COUNT(e.student_id) with COUNT(*). Which original result becomes wrong, and why?
  4. Group only by title. What happens to the two Coding classes?
  5. Add course 50, Drama, with capacity 2 and no enrolments. Predict its total and free places.
  6. Add enrolment (2,20). What should minimum 2 now return?
  7. Try duplicate pair (1,10) and missing student pair (99,10). Explain each rejection.
  8. Why must the server check a minimum that the browser already checks?
  9. Explain why an empty array gets 200, while a negative minimum gets 400.
  10. Write a two-sentence recommendation and one limitation using the original data.

Explained answers

  1. Student ID and course ID link the paired enrolment table to their parent tables. The third table represents many students in many classes without repeating names or course facts.
  2. Minimum 1 returns 10, 20 and 30. Minimum 3 returns 10 only. Both filters include equality.
  3. Music becomes one instead of zero. COUNT(*) counts the preserved unmatched course row.
  4. Coding totals combine to four. This describes a title group, not either individual class.
  5. Drama has zero enrolments and two places left. A left join keeps it at minimum 0.
  6. Coding 20 now has two enrolments. Minimum 2 returns IDs 10 and 20, with totals three and two.
  7. The paired primary key rejects the duplicate. The enabled foreign key rejects student 99, who does not exist.
  8. A caller can send a request without using the page. Browser checks cannot protect the server by themselves.
  9. No matching rows is a successful query. A negative minimum breaks the API's input rule.
  10. Check remaining places in Coding 20, Art 30 and Music 40 before offering them. Music has most spare places in this example. Invented totals cannot predict actual student demand.

Interactive lessons on this topic · ⁨שיעורים אינטראקטיביים בנושא זה⁩

Work through it step by step, with instant-check exercises. · ⁨לעבור על הדברים צעד אחר צעד, עם תרגילים לבדיקה מיידית.⁩

More topics in GAC Computing · ⁨גאק מחשבים⁩ · ⁨נושאים נוספים בGAC Computing · ⁨גאק מחשבים⁩⁩

Log in or create account · ⁨היכנס או צור חשבון⁩

IGCSE, A-Level & AP