Skip to content · ⁨コンテンツへスキップ⁩

GAC017 Computing III: Data Science and Web Apps · ⁨GAC017 コンピューティングIII:データサイエンスとWebアプリ⁩

GAC Computing · ⁨GAC コンピューティング⁩ · Topic 3 · ⁨トピック 3⁩

View Slides · ⁨查看幻灯片⁩ Train · ⁨練習する⁩
3.1

What this module is, and how it is marked · ⁨このモジュールとは何か、および採点基準⁩

English

GAC017 is the Level III computing module: what sits behind a website. Six units cover back-end JavaScript, databases, SQL, connecting the two, and a first look at data science.

Assessment is entirely practical — a database 数据库 you design and build, a web app 网络应用 that talks to it, a data analysis project 数据分析项目, and coursework — usually spread across most of the semester rather than concentrated at the end.

  • The work is judged on whether it runs and answers a question, not on how much code there is.
  • ⚠ Design the database before you write a query. Almost every problem later is a table problem wearing a query's clothes.

Every SQL example here runs in the site's own code playground, and the SQL reference there is the fuller version of these notes.

日本語

GAC017はLevel IIIコンピューティングモジュールです:サイトの裏側にあるもの。6つのユニットで、バックエンドJavaScript、データベース、SQL、それらをつなぐこと、そしてデータサイエンスへの最初の探求を扱います。 JavaScript、データベース、SQL、両者の接続、そしてデータサイエンスへの第一歩。

評価は完全に実務的 — データベースの設計と構築、それに接続するウェブアプリ、データ分析プロジェクト、および coursework(課題)— 通常 これと対話するデータ分析プロジェクト、および課題 — 通常は 学期の終わりではなく、学期全体にわたって分散して行われる。

  • 作品はコードの量ではなく、動作するかそして質問に答えるかで評価される。
  • ⚠ クエリを書く前にデータベースを設計せよ。後続のほぼすべての問題はテーブルの問題である。 クエリの形式に騙されているだけだ。

ここにあるすべてのSQL例は、サイトの独自のコードプレイグラウンドで動作し、那里的SQLリファレンスは これらのメモのより完全なバージョンである。

Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
English 日本語
SQL/ˌes kjuː ˈel/ SQL
3.1

JavaScript for a web app's back end · ⁨ウェブアプリのバックエンド用JavaScript⁩

Syllabus · ⁨シラバス⁩

Unit 1 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

Module purpose: On completion of this module, students should be able to create a web app. Students will learn about back- end programming and how to create a dynamic website. They will be able to use SQL to analyze data from multiple tables in order to make informed decisions.

The module outcomes this unit works towards:

Learning Objective GAC017.1: Understand the basic components of a Web Application.

Source: Cambridge International syllabus · ⁨出典: Cambridge International シラバス⁩

English
  • The front end 前端 runs in the browser; the back end 后端 runs on a server and holds what the browser must not.
  • A server 服务器 receives a request 请求 and returns a response 响应. That loop is the whole architecture.
  • An API 应用程序接口 is the agreed shape of those requests and responses.
  • ⚠ Anything secret — a password, a key — belongs on the back end only. Code in a browser is readable by everyone who visits.
日本語
  • フロントエンドはブラウザ上で動作し、バックエンドはサーバー上で動作し、ブラウザが持つべきではない情報を保持する。 ブラウザに渡すべきではないデータ。
  • サーバーはリクエストを受け取り、レスポンスを返す。そのループこそが、 全体のアーキテクチャである。
  • APIとは、それらのリクエストとレスポンスの合意された形状のことである。
  • ⚠ 秘密となるもの(パスワードやキーなど)はすべてバックエンドにのみ格納されなければならない。ブラウザ内のコードは、 訪問者全員によって読み取られる可能性がある。
Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
English 日本語
database/ˈdeɪtəbeɪs/ データベース
web app/web æp/ Webアプリ
data analysis project/ˈdeɪtə əˈnæləsɪs ˈprɒdʒekt/ データ分析プロジェクト
front end/frʌnt end/ フロントエンド
back end/bæk end/ バックエンド
server/ˈsɜːvə/ サーバー
request/rɪˈkwest/ 依頼
response/rɪˈspɒns/ 応答
API/ˌeɪ piː ˈaɪ/ API
route/ruːt/ 経路
Validate input/ˈvælɪdeɪt ˈɪnpʊt/ 入力値の検証
SQL injection/ˌes kjuː ˈel ɪnˈdʒekʃn/ SQLインジェクション
relational database/rɪˈleɪʃənl ˈdeɪtəbeɪs/ リレーショナルデータベース
tables/ˈteɪblz/ テーブル
primary key/ˈpraɪməri kiː/ 主キー
foreign key/ˈfɒrən kiː/ 外部キー
Normalisation/ˌnɔːməlaɪˈzeɪʃn/ 正規化
entities/ˈentɪtiz/ エンティティ
3.2

Back-end programming · ⁨バックエンドプログラミング⁩

Syllabus · ⁨シラバス⁩

Unit 2 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.2: Adapt a back-end application using scripting languages to interact with databases.

Source: Cambridge International syllabus · ⁨出典: Cambridge International シラバス⁩

English
  • A route 路由 maps a URL to code that runs when that URL is requested.
  • Validate input 校验输入 on the server. Checking in the browser is a convenience for honest users, not a defence.
  • Never build a query by joining strings with user input. That is how SQL injection SQL 注入 happens, and it is the security failure this unit exists to prevent.
  • Return an honest status: 200 for success, 400 for a bad request, 404 for something that is not there.
日本語
  • ルートとは、URLをコードにマッピングし、そのURLがリクエストされたときに実行されるものを指す。
  • サーバー側で入力値を検証せよ。ブラウザでのチェックは誠実なユーザーのための利便性であり、防御手段ではない。 ユーザーのため、防衛のためではない。
  • ユーザー入力を文字列として結合してクエリを絶対に作成しない。それがSQLインジェクションという SQL攻撃の発生方法であり、この単元が存在する目的であるセキュリティ欠陥を防ぐためである。
  • 誠実なステータスコードを返せ。成功なら200、悪いリクエストなら400、存在しないものなら404。 存在しない場合。
3.3

Introduction to databases · ⁨データベース入門⁩

Syllabus · ⁨シラバス⁩

Unit 3 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.3: Create a database with multiple tables.

Source: Cambridge International syllabus · ⁨出典: Cambridge International シラバス⁩

English
  • A relational database 关系数据库 stores data in tables 表 of rows and columns.
  • A primary key 主键 identifies a row uniquely. A foreign key 外键 points at another table's primary key, and that pointer is the relationship.
  • Normalisation 规范化 removes duplicated data so one fact lives in one place.
  • Design by asking what the entities 实体 are, then what connects them.

Worked example. A school wants to store students, courses and who takes what.

Two tables cannot do it: a student takes many courses and a course has many students. The many-to-many needs a third table — enrolments — whose rows are (student, course) pairs.

Recognising that this third table is required is the single most useful database idea in the module, and it is where most first designs go wrong.

日本語
  • リレーショナルデータベースは、行と列からなるテーブルでデータを格納する。
  • プライマリキーはレコードを一意に識別する。フォリンキーは別の テーブルのプライマリキーを指し、その参照が関係性を表す。
  • 正規化により重複データを除去し、一つの事実を一处に留める。
  • エンティティが何かを考え、次にそれらがどう結びついているかを考えることで設計を行う。

** worked example.** 学校は生徒、コース、および誰がどのコースを受講しているかを記録したいと考えている。

二つのテーブルではこれを実現できない:一人の生徒は多くのコースを受講し、一つのコースには多くの生徒がいるからだ。 多数対多数の関係には第三のテーブル——登録——が必要であり、そのレコードは(生徒, コース)のペアとなる。

この第三のテーブルが必要であることを認識することが、このモジュールにおける最も有用なデータベースのアイデアの一つであり、 ほとんどの初級設計が失敗する場所でもある。

3.4

SQL for back-end programming · ⁨バックエンドプログラミング用のSQL⁩

Syllabus · ⁨シラバス⁩

Unit 4 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.4: Analyze data using SQL in order to make decisions.

Source: Cambridge International syllabus · ⁨出典: Cambridge International シラバス⁩

English
  • SQL 结构化查询语言 asks a database questions. SELECT … FROM … WHERE … is the core.
  • JOIN 连接 combines rows from two tables on a matching key.
  • GROUP BY 分组 with COUNT, SUM or AVG answers "how many per…" questions.
  • ⚠ WHERE filters rows before grouping; HAVING filters groups after. Using the wrong one is the classic SQL error, and it usually returns a plausible wrong answer.

Worked example. Which courses have more than 20 students?

The count is a property of the group, so the filter is HAVING. Written with WHERE it does not run — and when a similar mistake does run, it silently answers a different question.

日本語
  • SQL はデータベースに質問を行う。SELECT … FROM … WHERE … が核心である。
  • JOINは一致するキーに基づいて二つのテーブルからのレコードを結合する。
  • GROUP BY と COUNT、SUM または AVG を使用することで、「…あたり何件か」のような質問に回答できる。
  • ⚠ WHERE はグループ化の前にレコードをフィルタリングします;HAVING はグループ化後にフィルタリングします。間違えると 典型的なSQLエラーとなり、一見妥当だが誤った結果を返すことが多いです。

** worked example.** 受講生が20人を超えるコースはどれか?

SELECT c.title, COUNT(*) AS students
FROM enrolments e
JOIN courses c ON c.id = e.course_id
GROUP BY c.title
HAVING COUNT(*) > 20;

カウントはグループのプロパティなので、フィルタは HAVING である。WHERE で記述すると動作せず、 similarな間違いでも動作した場合は、別の質問に対して無言で回答してしまう。

Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
English 日本語
JOIN/dʒɔɪn/ JOIN
GROUP BY/ɡruːp baɪ/ GROUP BY
parameterised query/ˌpærəˈmetəraɪzd ˈkwɪərɪ/ パラメータ化クエリ
3.5

Connecting JavaScript with SQL · ⁨JavaScriptとSQLの接続⁩

Syllabus · ⁨シラバス⁩

Unit 5 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.2: Adapt a back-end application using scripting languages to interact with databases.

Learning Objective GAC017.4: Analyze data using SQL in order to make decisions.

Source: Cambridge International syllabus · ⁨出典: Cambridge International シラバス⁩

English
  • The back end takes a request, runs a parameterised query 参数化查询, and returns the rows as data, usually JSON 数据交换格式.
  • Parameterised means the values travel separately from the query text. That is what makes injection impossible rather than unlikely.
  • Handle the empty case. A query that returns no rows is normal, and a page that breaks on it is not finished.
日本語
  • バックエンドはリクエストを受け取り、パラメータ付きクエリを実行し、結果のレコードを データとして返す。通常は JSON 形式である。
  • パラメータ付きとは、値がクエリテキストとは別個に送られることを意味する。これが インジェクションを不可能にするのではなく、 unlikely にするものではない。
  • 空の結果ケースを処理せよ。レコードを返さないクエリは正常であり、それによって破損するページは 未完成である。
Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
English 日本語
JSON/ˈdʒeɪsn/ JSON
Data science/ˈdeɪtə ˈsaɪəns/ データサイエンス
Descriptive statistics/dɪˈskrɪptɪv stəˈtɪstɪks/ 記述統計
visualisation/ˌvɪʒuːəlaɪˈzeɪʃn/ 可視化
Correlation is not causation/ˌkɒrɪˈleɪʃn ɪz nɒt kɔːˈseɪʃn/ 相関は因果関係を意味しない
3.6

Data science · ⁨データサイエンス⁩

Syllabus · ⁨シラバス⁩

Unit 6 of 6 in GAC017 Computing III: Data Science and Web Apps (Level III). The module is taught over about 40 class hours plus 20 hours of independent study, and is assessed at the teaching centre and moderated by ACT — there is no external exam.

The module outcomes this unit works towards:

Learning Objective GAC017.5: Applying Data Science to other academic areas.

Source: Cambridge International syllabus · ⁨出典: Cambridge International シラバス⁩

English
  • Data science 数据科学 turns data into a decision, and most of the work is before the analysis: cleaning, joining, and checking what the data can support.
  • Descriptive statistics 描述性统计 summarise; a visualisation 可视化 shows shape; neither proves a cause.
  • Correlation is not causation 相关不等于因果 — the sentence every data project needs and most omit.
  • State the limitations of your dataset. A project that names what its data cannot show scores above one that quietly overclaims.
日本語
  • データサイエンスはデータを意思決定に変換するものであり、分析の前に行う作業の大部分は、 データのクリーニング、結合、およびデータが支持できる内容の確認である。
  • 記述統計は要約し、可視化は形状を示すが、 neither 因果関係を証明するものではない。 因果関係を証明するものではない。
  • 相関は因果ではない——これはすべてのデータプロジェクトに必要な文脈であり、 多くのプロジェクトが省略してしまう。
  • データセットの限界を明記せよ。データが示せないことを名乗るプロジェクトの方が、 静かに過大評価するプロジェクトより高い評価を得る。
Additional notes PDF
English

Follow one request from browser to database

A teacher asks which clubs have places left. A spreadsheet can answer once. A web app lets a reader ask again with a different filter.

Our example has four students, four classes and five enrolments. All records are invented. It is a learning project, not a school booking service.

The three parts have different jobs:

Part Job in the example Runs where?
Browser page Collect a minimum and show a table The reader's browser
JavaScript server Check the request and run the query The local server
SQLite database Store related records and calculate course totals Inside this server process

An HTTP request 请求信息 asks for a resource. An HTTP response 响应信息 contains a status and content. The browser sends GET /api/courses?min=2. The server checks the number, then asks SQLite for course totals. It returns a JSON object 数据对象. The browser reads that object and creates table cells. The database does not send HTML to the browser. The browser does not run our server's SQL.

Start the supplied three-file example with node server.mjs. Open the address it prints. Use Node.js 22.13 or newer with the built-in SQLite module available. Keep server.mjs, index.html and courses.sql together in your own working copy. No account or package download is needed. Stop your own server with Ctrl-C.

Get the complete example files from the site's static teaching folder:

  • /static/teaching/gac_computing/database-app/server.mjs
  • /static/teaching/gac_computing/database-app/courses.sql
  • /static/teaching/gac_computing/database-app/index.html.txt
  • /static/teaching/gac_computing/database-app/README.txt

Save the first two with their shown names. Save index.html.txt as index.html. The last file has the full run and adaptation instructions. Use these paths after the site's address. The page file is supplied as text for downloading. It must run through your local example server to reach the matching API.

This example uses an in-memory database 内存数据库. Restarting creates the original records again. A file database could keep changes after restart. That needs a different storage choice.

Design relationships before writing queries

Each student has one row in students. Each class has one row in courses. An enrolment links a student to a class. A student may join several classes. A class may contain several students. This is a many-to-many relationship 多对多关系. The third table stores one student–class pair per row.

Student 1 joins courses 10 and 20. Course 10 contains students 1, 2 and 3. The same student name need not be repeated in each enrolment row. To change Mei's name, change one student record. This avoids conflicting copies.

The following two blocks form one complete script. Run them in order in a new empty practice database. Do not run it against an existing project database.

The tables now exist. Add the fictional records, then query totals for each class.

A constraint 约束 rejects data that breaks a rule. NOT NULL requires a value. CHECK (capacity >= 0) rejects negative capacity. The paired primary key rejects a repeated enrolment, such as (1,10) twice. Either ID may appear in many pairs. The pair itself must be unique.

Foreign keys reject missing students or classes when foreign-key checking is enabled. The script enables that checking explicitly. A foreign key does not create the missing row. These rules do not prevent every error. For example, capacity 3 does not itself limit enrolments to 3. A real booking operation would need a capacity check and safe handling of simultaneous bookings.

Count classes without losing empty ones

Courses 10 and 20 both have the title Coding. They are different classes. Group by the course ID as well as its title and capacity. Grouping only by title would merge their enrolments and answer the wrong question.

LEFT JOIN keeps every course, including Music with no enrolments. The unmatched course has an empty enrolment side. COUNT(e.student_id) counts matched student IDs and gives zero for Music. COUNT(*) counts the joined row, including that unmatched row, and would give Music one.

ID Course Capacity Enrolled Places left
10 Coding 3 3 0
20 Coding 2 1 1
30 Art 2 1 1
40 Music 3 0 3

The browser calculates places left as capacity minus enrolled. There are five enrolments but only four students. Mei appears in two enrolment rows. Do not label five as the number of unique students.

To keep classes with at least two enrolments, add this line after GROUP BY:

This is a query fragment, added to the complete query. It returns course 10 only. HAVING checks each group total. WHERE checks individual rows before totals are calculated. For example, WHERE c.id = 20 selects one class before grouping; it does not test its total.

Validate and bind the backend input

The route /api/courses accepts a minimum from 0 to 99. The browser number control helps users enter it. Direct requests can skip that control. The server therefore checks the input again.

It rejects negative numbers, decimals, 100, repeated minimum parameters and text. Missing min means zero. A successful query with no courses is still a valid request.

Request Status Meaning
GET /api/courses?min=2 200 One course found
GET /api/courses?min=4 200 Valid query; empty list
GET /api/courses?min=-1 400 Invalid input
GET /missing 404 Route does not exist
POST /api/courses 405 This read-only route accepts GET

A prepared statement 预编译语句 keeps the SQL structure separate from a value. The server prepares its total-by-course query with >= ?, then calls courses.all(minimum). The bound number fills the value position. It is not joined into the SQL text.

Binding values protects this query from injection through that value. It does not prove that every route or operation is secure. SQL keywords and column names cannot be supplied as ordinary bound values. Keep the query structure fixed or choose it from permitted server-owned choices.

The server sends public course totals only. Student names stay out of this response. Real records would also need access rules and permission to use them. An invented example needs no real student information.

Handle loading, empty results and failures

The browser uses fetch to request the data. It must check the response status. A completed network request may still return 400 or 500. The browser's response.ok distinguishes successful HTTP responses from those errors.

The page clears old rows before loading. Otherwise a failed request could leave old results looking current. It displays a loading message and disables the load button during the request. It then shows the result, an empty message, or a failure message. The button becomes available again so the reader can retry.

Each displayed value goes into textContent, not into HTML built from a data string. A course title becomes text inside a cell. It is not treated as page markup.

The sample uses a request number to ignore an older response after a newer request starts. This protects the page from a late response replacing the newest result. It does not change database records or make bookings safe.

Try minimum 0, 2 and 4 in that order. Expect four courses, one course and no courses. Then stop the server and try loading again. The page should explain the failure and allow a retry. Restart the server and load again. The original fictional dataset should return.

Turn results into a supported academic decision

Begin with a question: which classes currently have spare places? State your unit of analysis 分析单位: one class, identified by course ID. Check missing values, repeated enrolment pairs, valid IDs and non-negative capacities before analysis. Name the data date in a real report, because enrolments can change.

The current answer is Coding 20, Art 30 and Music 40. Music has three spare places; the other two have one each. A teacher could first check whether those places are still available before announcing them.

A bar chart could compare enrolled and capacity for each course ID. Keep the two Coding classes separate and label them with their IDs. Show zero enrolments for Music. Do not hide it because its bar is short.

Explain the limitation 局限 of this decision. These records describe four invented classes at one time. They do not measure teaching quality, future demand or why students chose a class. More enrolments do not prove that a class caused better learning. Avoid using a descriptive count as evidence for a causal claim.

A short report can use five parts: question, data and checks, method, result, limits and next action. Include the query or name the calculation so another reader can reproduce the result. Keep student and enrolment counts separate.

Practise with changes and explain your answers

  1. Sketch the three tables. Which keys link them, and why is the third table needed?
  2. Predict minimum 1 and minimum 3 before running either request.
  3. Replace COUNT(e.student_id) with COUNT(*). Which original result becomes wrong, and why?
  4. Group only by title. What happens to the two Coding classes?
  5. Add course 50, Drama, with capacity 2 and no enrolments. Predict its total and free places.
  6. Add enrolment (2,20). What should minimum 2 now return?
  7. Try duplicate pair (1,10) and missing student pair (99,10). Explain each rejection.
  8. Why must the server check a minimum that the browser already checks?
  9. Explain why an empty array gets 200, while a negative minimum gets 400.
  10. Write a two-sentence recommendation and one limitation using the original data.

Explained answers

  1. Student ID and course ID link the paired enrolment table to their parent tables. The third table represents many students in many classes without repeating names or course facts.
  2. Minimum 1 returns 10, 20 and 30. Minimum 3 returns 10 only. Both filters include equality.
  3. Music becomes one instead of zero. COUNT(*) counts the preserved unmatched course row.
  4. Coding totals combine to four. This describes a title group, not either individual class.
  5. Drama has zero enrolments and two places left. A left join keeps it at minimum 0.
  6. Coding 20 now has two enrolments. Minimum 2 returns IDs 10 and 20, with totals three and two.
  7. The paired primary key rejects the duplicate. The enabled foreign key rejects student 99, who does not exist.
  8. A caller can send a request without using the page. Browser checks cannot protect the server by themselves.
  9. No matching rows is a successful query. A negative minimum breaks the API's input rule.
  10. Check remaining places in Coding 20, Art 30 and Music 40 before offering them. Music has most spare places in this example. Invented totals cannot predict actual student demand.
日本語

Follow one request from browser to database

A teacher asks which clubs have places left. A spreadsheet can answer once. A web app lets a reader ask again with a different filter.

Our example has four students, four classes and five enrolments. All records are invented. It is a learning project, not a school booking service.

The three parts have different jobs:

Part Job in the example Runs where?
Browser page Collect a minimum and show a table The reader's browser
JavaScript server Check the request and run the query The local server
SQLite database Store related records and calculate course totals Inside this server process

An HTTP request 请求信息 asks for a resource. An HTTP response 响应信息 contains a status and content. The browser sends GET /api/courses?min=2. The server checks the number, then asks SQLite for course totals. It returns a JSON object 数据对象. The browser reads that object and creates table cells. The database does not send HTML to the browser. The browser does not run our server's SQL.

Start the supplied three-file example with node server.mjs. Open the address it prints. Use Node.js 22.13 or newer with the built-in SQLite module available. Keep server.mjs, index.html and courses.sql together in your own working copy. No account or package download is needed. Stop your own server with Ctrl-C.

Get the complete example files from the site's static teaching folder:

  • /static/teaching/gac_computing/database-app/server.mjs
  • /static/teaching/gac_computing/database-app/courses.sql
  • /static/teaching/gac_computing/database-app/index.html.txt
  • /static/teaching/gac_computing/database-app/README.txt

Save the first two with their shown names. Save index.html.txt as index.html. The last file has the full run and adaptation instructions. Use these paths after the site's address. The page file is supplied as text for downloading. It must run through your local example server to reach the matching API.

This example uses an in-memory database 内存数据库. Restarting creates the original records again. A file database could keep changes after restart. That needs a different storage choice.

Design relationships before writing queries

Each student has one row in students. Each class has one row in courses. An enrolment links a student to a class. A student may join several classes. A class may contain several students. This is a many-to-many relationship 多对多关系. The third table stores one student–class pair per row.

Student 1 joins courses 10 and 20. Course 10 contains students 1, 2 and 3. The same student name need not be repeated in each enrolment row. To change Mei's name, change one student record. This avoids conflicting copies.

The following two blocks form one complete script. Run them in order in a new empty practice database. Do not run it against an existing project database.

PRAGMA foreign_keys = ON;
CREATE TABLE students (
  id INTEGER PRIMARY KEY,
  name TEXT NOT NULL
);
CREATE TABLE courses (
  id INTEGER PRIMARY KEY,
  title TEXT NOT NULL,
  capacity INTEGER NOT NULL CHECK (capacity >= 0)
);
CREATE TABLE enrolments (
  student_id INTEGER NOT NULL REFERENCES students(id),
  course_id INTEGER NOT NULL REFERENCES courses(id),
  PRIMARY KEY (student_id, course_id)
);

The tables now exist. Add the fictional records, then query totals for each class.

INSERT INTO students VALUES
  (1, 'Mei'), (2, 'Kai'), (3, 'Lin'), (4, 'Jia');
INSERT INTO courses VALUES
  (10, 'Coding', 3), (20, 'Coding', 2),
  (30, 'Art', 2), (40, 'Music', 3);
INSERT INTO enrolments VALUES
  (1, 10), (2, 10), (3, 10), (1, 20), (4, 30);
SELECT c.id, c.title, c.capacity,
       COUNT(e.student_id) AS enrolled
FROM courses c
LEFT JOIN enrolments e ON c.id = e.course_id
GROUP BY c.id, c.title, c.capacity
ORDER BY enrolled DESC, c.id;

A constraint 约束 rejects data that breaks a rule. NOT NULL requires a value. CHECK (capacity >= 0) rejects negative capacity. The paired primary key rejects a repeated enrolment, such as (1,10) twice. Either ID may appear in many pairs. The pair itself must be unique.

Foreign keys reject missing students or classes when foreign-key checking is enabled. The script enables that checking explicitly. A foreign key does not create the missing row. These rules do not prevent every error. For example, capacity 3 does not itself limit enrolments to 3. A real booking operation would need a capacity check and safe handling of simultaneous bookings.

Count classes without losing empty ones

Courses 10 and 20 both have the title Coding. They are different classes. Group by the course ID as well as its title and capacity. Grouping only by title would merge their enrolments and answer the wrong question.

LEFT JOIN keeps every course, including Music with no enrolments. The unmatched course has an empty enrolment side. COUNT(e.student_id) counts matched student IDs and gives zero for Music. COUNT(*) counts the joined row, including that unmatched row, and would give Music one.

ID Course Capacity Enrolled Places left
10 Coding 3 3 0
20 Coding 2 1 1
30 Art 2 1 1
40 Music 3 0 3

The browser calculates places left as capacity minus enrolled. There are five enrolments but only four students. Mei appears in two enrolment rows. Do not label five as the number of unique students.

To keep classes with at least two enrolments, add this line after GROUP BY:

HAVING COUNT(e.student_id) >= 2

This is a query fragment, added to the complete query. It returns course 10 only. HAVING checks each group total. WHERE checks individual rows before totals are calculated. For example, WHERE c.id = 20 selects one class before grouping; it does not test its total.

Validate and bind the backend input

The route /api/courses accepts a minimum from 0 to 99. The browser number control helps users enter it. Direct requests can skip that control. The server therefore checks the input again.

It rejects negative numbers, decimals, 100, repeated minimum parameters and text. Missing min means zero. A successful query with no courses is still a valid request.

Request Status Meaning
GET /api/courses?min=2 200 One course found
GET /api/courses?min=4 200 Valid query; empty list
GET /api/courses?min=-1 400 Invalid input
GET /missing 404 Route does not exist
POST /api/courses 405 This read-only route accepts GET

A prepared statement 预编译语句 keeps the SQL structure separate from a value. The server prepares its total-by-course query with >= ?, then calls courses.all(minimum). The bound number fills the value position. It is not joined into the SQL text.

Binding values protects this query from injection through that value. It does not prove that every route or operation is secure. SQL keywords and column names cannot be supplied as ordinary bound values. Keep the query structure fixed or choose it from permitted server-owned choices.

The server sends public course totals only. Student names stay out of this response. Real records would also need access rules and permission to use them. An invented example needs no real student information.

Handle loading, empty results and failures

The browser uses fetch to request the data. It must check the response status. A completed network request may still return 400 or 500. The browser's response.ok distinguishes successful HTTP responses from those errors.

The page clears old rows before loading. Otherwise a failed request could leave old results looking current. It displays a loading message and disables the load button during the request. It then shows the result, an empty message, or a failure message. The button becomes available again so the reader can retry.

Each displayed value goes into textContent, not into HTML built from a data string. A course title becomes text inside a cell. It is not treated as page markup.

The sample uses a request number to ignore an older response after a newer request starts. This protects the page from a late response replacing the newest result. It does not change database records or make bookings safe.

Try minimum 0, 2 and 4 in that order. Expect four courses, one course and no courses. Then stop the server and try loading again. The page should explain the failure and allow a retry. Restart the server and load again. The original fictional dataset should return.

Turn results into a supported academic decision

Begin with a question: which classes currently have spare places? State your unit of analysis 分析单位: one class, identified by course ID. Check missing values, repeated enrolment pairs, valid IDs and non-negative capacities before analysis. Name the data date in a real report, because enrolments can change.

The current answer is Coding 20, Art 30 and Music 40. Music has three spare places; the other two have one each. A teacher could first check whether those places are still available before announcing them.

A bar chart could compare enrolled and capacity for each course ID. Keep the two Coding classes separate and label them with their IDs. Show zero enrolments for Music. Do not hide it because its bar is short.

Explain the limitation 局限 of this decision. These records describe four invented classes at one time. They do not measure teaching quality, future demand or why students chose a class. More enrolments do not prove that a class caused better learning. Avoid using a descriptive count as evidence for a causal claim.

A short report can use five parts: question, data and checks, method, result, limits and next action. Include the query or name the calculation so another reader can reproduce the result. Keep student and enrolment counts separate.

Practise with changes and explain your answers

  1. Sketch the three tables. Which keys link them, and why is the third table needed?
  2. Predict minimum 1 and minimum 3 before running either request.
  3. Replace COUNT(e.student_id) with COUNT(*). Which original result becomes wrong, and why?
  4. Group only by title. What happens to the two Coding classes?
  5. Add course 50, Drama, with capacity 2 and no enrolments. Predict its total and free places.
  6. Add enrolment (2,20). What should minimum 2 now return?
  7. Try duplicate pair (1,10) and missing student pair (99,10). Explain each rejection.
  8. Why must the server check a minimum that the browser already checks?
  9. Explain why an empty array gets 200, while a negative minimum gets 400.
  10. Write a two-sentence recommendation and one limitation using the original data.

Explained answers

  1. Student ID and course ID link the paired enrolment table to their parent tables. The third table represents many students in many classes without repeating names or course facts.
  2. Minimum 1 returns 10, 20 and 30. Minimum 3 returns 10 only. Both filters include equality.
  3. Music becomes one instead of zero. COUNT(*) counts the preserved unmatched course row.
  4. Coding totals combine to four. This describes a title group, not either individual class.
  5. Drama has zero enrolments and two places left. A left join keeps it at minimum 0.
  6. Coding 20 now has two enrolments. Minimum 2 returns IDs 10 and 20, with totals three and two.
  7. The paired primary key rejects the duplicate. The enabled foreign key rejects student 99, who does not exist.
  8. A caller can send a request without using the page. Browser checks cannot protect the server by themselves.
  9. No matching rows is a successful query. A negative minimum breaks the API's input rule.
  10. Check remaining places in Coding 20, Art 30 and Music 40 before offering them. Music has most spare places in this example. Invented totals cannot predict actual student demand.

Interactive lessons on this topic · ⁨このトピックのインタラクティブ授業⁩

Work through it step by step, with instant-check exercises. · ⁨一歩ずつ進め、即時チェック付きの問題で学習します。⁩

More topics in GAC Computing · ⁨GAC コンピューティング⁩ · ⁨GAC Computing · ⁨GAC コンピューティング⁩ の他のトピック⁩

Log in or create account · ⁨ログインまたはアカウント作成⁩

IGCSE, A-Level & AP