warming up your workspace

Backend Java

Build the pieces behind a web service with Java. Explore HTTP, parsing, routing, validation, storage, and sessions before assembling a REST service.

What helps

The Java Foundations section is available if the language is new to you. The main projects are easier to follow with an understanding of functions, classes, and collections.

Java pathway

Programming Foundations / Practice rooms / Track curriculum and enrollment

  1. The HTTP Protocol

    Every web framework is, at bottom, a string parser: a browser sends a few lines of text, and the server sends a few lines back. This project builds that text protocol from scratch, splitting a request into method, path, and version, reading headers with case-insensitive lookup, decoding query strings and percent-escapes, mapping status codes to their reason phrases, and assembling a well-formed response. No sockets, just the wire format every backend speaks.

    • The Request Line: 5 lessons
    • Headers: 5 lessons
    • Query Strings: 5 lessons
    • Status & Response: 5 lessons
    • The Full Message: 5 lessons
  2. A JSON Parser from Scratch

    Behind every @RequestBody and res.json() is a parser that turns a stream of characters into a tree of objects. This project builds one: a tokenizer that recognizes strings, numbers, and punctuation; a recursive-descent reader that assembles maps, lists, and scalars; and a serializer that walks the tree back to text with the escaping the spec demands. Once you have written it, JSON stops being magic.

    • Scalars: 5 lessons
    • Arrays: 5 lessons
    • Objects: 5 lessons
    • Serialization: 5 lessons
    • Robust Parsing: 5 lessons
  3. Routing

    A router is a lookup table from (method, path) to handler. This project builds one from scratch: matching exact paths, extracting path parameters like /users/:id, distinguishing a missing route (404) from a wrong method (405), ordering routes so the most specific wins, and assembling a Router class that dispatches a request to the right handler. The piece of every framework that decides which of your functions runs.

    • Exact Matches: 5 lessons
    • Path Parameters: 5 lessons
    • Method Matching: 5 lessons
    • Route Precedence: 5 lessons
    • The Router: 5 lessons
  4. Middleware

    Between the router and your handler sits a stack of middleware: functions that log, authenticate, parse, compress, and short-circuit. This project builds the chain from scratch, a shared request context, before-and-after hooks, the onion model where each layer wraps the next, auth gates that stop the request early, and a composed pipeline. Once you have written it, app.use() stops being magic.

    • The Request Context: 5 lessons
    • The Chain: 5 lessons
    • Short-Circuiting: 5 lessons
    • The Onion Model: 5 lessons
    • The Application Stack: 5 lessons
  5. The Repository Layer

    Behind every save() and findById() is a data store and a mapping. This project builds a mini-ORM in memory: a table of rows keyed by an auto-incrementing id, full CRUD, mapping rows to and from entity objects, finding by arbitrary fields, and a small query DSL with filtering, sorting, and paging. No database, just the HashMap and the abstractions that make it look like one.

    • The Table: 5 lessons
    • CRUD: 5 lessons
    • Entity Mapping: 5 lessons
    • Querying: 5 lessons
    • A Query DSL: 5 lessons
  6. Connection Pooling & Rate Limiting

    Opening a database connection is expensive, so servers keep a POOL and lend them out. Sending unlimited requests is dangerous, so servers RATE-LIMIT. This project builds both from scratch: a bounded pool with borrow, return, exhaustion, validation, and statistics; and a token-bucket limiter that refills over time. Time and randomness are passed in so everything stays deterministic and testable.

    • The Pool: 5 lessons
    • Connection Lifecycle: 5 lessons
    • Token Bucket: 5 lessons
    • Limiting Strategies: 5 lessons
    • The Resource Guard: 5 lessons
  7. Caching

    A cache trades memory for speed, and the hard parts are eviction and freshness. This project builds them: an LRU cache that drops the least recently used entry when full, TTL expiry that retires stale entries, the cache-aside pattern that loads on a miss, hit/miss statistics that tell you if the cache is worth it, and ETag conditional responses that skip the body entirely. Time is passed in, so every test is deterministic.

    • A Basic Cache: 5 lessons
    • LRU Eviction: 5 lessons
    • TTL & Expiry: 5 lessons
    • Cache-Aside: 5 lessons
    • HTTP Caching: 5 lessons
  8. Validation & DTOs

    A request body arrives as untrusted data; before your handler touches it, it must be validated and bound into a typed object. This project builds that layer: individual constraints (required, range, length, pattern), a validator that collects EVERY violation instead of failing on the first, binding a map into a DTO, and the problem-detail error response that tells the client exactly what went wrong. The boundary between the wild internet and your clean domain.

    • Constraints: 5 lessons
    • The Validator: 5 lessons
    • Request Binding: 5 lessons
    • Problem Details: 5 lessons
    • Sanitization: 5 lessons
  9. Sessions & Auth

    Authentication answers 'who are you?' and authorization answers 'what may you do?'. This project builds both: a signed token (using a simple deterministic hash, a TEACHING stand-in for real HMAC, never use it in production), verification that detects tampering, a session store with expiry, bearer-header extraction, and role and permission checks. The shape of every auth system, with the cryptography deliberately simplified so the structure stays visible.

    • Signed Tokens: 5 lessons
    • Expiry: 5 lessons
    • The Session Store: 5 lessons
    • Auth Headers: 5 lessons
    • Authorization: 5 lessons
  10. Capstone: A REST Service

    Ten projects of machinery, one running service. This capstone assembles a small in-memory user API: a repository holds the data, a router maps requests to handlers, the JSON layer parses bodies and serializes responses, middleware authenticates, and a cache speeds reads. Each chapter wires one more layer, and the finale takes a raw HTTP request string and returns a raw response string, the whole backend you built, end to end.

    • The User Resource: 5 lessons
    • The Handlers: 5 lessons
    • Wiring the Router: 5 lessons
    • The Request Pipeline: 5 lessons
    • End to End: 5 lessons