Understanding Technology
You don't need to write code, but you do need to know which layer something happens on. Confuse the layers and your needs won't land—and the errors you see will be unreadable.
- 「这个改前端就行」和「要动后端」的区别在哪
- 为什么登录状态会莫名其妙掉,token 是个什么东西
- AI 写的代码里,哪几个地方是安全隐患的高发区
Frontend and backend
One-sentence dividing line: anything changeable in the user's browser is frontend; anything that has to compute on your server is backend. Anything involving money, permissions, or someone else's data always lives on the backend.
| 这件事 | 在哪一层 | 为什么 |
|---|---|---|
| 按钮改个颜色 | 前端 | 纯展示,跟数据无关 |
| 列表加个筛选 | 前端后端 | 数据量小前端筛,量大要后端出接口 |
| 判断能不能删 | 后端 | 前端的判断能被绕过,权限必须在后端拦 |
| 算价格和优惠 | 后端 | 前端算的价格用户能改,这是常见的漏洞 |
| 页面加载慢 | 看情况 | 可能是图片太大(前端),也可能是查询太慢(后端) |
How login works
Login isn't "verify once and done." It's "verify once, then carry a token on every request after."
What a database looks like
Just tables. Each table stores one kind of thing, and tables relate to each other by id. When you sketch a data model, this is what you're drawing.
| id | name | created_at |
|---|---|---|
| u_31 | 李明 | 2026-03-04 |
| u_88 | 王芳 | 2026-05-19 |
| id | user_id | amount | status |
|---|---|---|---|
| 2048 | u_31 | 124.00 | 已付 |
| 2047 | u_31 | 38.80 | 待付 |
Deployment and environments
The same code runs in three places. When something breaks, first ask which one.
| 环境 | 谁在用 | 数据是真的吗 |
|---|---|---|
| 本地 | 只有你自己 | 假数据,随便删 |
| 预发 | 你和少数几个人验收 | 接近真实,但删了不心疼 |
| 线上 | 所有真实用户 | 真的,删了就没了 |
Six security basics
AI-generated code fails most often in these six spots. Give them a scan after every generation.
- Secrets don't go in code. API keys and database passwords belong in environment variables—and never in frontend code, that's the same as publishing them.
- Permissions are checked on the backend. Hiding a button on the frontend isn't permission control; the API itself must verify whether this person is allowed.
- All user input is untrusted. Concatenating SQL and rendering HTML directly are both injection entry points.
- Only return the fields you should. A user API that returns phone number and ID number together is the most common data leak.
- Money and stock are computed on the backend. Any number the frontend computes and passes to the backend can be tampered with.
- Deletion must be recoverable. Do soft delete first; real physical deletion goes through a separate flow.
