Full-Stack Web Development
Build, test, containerise and deploy a complete multi-user web application in TypeScript, and defend every layer of it under questioning.
What you'll be able to do
Graduates can build, test, containerise, deploy and operate a complete multi-user web application, and can explain and defend every layer of it under questioning.
- Write strict TypeScript across frontend and backend
- Design a normalised relational schema and manage it with migrations
- Build a documented, validated REST API with authentication and role-based authorisation
- Handle file uploads, background jobs and third-party integrations
- Write unit, integration and end-to-end tests that run in CI
- Containerise an application and run the full stack locally with one command
- Deploy through a CI/CD pipeline and diagnose production issues from logs
Who it's for
- CS/IT students and graduates
- Career-switchers with some coding exposure
- Self-taught developers with gaps in testing, deployment or database work
- Frontend developers moving to full-stack
Prerequisites
- Basic programming logic in any language: variables, loops, functions
- HTML and CSS familiarity
- Comfort with a computer's filesystem
A two-week JavaScript primer runs before each cohort for applicants who need it.
All students complete the two-session Engineering Onboarding module before Module 1.
Tools and technologies
Target roles
Course curriculum
- Concepts
- ES modules; scope and closures; array and object methods; destructuring and spread; asynchronous JavaScript, including the event loop, promises, error propagation and concurrent against sequential awaits; HTTP fundamentals covering methods, status codes, headers and CORS; TypeScript structural typing, interfaces and types, unions and narrowing, generics, unknown against any, typing API responses, strict mode; package management and semantic versioning; linting and formatting.
- Lab
- convert an untyped script to strict TypeScript with no escape hatches; build a typed API client with error handling and retries; identify and fix a race condition; debug with breakpoints rather than log statements.
- Project
- a typed CLI tool consuming a public API, with graceful failure handling and a README.
- Concepts
- declarative rendering; composition and typed component contracts; state hooks and dependency-array pitfalls; derived against stored state; lists and keys; controlled forms and validation experience; lifting state; context and its limits; data-fetching patterns treating loading, error, empty and success as first-class states; custom hooks; memoisation only when measured; accessibility basics covering labels, focus, keyboard navigation and semantics; responsive layout.
- Lab
- build a filterable, sortable, paginated data table against a real API handling all four states; build a multi-step form with per-field validation and optimistic updates; profile and fix a component that re-renders excessively.
- Project
- Mini-project 1: a responsive, accessible frontend consuming a public API, deployed at a live URL.
- Concepts
- entities, relationships, practical normalisation and key selection; SQL covering joins, aggregation, grouping, subqueries and window function basics; indexes and query performance; transactions; the N+1 query problem; ORM against raw SQL and when to drop down; migrations as versioned schema history; seeding; timestamps, soft deletes and audit columns; multi-tenancy basics; parameterisation and SQL injection; when a document store is the better fit.
- Lab
- model a multi-user domain with roles from a written specification; write the migrations; seed realistic data volume; write twelve progressively harder SQL queries by hand; find and fix an N+1 using query logs; add an index and measure the improvement with EXPLAIN.
- Project
- the capstone schema, migrations and seed data, reviewed for modelling quality before API work begins.
- Concepts
- REST design covering resources, methods, status codes, pagination, filtering, versioning and idempotency; boundary validation; consistent error contracts; password hashing; sessions against JWTs and their trade-offs; refresh tokens; OAuth flows; email verification and password reset; role-based access control and ownership checks; the OWASP Top 10 applied concretely to injection, broken access control, XSS, CSRF, secrets handling and SSRF; rate limiting; CORS; API documentation as a deliverable.
- Lab
- build a validated, paginated, role-aware CRUD API; implement signup, login and password reset end to end; attempt broken access control, missing ownership checks and injection against a classmate's API, then fix your own; publish OpenAPI documentation.
- Project
- Mini-project 2: a documented, secured REST API with a Postman collection and an authorisation matrix in the README.
- Concepts
- Next.js App Router covering server and client components, rendering strategies, server actions, layouts and route protection; caching and revalidation; file upload and object storage; email delivery; background work through queues, workers and scheduled jobs; webhooks and signature verification; third-party integration using payments as the worked example; real-time updates; integrating an LLM feature with server-side keys, streaming, cost limits and graceful failure; performance basics covering bundle size and Core Web Vitals.
- Lab
- protect routes with server-side session checks; upload documents to object storage with type and size validation; move a slow export into a background job with status polling; consume and verify a signed webhook; add a streaming AI summarisation feature with a token budget.
- Project
- the capstone application reaches feature-complete.
- Concepts
- the testing pyramid applied pragmatically; unit tests for pure logic; integration tests against a real test database; test data factories and isolation; what to mock and what never to mock; end-to-end tests for critical journeys; test naming as documentation; flaky tests and their root causes in waiting, ordering and shared state; coverage as a signal; test-driven development demonstrated on one feature; regression tests written from real bugs.
- Lab
- write tests for untested code and locate existing bugs; integration-test the authentication flow including negative cases; write three Playwright journeys; fix a flaky test by replacing a sleep with proper waiting.
- Project
- the capstone covers business logic, all API routes and three critical journeys.
- Concepts
- containers against virtual machines; Dockerfile authoring covering layers, caching, multi-stage builds, image size and non-root users; Docker Compose for multi-service local development; environment configuration and secrets across environments; CI/CD stages, branch protection, required checks, preview deployments, migration strategy on deploy and rollback; database backups; structured logging with request correlation; error tracking; uptime and health checks; alerting; HTTPS, domains and security headers; cost awareness.
- Lab
- containerise the stack so it starts with one command; build the pipeline covering lint, typecheck, test, build, migrate and deploy, with a required green check to merge; deploy to production; diagnose a deliberately broken production deployment from logs and error tracking alone; execute a rollback; run the same application on AWS in the variant lab.
- Project
- the capstone is live, containerised, pipeline-deployed, monitored and documented.
- Concepts
- Agile practice covering backlog, estimation, sprint, standup, review and retrospective; user stories and acceptance criteria; issue tracking and definition of done; branching strategy for a team; code review as a craft, including how to give, receive and disagree with feedback; technical debt as a recorded decision; documentation covering README, architecture decision records, API reference and onboarding guide; handover; final performance and security passes; refactoring under test cover.
- Lab
- a two-day sprint on a shared client backlog with full ceremonies; each student reviews two classmates' pull requests against a rubric; Lighthouse and dependency-audit remediation; write an onboarding guide and have a classmate follow it without assistance.
Capstone project
A complete multi-user SaaS application, built individually across weeks three to eight against a written client brief. Options include a clinic appointment and records system, a school fee and attendance platform, a multi-vendor inventory and orders system, or a freelance invoicing and payments platform.
Requirements
- Role-based authentication and authorisation
- Normalised PostgreSQL schema with migrations
- Documented REST API with validation
- File uploads
- At least one background job
- One third-party integration
- One AI-assisted feature
- Unit, integration and three end-to-end tests, green in CI
- Docker Compose local environment
- CI/CD pipeline with branch protection
- Deployed live URL
- Structured logging and error tracking
- README covering architecture, setup, API reference, trade-offs and known limitations
- Complete pull request history showing incremental work
Assessment
Capstone standard: runs from a clean clone, tests pass in CI, deployed at a URL, README explains architecture and trade-offs, commit history shows incremental work, and the student can defend every design decision.
Out of scope
- Kubernetes
- Microservices architecture
- GraphQL beyond one awareness session
- Native mobile development
- Advanced data structures and algorithms
Enquire about this course
Ask about the next cohort, schedule or prerequisites and our team will get back to you.



