Build Taskboard from the first request to the final check
Start in an empty taskboard folder. Keep one project throughout these fifty steps. Let AI implement each bounded change. Review the code and run the checkpoint checks before advancing.
Build completion is your record of observed results. The course does not run checks against your local project.
1. Build a task API
Create and list tasks in a local browser.
- Start the server in an empty folder.
- Create the first task.
- List tasks with a clear HTTP contract.
- Keep requests responsive while awaiting work.
- Put request checks in the right order.
- Reject invalid task input.
Release check. Create a task through the form, list it, reject bad input, and explain why a restart loses it.
2. Keep tasks in PostgreSQL
Tasks survive a restart and conflicting edits are rejected.
- Give tasks a relational home.
- Apply the first migration safely.
- Replace the in-memory task store.
- Reject impossible relationships.
- Describe the persisted model in code.
- Commit a change and its history together.
- Protect task edits from stale versions.
- Load bounded task pages.
Release check. Create, edit, paginate, restart, and reload a task. Prove a stale edit and invalid relationship fail.
3. Add accounts and teams
Signed-in users work only inside their authorized workspace.
- Register an account safely.
- Keep the caller signed in.
- Protect browser writes.
- Create a team workspace.
- Scope every task to its workspace.
- Enforce each team role.
- Prove that changed IDs grant no access.
Release check. Register, log in, choose a workspace, add a project and comment, then reject a foreign account and forbidden role.
4. Deliver durable work
The worker delivers email and the app survives retries.
- Expose the gap after a commit.
- Record the work before returning success.
- Run the first worker.
- Recover a stopped worker.
- Retry recorded failures without a tight loop.
- Deliver an email through local SMTP.
- Verify the account through its email link.
- Invite a verified colleague.
- Reset the password and revoke sessions.
- Replay a create without adding another task.
- Reject a changed payload under the same key.
- Inspect and replay failed work deliberately.
- Check what an external acknowledgement proves.
Release check. Verify an account, invite and accept a colleague, reset a password, replay a task create, and recover an expired job claim.
5. Add live updates and payments
Connected teammates refresh changes and billing follows provider state.
- Connect the second browser.
- Recheck access before sending an event.
- Recover the view after a disconnect.
- Create a test checkout safely.
- Enforce the subscription on the server.
- Verify the provider message before trusting it.
- Record each provider event once.
- Reconcile with current provider state.
Release check. Use two clients, disconnect and reconnect, exercise test checkout and portal, and reject invalid or duplicate webhooks.
6. Run and recover the project
The complete app starts, stops, restores, and passes its checks.
- Finish the security boundaries.
- Follow a failure across API and worker.
- Find and remove one measured bottleneck.
- Package the whole app stack.
- Rehearse a deployment locally.
- Drain work when a process stops.
- Restore into a fresh database.
- Accept the completed Taskboard project.
Release check. Start API and worker from built images, rehearse migrations, drain shutdown, restore into a disposable database, and run final acceptance.
The deployment step rehearses locally. Finish shutdown, restore, and final acceptance before a public rollout. The completed reference app is a comparison when you need one, not code to preload into the empty project.