Middleware
In short
Middleware is software that sits between two layers of a system, most often code that runs between an incoming request and the final response in a web server.
What is middleware?
Middleware is a general term for software that connects or sits between other pieces of software. In backend web development, it usually means a function that runs in the middle of handling a request: after the server receives it and before the route handler that produces the final response.
Middleware functions are chained into a pipeline. Each one can read or modify the request, add something to the response, stop the request early (for example, by returning 401 Unauthorized), or pass control to the next function, often by calling next(). Web frameworks such as Express, Koa, ASP.NET Core, Django, and Next.js all use this pattern.
Think of airport security: before you reach your gate, you pass through a ticket check, a security scan, and passport control, and any of them can stop you. Middleware is used the same way for cross-cutting concerns, meaning tasks shared by many routes, such as logging, authentication, parsing JSON bodies, compression, rate limiting, and CORS headers.
The word also has an older, broader meaning in enterprise software, where middleware refers to systems like message brokers, application servers, and integration platforms that connect separate applications. Both meanings share the same idea: a layer in the middle that handles shared work so the pieces on either side don't have to.
Key takeaways
- Middleware runs between receiving a request and sending the response.
- Multiple middleware functions form a chain that runs in order.
- Each one can modify the request, end it early, or pass it on.
- Common uses include logging, authentication, body parsing, CORS, and rate limiting.
Example
// Log every request, then hand it to the next function in the chain
function logRequests(req, res, next) {
console.log(`${req.method} ${req.url}`);
next();
}
app.use(logRequests); // runs for every request
app.use(express.json()); // built-in middleware that parses JSON bodies
app.get("/hello", (req, res) => {
res.send("Hello!");
});Readers ask
What does next() do in middleware?
In frameworks like Express, calling next() hands the request to the next middleware or route handler in the chain. If a middleware neither calls next() nor sends a response, the request hangs.
Is middleware the same as an API?
No. An API is the interface that clients call, while middleware is internal code that processes requests on their way to the code that implements that API.
Does the order of middleware matter?
Yes. Middleware runs in the order it is registered, so a body parser must run before any handler that reads the request body, and authentication must run before protected routes.
See also
- APIBackend & APIs, p. 2An API is a set of rules that lets one piece of software request data or actions from another in a predictable, documented way.
- HTTPWeb Development, p. 19HTTP is the protocol that browsers, apps, and servers use to exchange web pages and data through a simple cycle of requests and responses.
- FunctionProgramming Fundamentals, p. 21A function is a named, reusable block of code that performs a specific task, optionally taking inputs called parameters and returning a result.
- FrameworkProgramming Fundamentals, p. 20A framework is a reusable foundation of code, tools, and conventions that provides the structure of an application, so developers only fill in their own logic.
- CORSWeb Development, p. 8CORS is a browser security mechanism that lets a server declare which other websites may read its responses when they make requests from JavaScript.
- EndpointBackend & APIs, p. 12An endpoint is a specific URL, combined with an HTTP method, where an API receives requests and returns responses for one particular resource or action.
Spotted a mistake or something missing on this page?Suggest an edit