← React Course

REACT CORE · 100

React Architecture:Component Boundary、State Ownership、Client / Server

最後一課不再加 Hook。你要把 React 放回整個系統:哪些是 UI state、哪些是 server data、哪些規則不能只相信 Browser、component tree 怎麼對應責任。

Learning outcomes

1. Component tree 應反映 responsibility

App
├─ Header
└─ CoursePage
   ├─ CourseFilters
   ├─ CourseSummary
   └─ CourseList
      └─ CourseCard

不是每一個 div 都需要 component;也不是整頁只需要 App。

2. 三種 state 先分層

State例子常見 owner
Local UImodal open、input draft最近使用它的 component
Shared UIfilter、selected course最近共同 parent / context
Server datacourses、current userdata fetching layer / cache

3. 不要把 server data 複製成太多 local state

如果 courses 已經是 source of truth,就不要再存:

passedCourses
failedCourses
averageScore
courseCount

這些通常能由 courses derive。複製越多,越容易彼此不同步。

4. Context 解決傳遞,不自動解決 architecture

Context 可以避免深層 prop drilling,但把所有 state 塞進一個巨大 context 不會自動讓設計變好。State boundary 仍需要依 ownership / update frequency / responsibility 決定。

5. React Browser 不是 security boundary

React UI
  ↓ HTTPS
Backend / Supabase
  ↓ auth + authorization
Database / RLS

隱藏按鈕不等於 authorization。Client validation 不等於 server validation。React code 裡看不到 secret 不代表 backend policy 自動安全。

6. CSR 與 server rendering 不要混成一句「React 網站」

純 client-side React build 可以只是 static HTML/CSS/JS assets;SSR / server components 等架構則引入不同 server execution boundary。遇到實際 framework 時再依該框架版本與官方文件判斷。

7. Project checkpoint:Course Dashboard final architecture

Browser
└─ React App
   ├─ CourseFilters
   ├─ CourseSummary
   └─ CourseList
        ↓
   request layer
        ↓ HTTPS
Node / API / Supabase
        ↓
validation + auth
        ↓
Database / RLS

UI responsibility 留在 React;authorization / data integrity 留在可信 server/data layer。

8. React 96–100 真正學到什麼?

課能力
96JSX/build/component render model
97props/state/snapshot/ownership
98events/forms/list identity
99effect/external synchronization/cancellation
100component/client/server architecture

Knowledge check / Final challenge

  1. 替 Course Dashboard 畫 component tree 與 state owner。
  2. 標出哪些值是 derived data,不應額外存 state。
  3. 畫出 GET /courses 從 Browser 到 Database 再回 UI 的完整流。
  4. 指出「隱藏 Edit 按鈕」為什麼不是 authorization。