Middleware

Middleware is one of the most important Express concepts.

A middleware function runs during the request-response cycle.

It can:

Basic middleware

function logger(req, res, next) {
  console.log(req.method, req.url)
  next()
}

app.use(logger)

next() passes control to the next middleware or route handler.

Request flow

request -> middleware -> middleware -> route handler -> response

Example:

app.use(express.json())
app.use(logger)
app.get('/users', getUsers)

Express runs them in order.

Real request pipeline example

For a protected create-note API, the request may pass through this pipeline:

POST /notes
-> express.json()
-> requestLogger
-> requireAuth
-> validateCreateNote
-> createNoteController
-> errorHandler if something fails

Express code:

app.post(
  '/notes',
  requireAuth,
  validateCreateNote,
  createNoteController,
)

Each middleware has one job:

This keeps route logic readable.

Middleware can protect routes

function requireAuth(req, res, next) {
  if (!req.user) {
    return res.status(401).json({ error: 'Unauthorized' })
  }

  next()
}

app.get('/profile', requireAuth, getProfile)

Error middleware

Error middleware has four parameters:

function errorHandler(error, req, res, next) {
  res.status(500).json({ error: 'Something went wrong' })
}

Common mistake

If middleware does not send a response and does not call next(), the request hangs.

Bad:

function broken(req, res, next) {
  console.log('hello')
}

Interview answer

Middleware functions run in order during Express's request-response cycle. They can inspect or modify the request, send a response, call next() to continue, or pass errors to error-handling middleware. Middleware is commonly used for logging, authentication, validation, parsing, and error handling.