Review Checklist
Use this checklist when reviewing backend code, design docs, or generated implementations.
Architecture
- Are controllers thin and transport-only?
- Is business logic isolated in services?
- Are repositories the only layer touching persistence details?
- Are external integrations behind adapters?
API And Validation
- Are request and response contracts explicit?
- Are status codes semantically correct?
- Is validation done before business logic?
- Are pagination, filtering, and versioning sensible?
- Are idempotency and retry semantics defined for transactional endpoints?
Database And Cache
- Any N+1 queries or hidden ORM loops?
- Are indexes aligned to real filter and sort paths?
- Are transactions scoped tightly?
- Is cache invalidation defined?
- Is the cache strategy justified?
- Are uniqueness guarantees enforced in the database where correctness depends on them?
Reliability
- Are timeouts, retries, and cancellation handled?
- Are background jobs used where synchronous work is too slow?
- Is shutdown graceful?
- Are webhooks and jobs idempotent?
- Are downstream failures isolated well enough to avoid cascading outages?
Security
- Are authn and authz enforced at the correct boundary?
- Are secrets protected?
- Are CORS and rate limits configured?
- Are internal errors hidden from clients?
- Are common injection paths blocked?
Observability
- Are logs structured?
- Is a request or trace ID propagated?
- Are key metrics measurable?
- Are downstream calls traceable?
Testing And Delivery
- Are happy path and failure path tests present?
- Are integration tests covering DB, cache, queue, or external boundaries?
- Would CI catch schema, migration, or contract regressions?
- Is deployment strategy safe for the change risk?
- Is there at least one test that would catch the most likely production incident here?