An API that only speaks JSON is rare in practice. Sooner or later the same Express 24,430 process has to hand a browser a stylesheet, render an HTML page, or accept a cover image a user picked from disk. Express covers the first two out of the box: express.static maps a URL prefix onto a directory, and the view layer — app.set('view engine') plus res.render — turns a template and an object into HTML. Uploads need one package, multer 12,087 .
Security runs through all three. A static directory is a promise that only those files are public. A template that interpolates user text without escaping is a stored cross-site-scripting bug. An upload endpoint without a size limit invites disk exhaustion; one that trusts the client's filename invites path traversal.
HTML forms, the multipart/form-data encoding and the caching headers are Front-End Web Development material; Node's streams are Buffers and Streams and res.sendFile is Redirects and Downloads. What follows stays on the server side of the wire.