The Bookshelf API

Everything this chapter introduced separately now arrives as one program: a catalog API with four resources, fourteen endpoints, offset pagination, Zod 44,027 validation at the edge, bearer tokens, role and ownership rules, a generated OpenAPI document, and a Supertest 14,405 suite that runs in five seconds with no database. All 631 lines of it were run before they were printed.

The decision worth arguing about is the last layer. Bookshelf reaches records through a store object with a fixed set of methods; behind that object is an array in memory. MongoDB implements the same methods over Mongoose 243,355 models and swaps them in by changing one line, leaving routes, services, validation and tests untouched.

A request through Bookshelf, and the only layer Chapter 4 replaces
A request through Bookshelf, and the only layer MongoDB replaces

Build it rather than read it: npm 2,036 init -y, "type": "module", then express@5.2.1 zod@4.6.5 jsonwebtoken 18,189 @9.0.3 bcryptjs 3,797 @3.0.3 @asteasolutions/zod-to-openapi@9.1.0 supertest@7.2.2 — all current in September 2026, on Node.js 25.8 2,131 .

Subsections