Every route you have written so far trusts its input. req.body.year is assumed to be a number, req.params.id is assumed to name a book that exists, and the store is assumed to answer. Production breaks all three within a day: a mobile client ships a string where a number belongs, a crawler requests an id deleted last month, and the database refuses a connection during a failover.
Two mechanisms absorb that. Validation decides, before any handler logic runs, whether a request is worth processing at all, and rejects it precisely enough for the client developer to fix their code. Error handling decides what the client sees when something fails anyway — a deliberate refusal such as "that ISBN is already taken," or an unplanned one such as a dropped socket. Get them wrong and you ship two failure modes at once: 500s that should have been 400s, and stack traces printed to strangers. They meet at one point: a validator throws rather than writing a response, and one middleware at the bottom of the stack turns everything thrown into a single shape.

Node's error fundamentals — the Error object, cause, operational versus programmer errors, and structured logging with pino 18,227 — are Errors and Causes through Request Logging. What follows is what Express 24,430 adds on top.