A course is the basic teaching unit, it's design as a medium for a student to acquire comprehensive knowledge and skills indispensable in the given field. A course guarantor is responsible for the factual content of the course.
For each course, there is a department responsible for the course organisation. A person responsible for timetabling for a given department sets a time schedule of teaching and for each class, s/he assigns an instructor and/or an examiner.
Expected time consumption of the course is expressed by a course attribute extent of teaching. For example, extent = 2 +2 indicates two teaching hours of lectures and two teaching hours of seminar (lab) per week.
At the end of each semester, the course instructor has to evaluate the extent to which a student has acquired the expected knowledge and skills. The type of this evaluation is indicated by the attribute completion. So, a course can be completed by just an assessment ('pouze zápočet'), by a graded assessment ('klasifikovaný zápočet'), or by just an examination ('pouze zkouška') or by an assessment and examination ('zápočet a zkouška') .
The difficulty of a given course is evaluated by the amount of ECTS credits.
The course is in session (cf. teaching is going on) during a semester. Each course is offered either in the winter ('zimní') or summer ('letní') semester of an academic year. Exceptionally, a course might be offered in both semesters.
The subject matter of a course is described in various texts.
ANI-AM2 Middleware Architectures 2 Extent of teaching: 2P+1C Instructor: Vitvar T. Completion: Z,ZK Department: 18102 Credits: 5 Semester: Annotation:
Students will become familiar with modern web application architectures such as SPA and MPA. They will gain an overview of the asynchronous I/O model in JavaScript, network communication in the browser, and technologies such as XHR, Fetch API, SSE, WebSockets, and gRPC-Web. The course also covers web security, including Same-Origin Policy, CSRF, CORS, TLS, JWT, and OAuth2, as well as protection against attacks. Students will also learn the differences between REST and GraphQL and the principles of scaling distributed applications. The course further includes deployment and monitoring of web applications in Kubernetes using Prometheus and OpenTelemetry.
Lecture syllabus:
1. Web application architectures, SPA vs MPA, server-side rendering (SSR) vs client-side rendering (CSR). 2. Asynchronous I/O model in JavaScript in the browser and in Node.js 3. Architecture of network communication in the browser, XHR and FetchAPI. 4. Web Security Principles, Same-Origin Policy, Cookies and CSRF Protection 5. Web attacks and protection against them, CORS, XSS, SQL Injection, Clickjacking, Content Security Policy. 6. Authentication, authorization and security of communication on the Web, TLS, HSTS, RBAC. 7. (2) JWT and modern authentication protocols, JWT structure, OAuth2, OpenID Connect. 8. Streaming and realtime communication on the Web, protocols SSE, WebSockets, gRPC-Web. 9. GraphQL and the difference with REST, API Gateway. 10. Distributed systems and scaling on the Web, Load balancing, CDN, caching, API rate limiting. 11. Web application architecture in Kubernetes. 12. Monitoring, observability and debugging of Web applications. Seminar syllabus:
bude doplněnoLiterature:
1. Newman, S.: Building Microservices (2nd Edition). O?Reilly, 2019. ISBN 978-1492034025. 2. Pollard, B.: HTTP/2 in Action. Manning Publications, 2019. ISBN 978-1617295164. 3. Grigorik, I.: High Performance Browser Networking. O'Reilly Media, 2013. ISBN 9781449344757. Requirements:
Pro získání zápočtu je potřeba dostatek bodů z vypracování úloh na cvičení a samostatných domácích úloh. Zkouška se skládá z povinné písemné části.
Informace o předmětu a výukové materiály naleznete na https://courses.fit.cvut.cz/NI-AM2/ The course is also part of the following Study plans:
Study Plan Study Branch Role Recommended semester QNI Unspecified Specialisation of Study V 3 ANI-WI Web Engineering PS 3 ANI-SI Software Engineering (in Czech) VO 3 NI-PB.2026 Computer Security V 3 NI-SPOL.2026 Unspecified Specialisation of Study V 3 NI-UI.2026 Artificial Intelligence V 3 NI-PJ.2026 Programming Languages V 3 NI-TI.2026 Computer Science V 3 NI-PSS.2026 Computer Systems and Networks V 3 ANI-ES Embedded systems VO 3 ANI-MI Business Informatics VO 3 ANI-VG Visual computing and Game design VO 3 ANI-SPOL Unspecified Specialisation of Study VO 3
Page updated 18. 8. 2026, semester: Z/2023-4, Z/2021-2, Z/2022-3, L/2025-6, L/2022-3, Z/2025-6, L/2023-4, L/2024-5, Z/2026-7, L/2021-2, L/2026-7, Z/2024-5, Send comments to the content presented here to Administrator of study plans Design and implementation: J. Novák, I. Halaška