惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
F
Fortinet All Blogs
J
Java Code Geeks
Y
Y Combinator Blog
Stack Overflow Blog
Stack Overflow Blog
V
Visual Studio Blog
M
MIT News - Artificial intelligence
腾讯CDC
Last Week in AI
Last Week in AI
The Cloudflare Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
Microsoft Security Blog
Microsoft Security Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
P
Proofpoint News Feed
博客园 - 叶小钗
Recent Announcements
Recent Announcements
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
人人都是产品经理
人人都是产品经理
L
LangChain Blog
博客园 - 司徒正美
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
Why DaloyJS Is the Best Backend (or BFF) for Your Electro...
Daloy JS · 2026-06-05 · via DEV Community

If you've ever built an Electron app that needs a backend, you know the problem. You want something lightweight, something that runs on Node, something where you don't spend three hours configuring Swagger, and something that doesn't make you feel like you're setting up a microservices architecture just to expose two endpoints to your own desktop UI.

I've shipped Electron apps with Express. I've tried Fastify. Both work, but they leave you doing a lot of plumbing yourself. Then I found DaloyJS, and honestly, it clicked.

The Electron Backend Problem

Here's the thing about Electron: your renderer process is basically a browser, and your main process is a Node.js server. When you need data from external APIs, or you need a clean layer between your UI and your business logic, you want a BFF, a Backend for Frontend. A thin server that composes upstream calls, holds the session, and returns exactly the shape your UI needs.

DaloyJS was built for this role. The docs even say so plainly: typed upstream client, fetchGuard for safe egress, session handling, and edge runtime support. That combination is exactly the BFF toolkit.

Contract-First Means Less Glue

The killer feature for desktop apps is contract-first routing. You define a route once, and DaloyJS gives you validation, OpenAPI 3.1 docs, and a typed in-process client all from the same source. No stale spec files. No writing types by hand.

Here's what a basic Electron BFF route looks like:

import { z } from "zod";
import { App, requestId, secureHeaders, rateLimit } from "@daloyjs/core";
import { serve } from "@daloyjs/core/node";

const app = new App({
  bodyLimitBytes: 1 << 20,
  requestTimeoutMs: 5_000,
  docs: true, // auto-mounts /docs and /openapi.json
});

app.use(requestId());
app.use(secureHeaders());
app.use(rateLimit({ windowMs: 60_000, max: 120 }));

app.route({
  method: "GET",
  path: "/settings/:userId",
  operationId: "getUserSettings",
  request: { params: z.object({ userId: z.string() }) },
  responses: {
    200: {
      description: "OK",
      body: z.object({ theme: z.string(), language: z.string() }),
    },
  },
  handler: async ({ params }) => ({
    status: 200,
    body: { theme: "dark", language: "en" },
  }),
});

serve(app, { port: 3123 });

Enter fullscreen mode Exit fullscreen mode

From the renderer, you call it with a typed client. No fetch boilerplate, no guessing the response shape:

import { createClient } from "@daloyjs/core/client";

const client = createClient(app, { baseUrl: "http://localhost:3123" });
const result = await client.getUserSettings({ params: { userId: "me" } });
// result.body is fully typed: { theme: string, language: string }

Enter fullscreen mode Exit fullscreen mode

That's the whole loop. One definition, end-to-end types.

Secure by Default, Which Matters More Than You Think

Desktop apps often access local files, internal network APIs, and cloud services at the same time. That's a juicy attack surface if your BFF is careless. DaloyJS starts with prototype-pollution-safe JSON parsing, built-in load shedding, automatic 5xx info-disclosure stripping in production, and fetchGuard that blocks SSRF and cloud-metadata IPs by default. I learned the hard way on a previous job that "just use Express" means you're also responsible for all that yourself.

Scaffold and Go

Getting started takes one command:

pnpm create daloy@latest my-electron-api

Enter fullscreen mode Exit fullscreen mode

The scaffold drops in a hardened .npmrc (blocked install scripts, 24h release-age cooldown, source-verified lockfiles) plus an AGENTS.md so your coding assistant actually understands the project conventions. For a solo dev building a desktop app on the side, that's a lot of boilerplate you never have to write.

The Bottom Line

DaloyJS is not trying to be the next Express. It's trying to remove the glue between the best ideas in the ecosystem: FastAPI-style docs, Hono-style portability, Fastify-style ops, and Elysia-level typing. For an Electron BFF running on Node, that combination is hard to beat. You get a typed contract, security defaults you'd otherwise forget, and auto-generated docs your future self will thank you for.

Start with pnpm create daloy@latest, wire it to your renderer, and stop writing boilerplate.