| 📊 View Lecture Slides | Full-screen presentation with navigation |
Session 5: AI-Assisted Software Engineering
| Session Duration: 2 Hours | Block: 2 — AI-Assisted Engineering & Integration |
Session clock
| Minutes | Mode | Focus |
|---|---|---|
| 0–50 | Lecture | Theoretical Foundation & Concepts |
| 50–110 | Core lab | Copilot Workflows & Express API |
| 110–120 | Checkpoint | Pair share / show artifact |
Note: Stretch work starts only after the Core checkpoint is completed.
Learning Objectives
By the end of this session, students will be able to:
- Describe the modern AI-assisted software development workflow and the mental models required to succeed in it.
- Use GitHub Copilot to explain, generate, and debug backend JavaScript code within the course’s Node/Express starter kit.
- Apply the “describe → generate → evaluate → refine” cycle for robust code creation.
- Identify the strict limitations of AI code generation and understand where human architectural judgment is irreplaceable.
Part 1: Theoretical Foundation — AI as a Development Partner
1.1 The New Mental Model of Software Engineering
In traditional software development, the engineer writes nearly every line of code manually, either from memory or by constantly consulting StackOverflow and official documentation. The engineer is the primary typist of the system.
In AI-assisted software development, the paradigm shifts entirely. You transition from being a typist to being an architect and director. You direct the AI to write the boilerplate, the utility functions, and the standard logic. You then evaluate and refine its output. The AI handles the volume of implementation; you handle the strategy, security, and integration.
This shift has a critical implication for your education: You no longer need to memorise every syntax detail of every language by heart, but you absolutely must understand what correct, secure, and performant code looks like.
If you cannot read and evaluate the AI’s output, you cannot responsibly ship it. An AI-assisted developer who cannot read code is a liability, as they will blindly commit subtle bugs and security vulnerabilities into production.
1.2 Four Key GitHub Copilot Workflows
GitHub Copilot (and similar tools like Cursor or Claude Sonnet in-editor) offers several modes of interaction. Mastering these four workflows is essential for speed and accuracy.
Workflow 1: Explain Code (Onboarding & Navigation) You will frequently inherit code you didn’t write (including this course’s starter kit). Action: Highlight an entire function or file in VS Code, open the Copilot Chat panel, and type: “Explain what this code does, step by step, specifically focusing on how it handles errors.” Value: Rapid onboarding to new codebases or complex library internals.
Workflow 2: Generate Code from Comments (Implementation) This is the classic Copilot feature. You write a natural language comment describing the desired logic, press Enter, and wait for the ghost text to appear. Example:
// Parse the JSON body from the Express request, validate that 'userId' exists,
// and return a 400 error if it is missing.
Action: Press Tab to accept the suggestion.
Value: Eliminates boilerplate typing. However, you must immediately read the generated code to verify it matches your comment’s intent.
Workflow 3: Debug with Explanation (Troubleshooting) When an error occurs, do not just stare at the stack trace. Action: Copy the exact error message from your terminal, highlight the code block where the error occurred, and ask Copilot Chat: “I am getting this error: [Paste Error]. Here is the code: [Code]. What is the root cause, and how do I fix it?” Value: Drastically reduces time spent searching forums for obscure error codes.
Workflow 4: Write Tests (Quality Assurance) Writing unit tests is tedious but necessary. AI excels at this because test patterns are highly repetitive. Action: Select a function you just wrote and ask: “Write three Jest test cases for this function: one for the happy path, one for an edge case (empty array input), and one testing the error throw.” Value: Ensures higher code coverage with minimal developer friction.
1.3 The Evaluate-Refine Cycle
AI-generated code is always a first draft. Never treat it as production-ready without passing it through this cycle:
- Does it run? Syntax errors or hallucinated variable names are common. Run the code immediately.
- Does it do what I asked? Test it with simple inputs that you can verify manually.
- Does it handle edge cases? What happens if the user inputs an empty string? A massive payload? A completely different data type?
- Is it readable? Did the AI write a massively complex one-liner regex, or clean, maintainable logic? If it’s unreadable, ask the AI to refactor it for clarity.
- Is it secure? Did the AI trust user input without sanitization? Did it accidentally expose a
.envvariable?
1.4 What AI Cannot Replace
AI code generation is immensely powerful, but it is not magic. It relies on patterns it has seen before. It reliably fails at:
- Novel Architecture Decisions: Should this application use a monolithic Express server or serverless functions? The AI can list the pros and cons, but it cannot know your team’s budget, timeline, or scaling constraints.
- Business Logic Validation: The AI does not know if a 5% or 10% tax rate is legally correct for your specific product’s jurisdiction.
- Security Edge Cases: AI frequently generates code that is syntactically correct but fundamentally insecure (e.g., vulnerable to SQL injection).
- Complex Integration Debugging: When three different APIs interact unexpectedly, AI often hallucinates the root cause because it lacks systemic context.
Your role as an engineer is to provide the human judgment that these tasks require.
Part 2: Practical Labs — Navigate the Starter Kit
The backend starter lives at github.com/arjankc/ai-product-engineering. Use your track from Session 1 so you get that track’s PRD and domain vault. If you chose a custom product, stay on main.
Setup commands (copy-paste)
First time — replace NN with your track number (01 … 10). Custom product → stay on main.
git clone https://github.com/arjankc/ai-product-engineering.git
cd ai-product-engineering
git fetch --tags
git checkout track-NN
cp .env.example .env # Gemini key needed from Session 7; never commit .env
npm install
npm run dev
Examples: Track 1 → git checkout track-01 · Track 7 → git checkout track-07. Full branch names are in BRANCHES.md if you need them for commits after a detached tag checkout.
Already cloned?
cd ai-product-engineering
git fetch --tags
git checkout track-NN
npm install
npm run dev
Confirm with git status. Open http://localhost:3000.
Solutions: build on your track first. When stuck, open a phase tag, diff, return — HOW-TO-USE-SOLUTIONS.md. Phase 3 is real kit RAG; phase 4 adds multimodal, safety, calculator, KB search, and your domain tool.
Note: Session 5 Core is already implemented in the current starter (GET /health, lib/utils.js → normalizeQuery, and Stretch GET /version). Use this hour to explore with Copilot, verify behaviour, practise debug/test workflows, and rewrite the notes for your own understanding — do not wipe working Session 5 code.
Lab 5.1 — Explore with Copilot (Core)
- Open the cloned repository folder in VS Code (on your track).
- Confirm
npm run devis running. - Task 1 — Understand: Open
server.js. Highlight the middleware section (theapp.uselines). Ask Copilot Chat to explain what JSON body parsing and static file serving mean in this context. - Task 2 — Map the Session 5 pieces: Ask Copilot to explain
GET /health,GET /version(Stretch already present in the starter), and hownormalizeQueryfromlib/utils.jsis used inPOST /query. Then list which remainingTODOcomments belong to later sessions (7, 9, 11, 14).
Lab 5.2 — Verify and Debug (Core)
- Task 3 — Verify health (and optionally Stretch
/version; server must be running):
curl -s http://localhost:3000/health
curl -s http://localhost:3000/version
Confirm JSON like { "ok": true, "timestamp": "…" }. /version is Stretch already wired in the kit — verify it if you have time; Core requires /health.
- Task 4 — Verify query normalisation:
curl -s -X POST http://localhost:3000/query -H "Content-Type: application/json" -d "{\"query\":\" hello \"}"
curl -s -X POST http://localhost:3000/query -H "Content-Type: application/json" -d "{\"query\":\" \"}"
Confirm trim behaviour on the first call and a 400 on the empty/whitespace call.
- Task 5 — Debug: Intentionally break working code (delete a closing brace, or misspell
res.json). Restart, paste the terminal error into Copilot Chat, and ask it to diagnose. Restore the file when done.
Lab 5.3 — Own the helper (Core)
Open lib/utils.js and read normalizeQuery. With Copilot, do one of:
- Add a second exported helper your product will need (e.g. strip control characters, or reject queries shorter than 3 characters), wire it into
/query, and test it; or - Ask Copilot to propose improvements to
normalizeQuery, evaluate them, and keep only changes you can justify.
Lab 5.4 — Documenting the AI Interaction (Core)
03-Project/Copilot-Notes.md currently contains a filled reference example. Replace or heavily edit it with your own notes. Choose one:
- Option A: Document three test cases you actually ran (for
/health,normalizeQuery, or your Lab 5.3 helper), including the commands and results. - Option B: Document the intentional error from Lab 5.2 — error text, Copilot diagnosis, and whether it was helpful or misleading.
Stretch Goal: Add a product-specific route or response field that the generic starter does not have yet (still no Gemini key in the browser), and note it in Copilot-Notes.md.
If you get stuck later this block, return to your track after peeking at a phase tag:
git fetch --tags
git checkout solution-NN-phase-1 # example: solution-03-phase-1
# inspect, then:
git checkout track-NN
Key Takeaways
- AI-assisted development shifts your role from an “implementation typist” to a “software architect and quality controller.”
- The four core Copilot workflows are: Explain, Generate, Debug, and Test.
- The Evaluate-Refine cycle is non-negotiable. Never blindly ship unreviewed AI-generated code.
- AI excels at boilerplate and standard algorithms, but reliably fails at novel architecture, specific business logic validation, and complex security edge cases.
Further Reading & Resources
- GitHub Copilot Documentation: docs.github.com/copilot - Deep dive into advanced chat commands (
/explain,/fix). - Express.js Routing Guide: expressjs.com - The official documentation for the backend framework we are using.
- OWASP Top 10 Web Application Security Risks: Essential reading for understanding the security vulnerabilities AI might accidentally generate.


