From standing up Tomcat yourself through the servlet lifecycle, what a JSP really is, MVC Model 2, sessions and filters, JDBC and DAOs, file uploads and security, all the way to building and deploying a war. Twenty lessons that build one library management app from the first line to the last. Every piece of code and output was produced by actually running Tomcat 11.0.25 on Java 21.
The 20 lessons are grouped into five chapters. Working through them in order is the best way, but you are welcome to dip into whatever interests you. Note: Java cannot run inside the browser, so try everything in the project you create in lesson 1.
You stand up Tomcat yourself, deploy a war, and confirm that a servlet is one instance shared across many threads. By the end you have made a full pass over receiving a request and returning a response.
You watch a JSP being converted into a servlet by opening the generated .java file. You write your screens with EL and JSTL, and compare the lifetimes of the four scopes by measurement.
You give the app its shape with MVC Model 2: servlets as controllers, JSPs as views. Duplicate submissions, input checking, sign-in, filters and error pages are all covered here.
You replace the in-memory List with H2 and tidy it up with DAOs and a connection pool. You complete CRUD and implement search, paging and sorting.
You break each of the four rules of safe file upload on purpose to see why they matter, then work through XSS, SQL injection and CSRF. Finally you build separate wars for production.
Once you have finished all 20 lessons, move on to Spring Boot, where the framework takes over the parts you wrote by hand here. Membership unlocks every course.