Web Frameworks
The server-side frameworks that turn an HTTP request into application code — Spring and Quarkus on the JVM, Django and FastAPI in Python, Express and NestJS in Node, plus Laravel, Rails, ASP.NET Core, Gin, Axum and more. Interviewers use whichever framework you claim to probe how much of the request lifecycle you actually understand versus how much you let the framework hide.
on this pageshowhide
explore
- Spring Framework (has its own guide)2,380 questions
- Core Container & IoC224 questions
- Aspect-Oriented Programming152 questions
- Transaction Management150 questions
- Spring MVC (Servlet Web)171 questions
- Spring WebFlux (Reactive Web)145 questions
- Spring Boot155 questions
- Spring Data156 questions
- Spring Security186 questions
- Spring Cloud144 questions
- Messaging & Integration141 questions
- Spring Batch148 questions
- Testing171 questions
- Observability & Actuator148 questions
- AOT & Native Image145 questions
- Wider Spring Portfolio144 questions
- Quarkusempty
- GraalVM Native Imageempty
- CDI & Extensionsempty
- Panache Data Accessempty
- Ktor29 questions
- Application Setup4 questions
- Routing5 questions
- Plugins and Pipeline4 questions
- Content Negotiation5 questions
- Authentication5 questions
- Ktor Client6 questions
- Javalinempty
- Play Frameworkempty
- Vert.xempty
- http4sempty
- Tapirempty
- Scalatraempty
- Akkaempty
- Akka Streamsempty
- Akka HTTPempty
- Pekkoempty
- Django (has its own guide)556 questions
- Projects & Settings30 questions
- URL Dispatcher19 questions
- Views & Responses24 questions
- Class-Based Views27 questions
- Server-Side Templates27 questions
- Form Processing27 questions
- Model Classes42 questions
- QuerySet API29 questions
- ORM Query Tuning22 questions
- Databases & Transactions26 questions
- Migration Workflows24 questions
- Admin Site27 questions
- Accounts & Sign-In26 questions
- Access Rights & Groups17 questions
- Middleware Components11 questions
- Sessions & Messages14 questions
- Built-In Protections22 questions
- Static & Media Files17 questions
- Cache Toolkit16 questions
- Async Support14 questions
- Signals, Tasks & Email21 questions
- Translation & Locales20 questions
- Logging & Debugging14 questions
- Test Toolkit26 questions
- Running in Production14 questions
- Django REST Framework (has its own guide)71 questions
- Serializers19 questions
- API Views & Routers13 questions
- Auth & Throttle Policies13 questions
- Listing & Wire Contract17 questions
- Tests & Schemas9 questions
- Django Ninja19 questions
- Routers & Operations4 questions
- Pydantic Schemas & Errors6 questions
- Auth & Throttling5 questions
- Async Operations & Docs4 questions
- FastAPIempty
- Dependency Injectionempty
- Async & Concurrencyempty
- OpenAPI & Middlewareempty
- Flaskempty
- Routing and Viewsempty
- Jinja2 Templatingempty
- Blueprintsempty
- Pyramidempty
- Sanicempty
- Tornadoempty
- aiohttpempty
- Express.jsempty
- Routingempty
- Middleware Pipelineempty
- Request & Responseempty
- Error Handlingempty
- REST API Patternsempty
- Fastifyempty
- NestJSempty
- Modules and DIempty
- Pipes and Validationempty
- Honoempty
- Itty Routerempty
- Laravel581 questions
- App Setup & Structure33 questions
- Service Container20 questions
- URL Mapping30 questions
- Endpoint Classes12 questions
- Middleware Layers21 questions
- Request Data & Replies37 questions
- Eloquent Models44 questions
- Database Layer28 questions
- Cache & Locks11 questions
- Blade Views22 questions
- Frontend Stack Choices16 questions
- Artisan & Dev Tools20 questions
- Validating Incoming Data21 questions
- Crypto & Forgery Defenses12 questions
- Accounts & Access Control47 questions
- Errors, Logs & Debugging31 questions
- Localization11 questions
- Queues & Jobs24 questions
- Task Scheduler12 questions
- Signals & Outbound Messages25 questions
- Storage Facade11 questions
- Automated App Checks27 questions
- Everyday Helpers27 questions
- Shipping & Running24 questions
- Official Add-Ons15 questions
- Symfonyempty
- Event Dispatcherempty
- Doctrine Integrationempty
- Security Componentempty
- Forms and Validationempty
- Yiiempty
- Livewire49 questions
- Components & Properties6 questions
- Callable Actions & Dispatch5 questions
- Data Binding & Forms5 questions
- Hydrate, Update & Render Hooks6 questions
- Lazy Loading & Navigation6 questions
- Uploaded Files in Components6 questions
- Payload Security6 questions
- Alpine Integration & JS Hooks5 questions
- Rendered State Assertions4 questions
- Ruby on Railsempty
- Active Record ORMempty
- Migrations & Schemaempty
- Views & Hotwireempty
- Sinatra6 questions
- Rack6 questions
- ASP.NET Coreempty
- Middleware Pipelineempty
- Minimal APIs and MVCempty
- Dependency Injectionempty
- Hosting and Kestrelempty
- .NET Aspireempty
- SignalR Coreempty
- Orleansempty
- YARPempty
- Ocelotempty
- Steeltoeempty
- ginempty
- Middlewareempty
- Response Renderingempty
- Testing Gin Appsempty
- echoempty
- fiberempty
- beegoempty
- Actixempty
- Axumempty
- Routingempty
- Extractorsempty
- Tower Middlewareempty
- State and Sharingempty
- Error Handlingempty
- Rocketempty
- Locoempty
- hyperempty
- Vaporempty
- Hummingbirdempty
- Venomempty
- Web Framework Concepts238 questions
- Request Lifecycle & Routing30 questions
- Middleware, Filters & Interceptors29 questions
- Handler Binding & Content Negotiation31 questions
- Dependency Injection & Configuration25 questions
- Boundary Serialization & Validation29 questions
- Error Handling & Problem Responses24 questions
- Sessions, Cookies & State22 questions
- Blocking, Async & Streaming24 questions
- Testing the HTTP Layer24 questions
→ has its own guide
questions
3,935 · 10 sectionsWhat is @After advice in Spring AOP and when does it run?
basics
~20 s@After is advice that runs after a matched method finishes — whether it returned normally or threw an exception. It behaves like a finally block, so it is used for cleanup. It cannot see the return value or the exception.
What does Spring's @AfterReturning advice do, and when does it run?
basics
~10 s@AfterReturning is AOP advice that runs after an advised method finishes successfully (returns normally). It does NOT run if the method throws an exception. It can read the returned value but cannot replace it.
What is @AfterThrowing advice in Spring AOP and when does it run?
basics
~10 s@AfterThrowing is an aspect advice method that runs only when the matched method (join point) exits by throwing an exception. If the method returns normally, it does not run.
What is @Around advice in Spring AOP, and why must it call ProceedingJoinPoint.proceed()?
basics
~20 s@Around wraps a method call. It runs code before and after the target method. You must call proceed() to actually run the target method; if you skip it, the target never executes and you return your own value instead.
What is @Before advice in Spring AOP and when does it run?
basics
~10 s@Before advice is aspect code that runs before a matched method (the join point) executes. It's used for things like logging entry or validating arguments. It runs before, then the real method still runs.
In Ktor, what is the difference between starting a server with embeddedServer and with EngineMain?
basics
~10 sembeddedServer starts Ktor from Kotlin code, with the engine, host and port passed as arguments. EngineMain is a prebuilt main function that boots the same server from an application.conf or application.yaml file instead.
In Ktor, how do you protect a route with the Authentication plugin and read the principal?
basics
~10 sInstall Authentication and configure a named provider, then wrap the routes in authenticate("name") { }. Inside a handler, call.principal<T>() returns whatever the provider's validate block produced; routes outside the block stay public.
In Ktor, how do you create an HttpClient and read the status and body of a GET response?
basics
~10 sConstruct an HttpClient with an engine, then call the suspend function client.get(url). It returns an HttpResponse: read the code from response.status and the payload from response.bodyAsText() or the typed response.body<T>().
In Ktor, why do call.receive<User>() and call.respond(user) fail unless ContentNegotiation is installed?
basics
~20 sKtor's pipelines natively handle only bytes, text and form data. ContentNegotiation registers converters that map a media type to a class, so without it no converter exists for User and both the receive and the respond transformation fail.
In Ktor, what does install() do, and at which scopes can a plugin be installed?
basics
~20 sKtor's install() adds a plugin to a pipeline and runs its configuration block once at startup. Plugins can be installed application-wide inside a module, or — when the plugin is route-scoped — on a single route so only that subtree is affected.
How do you register a model with Django's admin, and how do you choose the columns its change list shows?
basics
~10 sRegister a model in the app's admin.py with admin.site.register(Ticket, TicketAdmin) or the @admin.register(Ticket) decorator on a ModelAdmin subclass. The change list shows the columns named in ModelAdmin.list_display, defaulting to the object's str.
In Django, what do the is_staff and is_superuser user flags each control, and can a superuser without is_staff use the admin?
basics
~20 sis_staff lets an active user into the Django admin; is_superuser makes has_perm() return True for every permission. They are independent: a superuser with is_staff=False cannot log in to the admin, and a staff user with no permissions sees nothing to edit.
In Django's async ORM, which QuerySet calls need an a-prefixed version in an async view, and which can you chain as usual?
basics
~10 sQuerySet builders such as filter(), exclude() and order_by() run no SQL, so they stay unchanged. Calls that execute a query use awaited a-prefixed versions: aget(), afirst(), acount(), acreate(). Iterate with async for.
In Django, how do you write an async view, both as a function-based view and as a class-based view?
basics
~20 sDeclare a function-based view with async def. For a class-based view, declare its HTTP handlers such as get() and post() with async def, leaving as_view() alone; the handlers must be all async or all sync.
In Django's contrib.auth, what is the difference between authenticate() and login(), and why does a sign-in view call both?
basics
~20 sauthenticate() checks credentials against the configured backends and returns a user or None without changing any state. login() takes that user and records it in the session, so later requests arrive with request.user set. A sign-in view needs both steps.
In Django REST Framework, what do authentication classes do, and what do request.user and request.auth hold after TokenAuthentication succeeds?
basics
~20 sAuthentication classes identify the caller; permission classes decide access. DRF tries each class in order, and the first returning (user, auth) sets request.user and request.auth: for TokenAuthentication, the token's user and Token instance; otherwise AnonymousUser and None.
In Django REST Framework, which permission applies to a view when none is configured, and how do you require authentication across the whole API?
basics
~10 sDRF's default permission is AllowAny, so an unconfigured view accepts anonymous requests. Set DEFAULT_PERMISSION_CLASSES to IsAuthenticated in REST_FRAMEWORK; a view's own permission_classes then replaces that list rather than adding to it.
In Django REST Framework, how do you switch on AnonRateThrottle and UserRateThrottle, and what does a throttled client receive back?
basics
~20 sDRF throttles nothing by default: list the classes in DEFAULT_THROTTLE_CLASSES and give 'anon' and 'user' rates like '100/day' in DEFAULT_THROTTLE_RATES. A throttled request gets 429 with a Retry-After header and a 'Request was throttled.' detail.
In Django REST Framework, what happens when a view raises NotFound, PermissionDenied or Throttled, and what body does the default exception handler return?
basics
~20 sDRF catches APIException subclasses raised in a view and returns a Response with the class's status_code and a body of {"detail": message}. Django's Http404 and PermissionDenied are mapped to 404 and 403; other exceptions propagate as a 500.
In Django REST Framework, how do filter_backends let clients filter, search and order a list endpoint such as GET /jobs/?
basics
~10 sA DRF generic view passes its queryset through each class in filter_backends: DjangoFilterBackend (django-filter) handles field filters like ?remote=true, SearchFilter handles ?search= over search_fields, and OrderingFilter handles ?ordering= limited to ordering_fields.
In Django Ninja, how do you protect a partner operation with an APIKeyHeader authenticator, and what does request.auth hold afterwards?
basics
~10 sSubclass ninja.security.APIKeyHeader, set param_name to the header, and implement authenticate(request, key) returning the partner or None; pass an instance as auth=. Ninja stores the truthy return value in request.auth, or answers 401.
In Django Ninja, how do NinjaAPI, Router and add_router() fit together, and how is the API mounted in urls.py?
basics
~10 sNinjaAPI is the API; each app defines a Router whose decorated functions are operations; api.add_router(prefix, router) mounts each router; and urls.py includes everything once with path('api/', api.urls), which also serves /docs and /openapi.json.
In Django Ninja, when a posted JSON body fails the operation's Schema, where does the 422 come from and what does it contain?
basics
~10 sDjango Ninja validates every declared parameter before calling the view, collects the failures into ninja.errors.ValidationError, and NinjaAPI's default handler for that exception returns 422 with a detail list of type, loc and msg entries.
In Django Ninja, with auth= set on the NinjaAPI, a Router and an operation, which applies, and how is one operation made public?
basics
~10 sThe most specific auth= replaces the others: operation, then the add_router() mount, then Router(auth=), then a parent router, then NinjaAPI(auth=). Settings are never merged. auth=None on an operation or router makes it public.
In Django Ninja, how does an operation decide whether a parameter comes from the path, the query string or the request body?
basics
~20 sDjango Ninja applies rules in order: an explicit Query/Path/Body/Form/File/Header/Cookie marker wins; a name in the path is a path parameter; a list, set, tuple or Schema is body; any other scalar is a query parameter.
In Laravel, what is the difference between a gate defined with Gate::define and a policy class, and when would you choose each?
basics
~20 sA gate is a named closure registered with Gate::define for one-off checks not tied to a model. A policy is a class grouping one model's abilities (view, update, delete), found from the model you pass; most model rules belong there.
In Laravel's config/auth.php, what is the difference between a guard and a user provider, and what ships by default?
basics
~20 sA guard decides how a request is authenticated and remembered; a user provider decides where user records are loaded from. The Laravel 13 skeleton ships one web guard (session driver) pointing at one users provider (eloquent, App\Models\User).
In Laravel, how does a hand-built login use Auth::attempt, and why does the documented example call $request->session()->regenerate() afterwards?
basics
~20 sAuth::attempt($credentials) finds the user by the non-password keys, checks the password hash and, on success, signs them into the session, returning true or false. Regenerating the session ID defeats session fixation; Laravel 13's guard already does it in login().
In Laravel, what must be in place for the verified middleware to keep users with unconfirmed email addresses out of a route?
basics
~10 sApp\Models\User must implement Illuminate\Contracts\Auth\MustVerifyEmail, users needs an email_verified_at column, sign-up must dispatch Registered, the verification.notice, verification.verify and verification.send routes must exist, and routes use ['auth', 'verified'].
What two authentication mechanisms does Laravel Sanctum provide, and which one suits a first-party SPA versus a mobile app?
basics
~20 sSanctum offers cookie-based session authentication for a first-party SPA on a stateful domain, and database-backed personal access tokens sent as a Bearer header for mobile apps and scripts. Your own SPA uses the session; the mobile app uses a token.
In Livewire, how do wire:click and wire:submit call component methods, and how are arguments passed to those methods?
basics
~20 swire:click="addItem(42)" and wire:submit="checkout" send a request that calls that public method on the Livewire component. Arguments are JavaScript expressions sent as JSON; type-hinted models are resolved from ids and container services are injected. wire:submit prevents the browser submit itself.
In a Livewire component's Alpine code, how do $wire reads, writes and method calls differ in when they reach the server?
basics
~20 sReading $wire.guests and assigning $wire.guests = 3 stay in the browser; the assignment rides along with the next Livewire request. $wire.$set() sends a request by default, and calling $wire.checkAvailability() always does, resolving with the PHP return value.
In Livewire, when does an input bound with wire:model send its value to the server, and what does the .live modifier change?
basics
~20 sBy default wire:model is deferred: typing updates only client-side state, and the value reaches the server with the next action's request, such as a wire:submit. wire:model.live sends an update as the value changes, debounced 150 ms on text inputs.
In Livewire, how do you pass data from a Blade view into a nested component, and when does that component's mount() method run?
basics
~20 sPass props as attributes on <livewire:name /> (a colon prefix evaluates PHP) or in @livewire's array. mount() receives them by parameter name, or matching public properties are filled. mount() runs once, at creation, never on later requests.
In a Livewire component, how do you run code whenever a user changes one public property, such as recomputing an order total?
basics
~20 sDefine an updatedQuantity() method on the component: Livewire calls it after it writes a new quantity sent from the browser, so it can recompute the total. updatingQuantity() runs before the write; generic updating() and updated() receive the property name.
In Sinatra, how is a request matched to a route such as get '/payments/:id', and how do you read path, splat and query parameters?
basics
~20 sSinatra tries the routes for the request's verb in definition order and runs the first match. Named segments, splats, regexp captures, query and form fields all land in params as strings, readable by string or symbol key.
In a Sinatra payment-webhook receiver, how would you use a before filter and a helper to reject requests whose signature fails to verify?
basics
~10 sDefine a helper that computes an HMAC of the raw body and calls halt 401 on a mismatch, then call it from before '/webhooks/*'. The halt skips the route, while after filters still run.
In Sinatra, what does erb :receipt render, and how do the layout, locals and instance variables reach that template?
basics
~10 serb :receipt renders views/receipt.erb, wrapped in views/layout.erb when that file exists. The template runs with the request's app instance as self, so it sees instance variables and helpers; the locals option adds local variables.
In a Sinatra route block, what is the difference between halt, pass and redirect, and what response does each one produce?
basics
~20 shalt stops the request at once and sends the status, headers and body you give it. pass abandons the current route so the next matching route answers, or a 404. redirect sets Location and a 302 or 303, then halts.
In Sinatra 4, how does a classic top-level app differ from a Sinatra::Base subclass in its defaults and startup, and how is each one run?
basics
~20 srequire 'sinatra' sends top-level DSL calls to Sinatra::Application and starts a server at exit when the file runs directly. A Sinatra::Base subclass is a plain Rack app with logging, method override and auto-start off, started by run! or a Rack server.
In Ruby, what is a Rack application, and what exactly must its call(env) method receive and return?
basics
~20 sA Rack application is any Ruby object that responds to call(env). It receives the request as an env Hash and returns a non-frozen three-element Array: an Integer status, a Hash of lower-case headers, and a body that responds to each or call.
In a Rack app, how would you write a middleware that measures each request's duration and adds it as a response header?
basics
~20 sA Rack middleware is a class whose initialize takes the inner app and whose call(env) reads a monotonic clock, calls @app.call(env), writes the elapsed time into the returned headers under a lower-case name, and returns the triple; config.ru adds it with use.
In a Rack config.ru, what do use, run and map do, and in which order does a request pass through the middleware?
basics
~20 sconfig.ru is Ruby evaluated inside a Rack::Builder: use adds a middleware, run sets the innermost app, and map mounts a sub-app under a path prefix. The first use line is the outermost layer, so it sees the request first and the response last.
In a Rack app, what do Rack::Request and Rack::Response give you over the raw env Hash and the response Array?
basics
~20 sRack::Request wraps the env Hash with readers such as params, path_info, get?, cookies and ip, caching parsed values in env. Rack::Response collects status, headers and body with helpers such as write, set_cookie and redirect, and finish returns the SPEC triple.
A Rack 2 middleware breaks after upgrading to Rack 3; what did the Rack 3 SPEC change about status, headers and the response Array?
basics
~20 sRack 3 requires an Integer status of at least 100, a mutable Hash of headers with lower-case names and Array values for repeated headers, and a non-frozen response Array; rackup, Rack::Server and Rack::Session also moved into separate gems.
In a server-side web framework, how does a JSON request body differ from a form-encoded one, and what tells the framework which arrived?
basics
~20 sThe Content-Type request header names the format, and the framework picks a body parser from it. A JSON body is one nested, typed value; a form-encoded body is a flat, percent-encoded list of string key/value pairs.
How does a server-side web framework turn a multipart/form-data request body into the parts a handler works with?
basics
~20 sA multipart/form-data body is a run of boundary-delimited parts, each with its own headers naming the form field and, for files, a filename. The framework walks them in arrival order as field values or file handles.
In a server-side web framework, which parts of an HTTP request can a handler parameter be bound from?
basics
~20 sHandler parameters bind from captured path segments, the query string, headers, cookies, form fields, or the parsed body. The framework picks the source from an explicit marker on the parameter, or infers it from the parameter's name and type.
In a server-side web framework, how does an object returned from a handler become a response body and a status code?
basics
~20 sThe returned value models the body, not the whole response. The framework picks a writer for the negotiated media type, serializes the value, synthesises Content-Type and framing, then applies a default success status, conventionally 200.
In a web framework, how does a text value from a URL become a typed handler argument such as a number or enum?
basics
~20 sA URL carries only text. The binder finds a converter for the parameter's declared type, runs it on the raw string, and passes the result in. A failed conversion ends the request as a client error before the handler runs.