skip to content

Web Frameworks

The server-side frameworks that turn an HTTP request into application code — Spring and Quarkus on the JVM, Django and FastAPI in Python, Express and NestJS in Node, plus Laravel, Rails, ASP.NET Core, Gin, Axum and more. Interviewers use whichever framework you claim to probe how much of the request lifecycle you actually understand versus how much you let the framework hide.

on this pageshow

explore

→ has its own guide

questions

3,935 · 10 sections

What is @After advice in Spring AOP and when does it run?

level: juniorimportance: must knowfreq 58%
basics
~20 s

@After is advice that runs after a matched method finishes — whether it returned normally or threw an exception. It behaves like a finally block, so it is used for cleanup. It cannot see the return value or the exception.

open as a page

What does Spring's @AfterReturning advice do, and when does it run?

level: juniorimportance: must knowfreq 60%
basics
~10 s

@AfterReturning is AOP advice that runs after an advised method finishes successfully (returns normally). It does NOT run if the method throws an exception. It can read the returned value but cannot replace it.

open as a page

What is @AfterThrowing advice in Spring AOP and when does it run?

level: juniorimportance: must knowfreq 65%
basics
~10 s

@AfterThrowing is an aspect advice method that runs only when the matched method (join point) exits by throwing an exception. If the method returns normally, it does not run.

open as a page

What is @Around advice in Spring AOP, and why must it call ProceedingJoinPoint.proceed()?

level: juniorimportance: must knowfreq 78%
basics
~20 s

@Around wraps a method call. It runs code before and after the target method. You must call proceed() to actually run the target method; if you skip it, the target never executes and you return your own value instead.

open as a page

What is @Before advice in Spring AOP and when does it run?

level: juniorimportance: must knowfreq 70%
basics
~10 s

@Before advice is aspect code that runs before a matched method (the join point) executes. It's used for things like logging entry or validating arguments. It runs before, then the real method still runs.

open as a page

In Ktor, what is the difference between starting a server with embeddedServer and with EngineMain?

level: juniorimportance: must knowfreq 80%
basics
~10 s

embeddedServer starts Ktor from Kotlin code, with the engine, host and port passed as arguments. EngineMain is a prebuilt main function that boots the same server from an application.conf or application.yaml file instead.

open as a page

In Ktor, how do you protect a route with the Authentication plugin and read the principal?

level: juniorimportance: must knowfreq 76%
basics
~10 s

Install Authentication and configure a named provider, then wrap the routes in authenticate("name") { }. Inside a handler, call.principal<T>() returns whatever the provider's validate block produced; routes outside the block stay public.

open as a page

In Ktor, how do you create an HttpClient and read the status and body of a GET response?

level: juniorimportance: must knowfreq 78%
basics
~10 s

Construct an HttpClient with an engine, then call the suspend function client.get(url). It returns an HttpResponse: read the code from response.status and the payload from response.bodyAsText() or the typed response.body<T>().

open as a page

In Ktor, why do call.receive<User>() and call.respond(user) fail unless ContentNegotiation is installed?

level: juniorimportance: must knowfreq 78%
basics
~20 s

Ktor's pipelines natively handle only bytes, text and form data. ContentNegotiation registers converters that map a media type to a class, so without it no converter exists for User and both the receive and the respond transformation fail.

open as a page

In Ktor, what does install() do, and at which scopes can a plugin be installed?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Ktor's install() adds a plugin to a pipeline and runs its configuration block once at startup. Plugins can be installed application-wide inside a module, or — when the plugin is route-scoped — on a single route so only that subtree is affected.

open as a page

How do you register a model with Django's admin, and how do you choose the columns its change list shows?

level: juniorimportance: must knowfreq 62%
basics
~10 s

Register a model in the app's admin.py with admin.site.register(Ticket, TicketAdmin) or the @admin.register(Ticket) decorator on a ModelAdmin subclass. The change list shows the columns named in ModelAdmin.list_display, defaulting to the object's str.

open as a page

In Django, what do the is_staff and is_superuser user flags each control, and can a superuser without is_staff use the admin?

level: juniorimportance: must knowfreq 62%
basics
~20 s

is_staff lets an active user into the Django admin; is_superuser makes has_perm() return True for every permission. They are independent: a superuser with is_staff=False cannot log in to the admin, and a staff user with no permissions sees nothing to edit.

open as a page

In Django's async ORM, which QuerySet calls need an a-prefixed version in an async view, and which can you chain as usual?

level: juniorimportance: must knowfreq 52%
basics
~10 s

QuerySet builders such as filter(), exclude() and order_by() run no SQL, so they stay unchanged. Calls that execute a query use awaited a-prefixed versions: aget(), afirst(), acount(), acreate(). Iterate with async for.

open as a page

In Django, how do you write an async view, both as a function-based view and as a class-based view?

level: juniorimportance: must knowfreq 58%
basics
~20 s

Declare a function-based view with async def. For a class-based view, declare its HTTP handlers such as get() and post() with async def, leaving as_view() alone; the handlers must be all async or all sync.

open as a page

In Django's contrib.auth, what is the difference between authenticate() and login(), and why does a sign-in view call both?

level: juniorimportance: must knowfreq 76%
basics
~20 s

authenticate() checks credentials against the configured backends and returns a user or None without changing any state. login() takes that user and records it in the session, so later requests arrive with request.user set. A sign-in view needs both steps.

open as a page

In Django REST Framework, what do authentication classes do, and what do request.user and request.auth hold after TokenAuthentication succeeds?

level: juniorimportance: must knowfreq 66%
basics
~20 s

Authentication classes identify the caller; permission classes decide access. DRF tries each class in order, and the first returning (user, auth) sets request.user and request.auth: for TokenAuthentication, the token's user and Token instance; otherwise AnonymousUser and None.

open as a page

In Django REST Framework, which permission applies to a view when none is configured, and how do you require authentication across the whole API?

level: juniorimportance: must knowfreq 68%
basics
~10 s

DRF's default permission is AllowAny, so an unconfigured view accepts anonymous requests. Set DEFAULT_PERMISSION_CLASSES to IsAuthenticated in REST_FRAMEWORK; a view's own permission_classes then replaces that list rather than adding to it.

open as a page

In Django REST Framework, how do you switch on AnonRateThrottle and UserRateThrottle, and what does a throttled client receive back?

level: juniorimportance: must knowfreq 55%
basics
~20 s

DRF throttles nothing by default: list the classes in DEFAULT_THROTTLE_CLASSES and give 'anon' and 'user' rates like '100/day' in DEFAULT_THROTTLE_RATES. A throttled request gets 429 with a Retry-After header and a 'Request was throttled.' detail.

open as a page

In Django REST Framework, what happens when a view raises NotFound, PermissionDenied or Throttled, and what body does the default exception handler return?

level: juniorimportance: must knowfreq 60%
basics
~20 s

DRF catches APIException subclasses raised in a view and returns a Response with the class's status_code and a body of {"detail": message}. Django's Http404 and PermissionDenied are mapped to 404 and 403; other exceptions propagate as a 500.

open as a page

In Django REST Framework, how do filter_backends let clients filter, search and order a list endpoint such as GET /jobs/?

level: juniorimportance: must knowfreq 62%
basics
~10 s

A DRF generic view passes its queryset through each class in filter_backends: DjangoFilterBackend (django-filter) handles field filters like ?remote=true, SearchFilter handles ?search= over search_fields, and OrderingFilter handles ?ordering= limited to ordering_fields.

open as a page

In Django Ninja, how do you protect a partner operation with an APIKeyHeader authenticator, and what does request.auth hold afterwards?

level: juniorimportance: must knowfreq 50%
basics
~10 s

Subclass ninja.security.APIKeyHeader, set param_name to the header, and implement authenticate(request, key) returning the partner or None; pass an instance as auth=. Ninja stores the truthy return value in request.auth, or answers 401.

open as a page

In Django Ninja, how do NinjaAPI, Router and add_router() fit together, and how is the API mounted in urls.py?

level: juniorimportance: must knowfreq 58%
basics
~10 s

NinjaAPI is the API; each app defines a Router whose decorated functions are operations; api.add_router(prefix, router) mounts each router; and urls.py includes everything once with path('api/', api.urls), which also serves /docs and /openapi.json.

open as a page

In Django Ninja, when a posted JSON body fails the operation's Schema, where does the 422 come from and what does it contain?

level: juniorimportance: must knowfreq 55%
basics
~10 s

Django Ninja validates every declared parameter before calling the view, collects the failures into ninja.errors.ValidationError, and NinjaAPI's default handler for that exception returns 422 with a detail list of type, loc and msg entries.

open as a page

In Django Ninja, with auth= set on the NinjaAPI, a Router and an operation, which applies, and how is one operation made public?

level: middleimportance: must knowfreq 45%
basics
~10 s

The most specific auth= replaces the others: operation, then the add_router() mount, then Router(auth=), then a parent router, then NinjaAPI(auth=). Settings are never merged. auth=None on an operation or router makes it public.

open as a page

In Django Ninja, how does an operation decide whether a parameter comes from the path, the query string or the request body?

level: middleimportance: must knowfreq 62%
basics
~20 s

Django Ninja applies rules in order: an explicit Query/Path/Body/Form/File/Header/Cookie marker wins; a name in the path is a path parameter; a list, set, tuple or Schema is body; any other scalar is a query parameter.

open as a page

In Laravel, what is the difference between a gate defined with Gate::define and a policy class, and when would you choose each?

level: juniorimportance: must knowfreq 72%
basics
~20 s

A gate is a named closure registered with Gate::define for one-off checks not tied to a model. A policy is a class grouping one model's abilities (view, update, delete), found from the model you pass; most model rules belong there.

open as a page

In Laravel's config/auth.php, what is the difference between a guard and a user provider, and what ships by default?

level: juniorimportance: must knowfreq 55%
basics
~20 s

A guard decides how a request is authenticated and remembered; a user provider decides where user records are loaded from. The Laravel 13 skeleton ships one web guard (session driver) pointing at one users provider (eloquent, App\Models\User).

open as a page

In Laravel, how does a hand-built login use Auth::attempt, and why does the documented example call $request->session()->regenerate() afterwards?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Auth::attempt($credentials) finds the user by the non-password keys, checks the password hash and, on success, signs them into the session, returning true or false. Regenerating the session ID defeats session fixation; Laravel 13's guard already does it in login().

open as a page

In Laravel, what must be in place for the verified middleware to keep users with unconfirmed email addresses out of a route?

level: juniorimportance: must knowfreq 50%
basics
~10 s

App\Models\User must implement Illuminate\Contracts\Auth\MustVerifyEmail, users needs an email_verified_at column, sign-up must dispatch Registered, the verification.notice, verification.verify and verification.send routes must exist, and routes use ['auth', 'verified'].

open as a page

What two authentication mechanisms does Laravel Sanctum provide, and which one suits a first-party SPA versus a mobile app?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Sanctum offers cookie-based session authentication for a first-party SPA on a stateful domain, and database-backed personal access tokens sent as a Bearer header for mobile apps and scripts. Your own SPA uses the session; the mobile app uses a token.

open as a page

In Livewire, how do wire:click and wire:submit call component methods, and how are arguments passed to those methods?

level: juniorimportance: must knowfreq 65%
basics
~20 s

wire:click="addItem(42)" and wire:submit="checkout" send a request that calls that public method on the Livewire component. Arguments are JavaScript expressions sent as JSON; type-hinted models are resolved from ids and container services are injected. wire:submit prevents the browser submit itself.

open as a page

In a Livewire component's Alpine code, how do $wire reads, writes and method calls differ in when they reach the server?

level: juniorimportance: must knowfreq 50%
basics
~20 s

Reading $wire.guests and assigning $wire.guests = 3 stay in the browser; the assignment rides along with the next Livewire request. $wire.$set() sends a request by default, and calling $wire.checkAvailability() always does, resolving with the PHP return value.

open as a page

In Livewire, when does an input bound with wire:model send its value to the server, and what does the .live modifier change?

level: juniorimportance: must knowfreq 70%
basics
~20 s

By default wire:model is deferred: typing updates only client-side state, and the value reaches the server with the next action's request, such as a wire:submit. wire:model.live sends an update as the value changes, debounced 150 ms on text inputs.

open as a page

In Livewire, how do you pass data from a Blade view into a nested component, and when does that component's mount() method run?

level: juniorimportance: must knowfreq 60%
basics
~20 s

Pass props as attributes on <livewire:name /> (a colon prefix evaluates PHP) or in @livewire's array. mount() receives them by parameter name, or matching public properties are filled. mount() runs once, at creation, never on later requests.

open as a page

In a Livewire component, how do you run code whenever a user changes one public property, such as recomputing an order total?

level: juniorimportance: must knowfreq 58%
basics
~20 s

Define an updatedQuantity() method on the component: Livewire calls it after it writes a new quantity sent from the browser, so it can recompute the total. updatingQuantity() runs before the write; generic updating() and updated() receive the property name.

open as a page

In Sinatra, how is a request matched to a route such as get '/payments/:id', and how do you read path, splat and query parameters?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Sinatra tries the routes for the request's verb in definition order and runs the first match. Named segments, splats, regexp captures, query and form fields all land in params as strings, readable by string or symbol key.

open as a page

In a Sinatra payment-webhook receiver, how would you use a before filter and a helper to reject requests whose signature fails to verify?

level: middleimportance: must knowfreq 57%
basics
~10 s

Define a helper that computes an HMAC of the raw body and calls halt 401 on a mismatch, then call it from before '/webhooks/*'. The halt skips the route, while after filters still run.

open as a page

In Sinatra, what does erb :receipt render, and how do the layout, locals and instance variables reach that template?

level: juniorimportance: should knowfreq 42%
basics
~10 s

erb :receipt renders views/receipt.erb, wrapped in views/layout.erb when that file exists. The template runs with the request's app instance as self, so it sees instance variables and helpers; the locals option adds local variables.

open as a page

In a Sinatra route block, what is the difference between halt, pass and redirect, and what response does each one produce?

level: middleimportance: should knowfreq 50%
basics
~20 s

halt stops the request at once and sends the status, headers and body you give it. pass abandons the current route so the next matching route answers, or a 404. redirect sets Location and a 302 or 303, then halts.

open as a page

In Sinatra 4, how does a classic top-level app differ from a Sinatra::Base subclass in its defaults and startup, and how is each one run?

level: seniorimportance: should knowfreq 45%
basics
~20 s

require 'sinatra' sends top-level DSL calls to Sinatra::Application and starts a server at exit when the file runs directly. A Sinatra::Base subclass is a plain Rack app with logging, method override and auto-start off, started by run! or a Rack server.

open as a page

In Ruby, what is a Rack application, and what exactly must its call(env) method receive and return?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A Rack application is any Ruby object that responds to call(env). It receives the request as an env Hash and returns a non-frozen three-element Array: an Integer status, a Hash of lower-case headers, and a body that responds to each or call.

open as a page

In a Rack app, how would you write a middleware that measures each request's duration and adds it as a response header?

level: middleimportance: must knowfreq 58%
basics
~20 s

A Rack middleware is a class whose initialize takes the inner app and whose call(env) reads a monotonic clock, calls @app.call(env), writes the elapsed time into the returned headers under a lower-case name, and returns the triple; config.ru adds it with use.

open as a page

In a Rack config.ru, what do use, run and map do, and in which order does a request pass through the middleware?

level: middleimportance: should knowfreq 46%
basics
~20 s

config.ru is Ruby evaluated inside a Rack::Builder: use adds a middleware, run sets the innermost app, and map mounts a sub-app under a path prefix. The first use line is the outermost layer, so it sees the request first and the response last.

open as a page

In a Rack app, what do Rack::Request and Rack::Response give you over the raw env Hash and the response Array?

level: middleimportance: should knowfreq 40%
basics
~20 s

Rack::Request wraps the env Hash with readers such as params, path_info, get?, cookies and ip, caching parsed values in env. Rack::Response collects status, headers and body with helpers such as write, set_cookie and redirect, and finish returns the SPEC triple.

open as a page

A Rack 2 middleware breaks after upgrading to Rack 3; what did the Rack 3 SPEC change about status, headers and the response Array?

level: seniorimportance: should knowfreq 34%
basics
~20 s

Rack 3 requires an Integer status of at least 100, a mutable Hash of headers with lower-case names and Array values for repeated headers, and a non-frozen response Array; rackup, Rack::Server and Rack::Session also moved into separate gems.

open as a page

In a server-side web framework, how does a JSON request body differ from a form-encoded one, and what tells the framework which arrived?

level: juniorimportance: must knowfreq 62%
basics
~20 s

The Content-Type request header names the format, and the framework picks a body parser from it. A JSON body is one nested, typed value; a form-encoded body is a flat, percent-encoded list of string key/value pairs.

open as a page

How does a server-side web framework turn a multipart/form-data request body into the parts a handler works with?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A multipart/form-data body is a run of boundary-delimited parts, each with its own headers naming the form field and, for files, a filename. The framework walks them in arrival order as field values or file handles.

open as a page

In a server-side web framework, which parts of an HTTP request can a handler parameter be bound from?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Handler parameters bind from captured path segments, the query string, headers, cookies, form fields, or the parsed body. The framework picks the source from an explicit marker on the parameter, or infers it from the parameter's name and type.

open as a page

In a server-side web framework, how does an object returned from a handler become a response body and a status code?

level: juniorimportance: must knowfreq 68%
basics
~20 s

The returned value models the body, not the whole response. The framework picks a writer for the negotiated media type, serializes the value, synthesises Content-Type and framing, then applies a default success status, conventionally 200.

open as a page

In a web framework, how does a text value from a URL become a typed handler argument such as a number or enum?

level: juniorimportance: must knowfreq 72%
basics
~20 s

A URL carries only text. The binder finds a converter for the parameter's declared type, runs it on the raw string, and passes the result in. A failed conversion ends the request as a client error before the handler runs.

open as a page