skip to content

Sessions, Cookies & State

What a framework keeps or resolves per user or request beyond the handler's arguments: session, signed cookies, request context, cache validators, locale. Asked as what survives between requests.

on this pageshow

explore

questions

22

In a server-side web framework, how is a request's locale resolved, and what happens when no source supplies one?

level: juniorimportance: must knowfreq 66%

basics

~20 s

A locale resolver runs early in each request and takes the first source that yields a supported locale: a URL marker, a stored preference in a cookie or session, the client's language header, then a configured default.

open as a page

In a server-side web framework, what is the per-request attribute bag, and how do values set by a hook reach the handler?

level: juniorimportance: must knowfreq 68%

basics

~20 s

A per-request attribute bag is a mutable key/value map the framework creates when a request arrives and discards when it completes. Earlier stages write entries into it; the handler and later stages read them, so derived values travel without extra parameters.

open as a page

What is flash scope in a web framework, and how does it differ from a plain session attribute?

level: juniorimportance: must knowfreq 60%

basics

~20 s

Flash scope holds a value written on one request and exposed to the next, after which the framework discards it without any delete call. A plain session attribute stays until code removes it, so it would reappear on later pages.

open as a page

Why does a web service render timestamps in the server's own time zone, and how is a per-request zone resolved?

level: middleimportance: must knowfreq 70%

basics

~20 s

Because the request carries no time zone. The language header conveys language and region, not a zone, so formatting falls back to the process default - whatever the host is configured to. A per-request zone must be supplied explicitly.

open as a page

In a web framework, how can a service deep in the call chain read request-scoped values without receiving them as parameters?

level: middleimportance: must knowfreq 60%

basics

~20 s

Through ambient context: the framework binds the values to the current unit of execution, and code inside that unit reads them without a parameter. The usual carriers are per-thread storage, runtime-carried task context, and a resolving accessor.

open as a page

In a web framework, how does an ETag produced by hashing the rendered body differ from one derived from a resource version?

level: middleimportance: must knowfreq 58%

basics

~20 s

A body-hash ETag is computed after the response is rendered, so it saves bytes but none of the work behind them. A validator derived from resource version can be read before rendering, letting the handler stop early.

open as a page

In a web framework, when is a session object actually created, and why does lazy creation matter?

level: middleimportance: must knowfreq 70%

basics

~20 s

Most frameworks create a session lazily: the identifier, the store entry and the identifier cookie appear only once a handler uses the session, typically on its first write. Eager creation instead gives every anonymous visitor an entry and a cookie.

open as a page

A framework's in-process response cache is keyed by request path, and users start seeing each other's personalized pages - why?

level: seniorimportance: must knowfreq 54%

basics

~20 s

The key omits everything the body varies on. Keyed by path alone, the first caller's rendered page is stored and replayed to everyone asking for that path. Fix the key, or refuse to cache identity-dependent responses.

open as a page

In a web framework, what does a route-level cache-control helper actually do to a response, and what does it not do?

level: juniorimportance: should knowfreq 52%

basics

~20 s

A route-level cache-control helper writes response headers: a freshness window, a shared-or-private marker, sometimes a validator. It keeps no copy and skips no work - the handler still runs and the body is still built on every request.

open as a page

How does a framework resolve a message key against locale-specific bundles, and how do runtime values enter the message?

level: middleimportance: should knowfreq 58%

basics

~20 s

Lookup narrows per key: the bundle for the full language-and-region locale, then the language-only bundle, then the default bundle. Runtime values are inserted through numbered or named placeholders and formatted in the same resolved locale.

open as a page

How does a framework decide whether to save the session back to its store after a request?

level: middleimportance: should knowfreq 52%

basics

~20 s

The framework tracks whether the request changed the session. Storing, removing or clearing an attribute marks it dirty, and a dirty session is written back through the store's save operation; an untouched one usually is not written at all.

open as a page

For an appointment scheduled months ahead, why is storing a UTC instant plus a fixed offset not enough?

level: seniorimportance: should knowfreq 52%

basics

~20 s

An offset is a snapshot of one moment's rule. Zone offsets change at daylight-saving transitions and when governments rewrite the rules, so a future commitment must store the local date-time plus the zone identifier, converted to an instant at use.

open as a page

A handler reads a caller id from request context fine, but the same read returns nothing while a streamed response body is produced or in an after-response callback. Why?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Request-scoped context is valid only inside the request's window, on the execution unit it was bound to. Chunk producers and completion callbacks run outside that window, so the binding is absent or recycled. Capture values while the handler still holds them.

open as a page

What goes wrong when independently written components share a request attribute bag keyed by plain strings, and how do you make it safe?

level: seniorimportance: should knowfreq 42%

basics

~20 s

One untyped namespace shared by every stage invites silent overwrites, wrong-type reads far from the write, and readers that run before their writer. Give each key one owner, a typed or namespaced name, an accessor, and a stated absence contract.

open as a page

A one-time flash message sometimes never appears and sometimes shows on the wrong page. How do you diagnose it?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Both symptoms mean a request other than the intended page consumed the entry. Log every flash write, read and sweep with a request identifier, then find which request landed between the write and the page.

open as a page

How would you order locale sources - URL marker, stored preference, language header - for a product with public pages and signed-in users?

level: principalimportance: should knowfreq 44%

basics

~20 s

Order by how explicit and how durable each signal is: an in-URL locale for public linkable pages, a signed-in user's stored preference for application surfaces, the client's language header only to seed a first visit, and the configured default last.

open as a page

How would you decide which responses may enter a framework's in-process response cache, and how would you bound their staleness when several instances run?

level: principalimportance: should knowfreq 38%

basics

~20 s

Admit only responses no per-caller input touched, that are expensive to produce and tolerant of being out of date. Since each instance holds its own copy with no cross-process purge, bound staleness with a short lifetime or version-stamped keys.

open as a page

How do you decide what belongs in session attributes rather than being re-derived on each request?

level: principalimportance: should knowfreq 38%

basics

~20 s

Store only what cannot be re-derived and must survive between requests: small, stable, self-contained values. Everything derivable is cheaper to re-fetch, because each attribute costs serialization on every save and couples two deployed versions to one shape.

open as a page