Methods and Status Codes
Which verb an operation deserves, what safe and idempotent actually promise, and what each status class asserts. Interviewers probe it to see whether you know the spec or only framework defaults.
part ofHTTPoverview, primer and where to startread it →on this pageshowhide
explore
- Safety and Idempotency5 questions
- Verb-by-Verb Semantics4 questions
- Introspection and Tunneling Verbs4 questions
- Response Classes4 questions
- Redirect Semantics5 questions
- Client Errors6 questions
- Server Errors5 questions
- API Testingskillanchors this topic
- AI Engineerrole
- AI Red Teamingrole
- API Designskill
- Backend Developerrole
- Computer Scienceskill
- Cyber Security Expertrole
- Data Engineerrole
- DevOps / SRE Engineerrole
- DevSecOps Engineerrole
- Frontend Developerrole
- Full Stack Developerrole
- GraphQLskill
- Java Backend Developerrole
- Java SDETrole
- Kotlin Backend Developerrole
- MLOps Engineerrole
- Network Engineerrole
- QA Engineerrole
- Software Architectrole
- iOS Developerrole
questions
page 2 of 2What does the HTTP specification say about sending a request body with a GET, and what should you do instead when query criteria are too large for a URL?
basics
~20 sRFC 9110 says content on a GET has no defined semantics, so servers may ignore or reject it and intermediaries may strip it — GET bodies are unreliable. For large criteria use POST with a body, or a two-step POST-then-GET so results stay cacheable.
The HTTP TRACE method makes a server echo the received request back to the client. What is it meant to be used for, and why do most production servers and proxies disable it?
basics
~20 sTRACE is a loop-back diagnostic: the final server echoes the request it received back as the response body, revealing how proxies rewrote it. It is disabled because the echo reflects cookies, Authorization headers, and internal proxy headers back to the caller — information disclosure, historically exploited as Cross-Site Tracing.
An HTTP/1.1 response starts with a line like 'HTTP/1.1 404 Not Found'. What happened to that trailing reason phrase in HTTP/2 and HTTP/3, and what breaks in software that depends on it?
basics
~20 sHTTP/2 and HTTP/3 dropped reason phrases entirely: a response carries only the three-digit :status pseudo-header. Anything that read, logged, asserted on, or smuggled information through the phrase gets nothing — clients synthesize a phrase from a lookup table or leave it empty.
showing 31–33 of 33