KNOWLEDGE / 06
Web, HTTP and networking
How browsers, protocols, and network layers affect system behaviour and testability.
Questions and practice
Open a question to see the answer, examples, and exercises.
How does 401 differ from 403?Junior
Answer
401 means suitable authentication credentials are missing; 403 means the server understood the request but refuses access.
Examples
- A request without a token gets 401, while an authenticated user lacking the required role gets 403.
Practice exercises
- Design negative API checks for missing, invalid, and insufficiently privileged tokens.
What are HTTP requests and responses made of?Junior
Answer
A request contains a method, target, headers, and optionally a body. A response returns a status code, headers, and a body. Semantics matter more than syntax: identical JSON can mean different things depending on the method, content type, cache directives, and resource state.
Examples
- POST /orders with a JSON body creates a resource, while a 201 response includes the new order’s Location.
Practice exercises
- Inspect one request and response in DevTools: method, URL, headers, body, status, and cache policy.
What happens on the network before the first HTTPS response?Junior
Answer
A client typically resolves an IP through DNS, establishes transport, negotiates TLS, and only then exchanges HTTP. DNS, routing, certificate validation, or the handshake can fail before the application server sees a request. HTTP/3 changes the transport but not the need to understand these layers.
Examples
- An expired certificate causes a browser error even when the endpoint and server business logic are healthy.
Practice exercises
- Create a diagnostic tree for “site unavailable,” from DNS through the application response.
What does an idempotent method mean?Middle
Answer
Several identical requests have the same expected effect on server state as one request. Responses may differ.
Examples
- Repeating a PUT for the same state does not create another resource, although a response timestamp may change.
Practice exercises
- Repeat a PUT and define separate expectations for state and response.
How does HTTP caching affect behaviour visible to users?Middle
Answer
Cache-Control defines where and how long a response may be reused; ETag and Last-Modified support revalidation. Defects arise from stale data, incorrect cache keys, cached private responses, or missing invalidation. Test the browser, CDN, and origin as separate layers.
Examples
- A profile response without Vary: Authorization could reach the wrong user through a shared cache.
Practice exercises
- Design cache-hit, revalidation, invalidation, and private-data checks for one GET endpoint.
How are cookies related to sessions and CSRF?Middle
Answer
A browser automatically attaches matching cookies to requests, allowing a session cookie to carry identity across stateless HTTP exchanges. Secure, HttpOnly, and SameSite reduce particular risks but do not replace CSRF protection or server-side session controls. Domain, path, and expiry also define scope.
Examples
- SameSite=Lax limits some cross-site requests, but a sensitive endpoint still needs an appropriate CSRF defence model.
Practice exercises
- Test a login session for rotation, logout invalidation, expiry, parallel devices, and cookie attributes.
What does CORS do?Senior
Answer
It controls whether a browser may read cross-origin responses; it does not replace server-side authorization.
Examples
- curl may read a response that browser JavaScript blocks because of CORS.
Practice exercises
- Compare the same cross-origin request in a browser and curl, and inspect the preflight.
How do reverse proxies and load balancers change the test surface?Senior
Answer
Intermediaries may terminate TLS, rewrite headers, route by host or path, retry, rate-limit, and perform health checks. A direct backend call therefore does not prove production-path behaviour. Test forwarded identity, timeout budgets, sticky sessions, and partial-failure handling.
Examples
- A proxy retry of an unsafe POST after timeout may create a duplicate unless the endpoint has idempotency protection.
Practice exercises
- Draw the production request path and identify one failure mode for DNS, CDN, proxy, balancer, and service.
Which browser security boundaries matter when testing a web application?Senior
Answer
The same-origin policy limits reading resources across origins; CORS provides controlled exceptions; CSP restricts executable-content sources; sandbox and permission policies narrow embedded-content capabilities. These mechanisms solve different problems, and none repairs weak server-side authorization.
Examples
- CORS lets a frontend read a response, but the backend must still verify the user’s access to that specific order.
Practice exercises
- For an application with an iframe and API, build a matrix of origin, credentials, CORS, CSP, and authorization expectations.