Backend
Lesson 1 of 8About 3 min readSuggest an edit

HTTP fundamentals

Almost every backend speaks HTTP. It is a request–response protocol: a client sends a request, a server sends back exactly one response.

Anatomy of a request and a response

POST /orders HTTP/1.1
Host: api.example.com
Content-Type: application/json
Authorization: Bearer eyJhbGciOi...

{"sku": "book-42", "quantity": 1}
HTTP/1.1 201 Created
Location: /orders/9001
Content-Type: application/json

{"id": 9001, "status": "pending"}

A request has a method, a path, headers and an optional body. A response has a status code, headers and an optional body.

Methods: safe and idempotent

  • A safe method does not change server state: GET, HEAD, OPTIONS.
  • An idempotent method has the same effect whether you send it once or ten times.
Method Safe Idempotent Typical use
GET yes yes Read a resource
PUT no yes Replace a resource at a known URL
DELETE no yes Remove a resource
POST no no Create or trigger an action
PATCH no not guaranteed Partial update

Idempotency matters because networks fail. If a PUT times out, the client can safely retry it. Retrying a POST might create two orders, which is why payment APIs accept an idempotency key header: the server remembers the key and returns the first result for repeats.

Status codes

  • 2xx success: 200 OK, 201 Created, 204 No Content.
  • 3xx redirection: 301 Moved Permanently, 302 Found, 304 Not Modified.
  • 4xx client error: 400 Bad Request (malformed), 401 Unauthorized (not authenticated), 403 Forbidden (authenticated but not allowed), 404 Not Found, 409 Conflict, 422 Unprocessable Content, 429 Too Many Requests.
  • 5xx server error: 500 Internal Server Error, 502 Bad Gateway, 503 Service Unavailable.

The line between 4xx and 5xx tells clients whether a retry could help: repeating a 4xx request unchanged will fail again.

Caching headers

  • Cache-Control: max-age=3600 lets clients and CDNs reuse a response for an hour.
  • Cache-Control: no-store forbids storing it at all. Use it for sensitive data.
  • Validators allow cheap revalidation. The server sends an ETag (a version fingerprint) or Last-Modified. The client later sends If-None-Match or If-Modified-Since, and the server replies 304 Not Modified with no body if nothing changed.

Content negotiation

The client says what it accepts (Accept: application/json, Accept-Encoding: gzip, br). The server picks a representation and says what it chose in Content-Type and Content-Encoding.

Statelessness and cookies

HTTP is stateless: each request carries everything the server needs, and no request depends on the previous one. Sessions are layered on top. The server sets a cookie:

Set-Cookie: sid=abc123; HttpOnly; Secure; SameSite=Lax; Path=/; Max-Age=2592000

The browser sends Cookie: sid=abc123 on later requests. HttpOnly hides the cookie from JavaScript, Secure restricts it to HTTPS, and SameSite=Lax stops it from being sent on most cross-site requests, which blocks common CSRF attacks.

Statelessness is what lets you run many identical server instances behind a load balancer: any instance can handle any request.

Next: Transactions and isolation

ACID, isolation levels, lost updates and how to keep concurrent writes correct.