惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
aimingoo的专栏
aimingoo的专栏
D
Docker
N
Netflix TechBlog - Medium
IT之家
IT之家
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
宝玉的分享
宝玉的分享
美团技术团队
P
Proofpoint News Feed
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Stack Overflow Blog
Stack Overflow Blog
The Cloudflare Blog
G
Google Developers Blog
腾讯CDC
Help Net Security
Help Net Security
Google DeepMind News
Google DeepMind News
Security Archives - TechRepublic
Security Archives - TechRepublic
Apple Machine Learning Research
Apple Machine Learning Research
L
LINUX DO - 最新话题
O
OpenAI News
博客园 - 司徒正美
Google Online Security Blog
Google Online Security Blog
H
Hacker News: Front Page
博客园 - 聂微东
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Project Zero
Project Zero
Vercel News
Vercel News
C
CXSECURITY Database RSS Feed - CXSecurity.com
C
Check Point Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
A
Arctic Wolf
Microsoft Security Blog
Microsoft Security Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Forbes - Security
Forbes - Security
www.infosecurity-magazine.com
www.infosecurity-magazine.com
人人都是产品经理
人人都是产品经理
大猫的无限游戏
大猫的无限游戏
S
Security @ Cisco Blogs
T
Tor Project blog
D
DataBreaches.Net
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Spread Privacy
Spread Privacy
W
WeLiveSecurity
V2EX - 技术
V2EX - 技术
Simon Willison's Weblog
Simon Willison's Weblog
AI
AI
Security Latest
Security Latest
S
Securelist

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
How the Internet Actually Works: Understanding Client-Server Architecture with Real Code
Anal Jyoti G · 2026-05-20 · via DEV Community

How the Internet Actually Works: Understanding Client-Server Architecture with Real Code

The Big Picture: What Happens When You Visit a Website?

Every time you type a URL into your browser and hit Enter, a surprisingly complex chain of events kicks off in the background. Most people never think about it, but understanding this process is the foundation of everything we'll cover in this guide.

Let's walk through what actually happens when you visit something like https://www.example.com.

Step 1: Your browser looks up the address

Your computer doesn't understand domain names like www.example.com. It needs an IP address, which is basically a numerical home address for a server somewhere in the world. To get it, your browser contacts a DNS (Domain Name System) server, which works like a giant phone book for the internet. It translates the human-friendly name into something like 93.184.216.34.

Step 2: Your browser opens a connection

Now that your browser knows the IP address, it reaches out to that server and says "hey, I'd like to talk." This happens using a protocol called TCP (Transmission Control Protocol), which sets up a reliable back-and-forth channel between your machine and the server.

Step 3: Your browser sends an HTTP request

Once the connection is open, your browser sends a message to the server. That message looks something like this:

GET / HTTP/1.1
Host: www.example.com
User-Agent: Mozilla/5.0
Accept: text/html

Enter fullscreen mode Exit fullscreen mode

This is a raw HTTP request. It's just text, following a specific format. The GET part means "please give me this resource." The / refers to the homepage.

Step 4: The server sends back a response

The server receives your request, figures out what you want, and sends back a response:

HTTP/1.1 200 OK
Content-Type: text/html

<!DOCTYPE html>
<html>
  <body><h1>Hello, World!</h1></body>
</html>

Enter fullscreen mode Exit fullscreen mode

The 200 OK means everything went fine. The server then sends the actual HTML content your browser will display.

Step 5: Your browser renders the page

Your browser reads the HTML, fetches any additional files it needs (like CSS, images, or JavaScript), and paints the final page on your screen.

The whole process typically takes under a second, but it involves your computer, at least one DNS server, and a web server potentially located on the other side of the planet.

This request-and-response cycle is the heartbeat of the web. Everything else we cover in this tutorial builds directly on top of it.

Clients vs. Servers: Who Does What?

Before we write any code, let's get one thing straight: a client and a server are just two computers (or programs) having a conversation. That's it. No magic involved.

Here's the simple breakdown:

  • The client is the one asking questions. Your web browser is a client. When you type a URL and hit enter, your browser is saying "Hey, can I have that webpage?"
  • The server is the one answering. It sits around waiting for requests, and when one arrives, it figures out what to send back.

Think of it like ordering food at a restaurant. You're the client, you make a request ("I'll have the burger"), and the kitchen is the server, preparing and sending back exactly what you asked for.

A Client Sends Requests

A request has a few key pieces:

  1. A method (like GET or POST) that says what kind of action you want
  2. A URL that says where you want to do it
  3. Headers that carry extra info (like what kind of data you can accept)
  4. A body (optional) that carries data you're sending along

Here's what a dead-simple client looks like in Python using the requests library:

import requests

response = requests.get("https://jsonplaceholder.typicode.com/posts/1")

print(response.status_code)  # 200 means success
print(response.json())       # The actual data sent back

Enter fullscreen mode Exit fullscreen mode

Run that and you'll see a dictionary of data come back. Your script just acted as a client.

A Server Listens and Responds

The server's job is to:

  1. Listen on a specific port for incoming connections
  2. Read the incoming request
  3. Process it (look up data, run some logic, whatever)
  4. Send back a response with a status code and some data

A status code is just a number that tells the client how things went. You've probably seen 404 before, which means "I couldn't find what you asked for." A 200 means everything went fine.

Here's a quick cheat sheet of the most common ones:

Code Meaning
200 OK, here's your stuff
201 Created successfully
400 Bad request (you messed up)
404 Not found
500 Server error (they messed up)

Neither side can do the other's job. The client can't serve data, and the server doesn't go out looking for things to do — the client always starts the conversation, and the server always responds. That boundary is also why you can swap out a Spring Boot backend for FastAPI without touching the Angular frontend, as long as the contract — the API — stays the same.

Next up, we'll actually build one of these servers from scratch.

Building a Basic HTTP Server in Python from Zero

Alright, let's get our hands dirty and actually build something. The good news is that Python comes with a built-in HTTP server module, so you don't need to install anything extra to get started.

Open up your terminal and try this one-liner first, just to see the magic happen:

python3 -m http.server 8080

Enter fullscreen mode Exit fullscreen mode

Point your browser to http://localhost:8080 and you'll see a file listing for whatever directory you ran that command in. Cool, right? But that's cheating a little. Let's build one ourselves so you actually understand what's going on.

Create a new file called server.py and paste in this code:

from http.server import HTTPServer, BaseHTTPRequestHandler

class MyHandler(BaseHTTPRequestHandler):
    def do_GET(self):
        # Send a 200 OK response
        self.send_response(200)
        self.send_header("Content-type", "text/html")
        self.end_headers()

        # Write the response body
        message = "<h1>Hello from my server!</h1>"
        self.wfile.write(message.encode("utf-8"))

# Start the server on port 8080
server = HTTPServer(("localhost", 8080), MyHandler)
print("Server running on http://localhost:8080")
server.serve_forever()

Enter fullscreen mode Exit fullscreen mode

Run it with python3 server.py, then visit http://localhost:8080 in your browser. You should see a big "Hello from my server!" heading. You just wrote a web server.

Let's break down what each part does:

  • BaseHTTPRequestHandler is the class we inherit from. It handles the low-level networking stuff so we don't have to.
  • do_GET is a method that gets called automatically whenever someone sends a GET request to your server. The name matters here, so don't rename it.
  • send_response(200) tells the client "everything went fine." That 200 is an HTTP status code.
  • send_header and end_headers package up the metadata about your response before the actual content.
  • self.wfile.write() is where you actually send the content back. It needs bytes, which is why we call .encode("utf-8").

Want to serve different content based on the URL? You can check self.path to see what the user requested:

def do_GET(self):
    self.send_response(200)
    self.send_header("Content-type", "text/html")
    self.end_headers()

    if self.path == "/about":
        message = "<h1>About Page</h1>"
    else:
        message = "<h1>Home Page</h1>"

    self.wfile.write(message.encode("utf-8"))

Enter fullscreen mode Exit fullscreen mode

Now visiting /about gives a different response than visiting /. That right there is the core concept behind routing — something every web framework like Flask or Django builds on top of. Worth noting: this raw http.server approach is useful for learning, but in production you'd reach for FastAPI or Spring Boot, where routing, validation, and serialization are handled for you. For now, though, knowing what happens underneath those abstractions is exactly the point.

Press Ctrl+C in your terminal to stop the server when you're done experimenting.

Making Your First API Request: Sending and Receiving Data

Now that you have a server running, let's actually talk to it. This is where things get fun.

An API request is just your code asking another computer for data. Think of it like ordering food at a restaurant: you (the client) tell the waiter (the HTTP request) what you want, and the kitchen (the server) sends it back.

We'll use Python's requests library to do this. If you don't have it yet, install it with:

pip install requests

Enter fullscreen mode Exit fullscreen mode

Fetching Data with a GET Request

A GET request means "give me some data." Here's the simplest possible example:

import requests

response = requests.get("https://jsonplaceholder.typicode.com/posts/1")

print(response.status_code)   # Should print 200
print(response.json())        # Prints the actual data

Enter fullscreen mode Exit fullscreen mode

Run that and you'll see a real JSON response come back. The status_code of 200 means everything went fine. You'll also notice response.json() automatically converts the raw text into a Python dictionary you can work with right away.

Sending Data with a POST Request

A POST request means "here's some data, do something with it." This is how login forms, sign-up pages, and chat apps send information to a server.

import requests

new_post = {
    "title": "My First Post",
    "body": "Hello, internet!",
    "userId": 1
}

response = requests.post(
    "https://jsonplaceholder.typicode.com/posts",
    json=new_post
)

print(response.status_code)   # Should print 201 (Created)
print(response.json())

Enter fullscreen mode Exit fullscreen mode

Notice the status code here is 201 instead of 200. Servers use different codes to tell you what happened:

Code Meaning
200 OK, here's your data
201 Created successfully
404 Resource not found
500 Server had a problem

Reading the Response

Every response has two important parts:

  1. Headers: metadata about the response (content type, server info, etc.)
  2. Body: the actual data you requested
print(response.headers["Content-Type"])  # Tells you the data format
print(response.text)                     # Raw response as a string
print(response.json())                   # Parsed as a Python dict

Enter fullscreen mode Exit fullscreen mode

One quick tip: always check the status code before trusting the data. A simple habit is:

if response.status_code == 200:
    data = response.json()
    print(data)
else:
    print(f"Something went wrong: {response.status_code}")

Enter fullscreen mode Exit fullscreen mode

That's genuinely all there is to making API requests. You're sending a message over the internet and reading the reply. Everything else is just details built on top of this foundation.

Understanding Stateless vs. Stateful Communication

Here's one of those concepts that trips up a lot of beginners, but once it clicks, everything starts to make more sense.

HTTP is stateless by default. That means every single request your browser sends to a server is treated as a brand new conversation. The server has no memory of you from one request to the next. It's like calling a customer service line where the agent forgets you the moment you hang up, and you have to re-introduce yourself every single time you call back.

Let's make this concrete. Imagine you log into a website. On request #1, you send your username and password. The server checks them and says "yep, that's valid." Now on request #2, you ask to see your profile page. The server has absolutely no idea who you are anymore. Stateless. Clean slate.

# Every request arrives with no memory of previous requests
# The server just sees raw data each time

from http.server import BaseHTTPRequestHandler, HTTPServer

class StatelessHandler(BaseHTTPRequestHandler):
    def do_GET(self):
        # The server has zero context about who called before
        self.send_response(200)
        self.end_headers()
        self.wfile.write(b"Who are you? I have no idea!")

Enter fullscreen mode Exit fullscreen mode

So how do websites actually remember you're logged in? They fake statefulness by passing identity information along with every request. The two most common tricks are:

Cookies - The server sends a small token to your browser after you log in. Your browser then automatically attaches that token to every future request, like wearing a name badge.

Tokens (like JWTs) - Similar idea, but the token itself contains encoded information about who you are, so the server can verify it without even checking a database.

# Simulating stateful behavior by reading a token from headers
class TokenHandler(BaseHTTPRequestHandler):
    def do_GET(self):
        token = self.headers.get("Authorization")

        if token == "Bearer secret-token-123":
            response = b"Welcome back! I recognize your token."
        else:
            response = b"Access denied. Who are you?"

        self.send_response(200)
        self.end_headers()
        self.wfile.write(response)

Enter fullscreen mode Exit fullscreen mode

Notice what happened there. The server itself still has no memory. But because the client sent a token, the server could figure out who was asking. The state lives in the token, not in the server.

This is actually a really smart design. If the server held everyone's session in memory, it would get overwhelmed fast and become nearly impossible to scale. By keeping things stateless and pushing identity into tokens or cookies, you can run dozens of servers and any one of them can handle any request. In practice, this is exactly the pattern you see in Kubernetes-based deployments — pods can be added, removed, or replaced without any of them needing to share session memory, because the client carries its own identity on every call.

The takeaway: stateless does not mean insecure or forgetful from the user's perspective. It just means the client is responsible for proving who they are on every single request.

Common Pitfalls Beginners Make and How to Avoid Them

You've made it this far, which means you're ready to start building real things. But before you do, let's talk about the mistakes that trip up almost every beginner. Learning these now will save you hours of frustration later.


Pitfall #1: Forgetting to Handle Errors in Your Requests

A lot of beginners write code that assumes everything will work perfectly. Spoiler: it won't. Networks fail, servers go down, and URLs get mistyped. Always wrap your requests in error handling:

import requests

try:
    response = requests.get("https://api.example.com/data", timeout=5)
    response.raise_for_status()  # Raises an error for 4xx and 5xx status codes
    print(response.json())
except requests.exceptions.Timeout:
    print("The request timed out. Try again later.")
except requests.exceptions.HTTPError as e:
    print(f"HTTP error occurred: {e}")
except requests.exceptions.ConnectionError:
    print("Could not connect. Check your internet or the URL.")

Enter fullscreen mode Exit fullscreen mode

Notice the timeout=5 parameter too. Without it, your program could hang forever waiting for a response that never comes.


Pitfall #2: Hardcoding Sensitive Data

Never put API keys, passwords, or tokens directly in your code like this:

# BAD - don't do this!
api_key = "my_super_secret_key_12345"

Enter fullscreen mode Exit fullscreen mode

If you push this to GitHub, the whole world can see it. Instead, use environment variables:

import os

api_key = os.environ.get("API_KEY")

Enter fullscreen mode Exit fullscreen mode

Then set the variable in your terminal before running your script:

export API_KEY="my_super_secret_key_12345"

Enter fullscreen mode Exit fullscreen mode


Pitfall #3: Ignoring Status Codes

A request can "succeed" in the sense that it got a response, but that response might be a 404 Not Found or a 500 Internal Server Error. Beginners often skip checking the status code and then wonder why their data looks weird.

Always check response.status_code or use raise_for_status() as shown above.


Pitfall #4: Not Closing Your Server Properly

When you run a local Python server during testing, always stop it with Ctrl + C when you're done. If you just close the terminal window, the port can stay occupied. Then the next time you try to start the server, you'll see something like:

OSError: [Errno 98] Address already in use

Enter fullscreen mode Exit fullscreen mode

You can find and kill the process using:

lsof -i :8080   # Find what's using port 8080
kill -9 <PID>   # Replace <PID> with the process ID shown

Enter fullscreen mode Exit fullscreen mode


Pitfall #5: Assuming JSON is Always the Answer

JSON is super common, but not every API returns it. Some return XML, plain text, or even HTML. Always check the Content-Type header in the response before blindly calling .json(), or you'll get a confusing parse error.

print(response.headers["Content-Type"])

Enter fullscreen mode Exit fullscreen mode

Avoiding these five mistakes puts you way ahead of where most beginners start. Keep them in your back pocket and your debugging sessions will be a lot shorter.