惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Attack and Defense Labs
Attack and Defense Labs
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Threatpost
Project Zero
Project Zero
Know Your Adversary
Know Your Adversary
T
The Exploit Database - CXSecurity.com
P
Palo Alto Networks Blog
T
Tenable Blog
Scott Helme
Scott Helme
T
Tor Project blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
NISL@THU
NISL@THU
Cisco Talos Blog
Cisco Talos Blog
Security Latest
Security Latest
Simon Willison's Weblog
Simon Willison's Weblog
S
Securelist
Help Net Security
Help Net Security
Google DeepMind News
Google DeepMind News
Cloudbric
Cloudbric
C
Check Point Blog
Jina AI
Jina AI
Webroot Blog
Webroot Blog
量子位
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
P
Privacy & Cybersecurity Law Blog
罗磊的独立博客
H
Heimdal Security Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
人人都是产品经理
人人都是产品经理
N
News and Events Feed by Topic
www.infosecurity-magazine.com
www.infosecurity-magazine.com
宝玉的分享
宝玉的分享
Hacker News - Newest:
Hacker News - Newest: "LLM"
L
LINUX DO - 热门话题
The GitHub Blog
The GitHub Blog
T
Troy Hunt's Blog
PCI Perspectives
PCI Perspectives
Vercel News
Vercel News
N
News | PayPal Newsroom
A
Arctic Wolf
T
The Blog of Author Tim Ferriss
博客园 - 司徒正美
博客园 - 叶小钗
Y
Y Combinator Blog
V
V2EX
美团技术团队
O
OpenAI News
Microsoft Security Blog
Microsoft Security Blog
AWS News Blog
AWS News Blog

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
The Request/Response Cycle, HTTP, Auth, JWT, OAuth & Sessions — Explained Properly
Chinwuba · 2026-05-26 · via DEV Community

Most developers learn backend development backwards.

They start with frameworks like Express.js, Next.js, or Django and only later realize they never actually understood what was happening underneath.

That’s why so many developers can build features but struggle to debug authentication issues, CORS problems, cookies, caching, or weird API behavior.

Everything on the web comes down to one thing:

A client sends a request.
A server sends a response.

That’s the entire internet.

But the details inside that cycle are what separate beginners from engineers who deeply understand systems.

The Request/Response Cycle

Imagine you type:

google.com

into your browser and hit Enter.

What happens next?

A lot more than most people think.

Step 1 — DNS Resolution

Your browser does not know where google.com lives.

It asks a DNS server:

“What IP address belongs to google.com?”

DNS responds with something like:

142.250.184.46

DNS is basically the internet’s phonebook.

Humans remember names.
Computers communicate with IP addresses.

Without DNS, we would all be typing raw IP addresses into browsers.

Step 2 — TCP Handshake

Before HTTP even begins, the browser and server establish a connection.

This happens using a TCP three-way handshake:

Client → SYN
Server → SYN-ACK
Client → ACK

This basically means:

“I want to connect.”
“Okay, I’m ready.”
“Great, let’s communicate.”

This setup takes time.

That’s why the first request to a server is slower than later requests.

Step 3 — TLS Handshake (HTTPS)

If the site uses HTTPS — which most modern websites do — another handshake happens.

Now the browser and server negotiate:

encryption algorithms
security certificates
encryption keys

This is what keeps your passwords, messages, and payment information secure while traveling across the internet.

Without HTTPS, anyone on the network could potentially read your traffic.

Step 4 — The HTTP Request

Now the browser finally sends the actual request.

A real request literally looks like this:

GET / HTTP/1.1
Host: google.com
Accept: text/html
User-Agent: Mozilla/5.0

That’s it.

Plain text.

HTTP is just structured text sent over a network connection.

Step 5 — The Server Processes the Request

The server receives the request and decides what to do.

Maybe it:

queries a database
authenticates a user
processes business logic
generates HTML
fetches cached data
talks to another API

Then it prepares a response.

Step 6 — The Response Comes Back

A response looks like this:

HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 48523

<!DOCTYPE html>
...

A response contains:

Status line
Headers
Blank line
Body

Every API response you’ve ever worked with follows this pattern.

Step 7 — The Browser Fires More Requests

The HTML might reference:

CSS files
JavaScript bundles
fonts
images
videos

Each one triggers additional requests.

A single page load can easily generate 50–100 requests.

This is why:

caching matters
CDNs matter
bundling matters
HTTP/2 matters
performance optimization matters

Every request has overhead.

HTTP Methods Explained Properly

Methods are the verbs of HTTP.

The URL is the noun.

Together they form a sentence.

GET

Retrieves data.

GET /users/42

Rules:

should not change server state
should be safe
should be idempotent

Calling it 10 times should behave the same as calling it once.

GET requests are aggressively cached by browsers.

POST

Creates data or triggers an action.

POST /users

POST requests usually contain a body:

{
"name": "Jeffrey"
}

POST is not idempotent.

Submitting the same form twice may create two records or send two emails.

PUT

Full replacement update.

If a resource has 10 fields and you PUT it, you send all 10.

Missing fields may get erased.

PATCH

Partial update.

Only send the fields that changed.

Most modern APIs prefer PATCH over PUT.

DELETE

Deletes a resource.

DELETE /users/42

Usually idempotent.

Deleting something twice should not crash the server.

HEAD

Like GET, but returns headers only.

Useful for:

checking file existence
checking last modified dates
validating caches

without downloading the body.

OPTIONS

Asks:

“What methods are allowed here?”

Browsers use this heavily during CORS preflight requests.

Status Codes — What They Actually Mean
2xx — Success
200 OK

Standard success.

201 Created

Something new was created.

Usually returned after POST.

204 No Content

Success with no response body.

Very common for DELETE operations.

3xx — Redirects
301 Moved Permanently

Permanent redirect.

Search engines update their records.

302 Found

Temporary redirect.

304 Not Modified

Used for caching.

Server tells the browser:

“Use your cached version.”

No response body needed.

4xx — Client Errors
400 Bad Request

Malformed request.

401 Unauthorized

Actually means unauthenticated.

“I don’t know who you are.”

403 Forbidden

Authenticated but not allowed.

“I know who you are, but you can’t do this.”

404 Not Found

Resource does not exist.

409 Conflict

Conflicts with current state.

Example:

duplicate email during signup
422 Unprocessable Entity

Valid syntax, invalid data.

429 Too Many Requests

Rate limiting.

5xx — Server Errors
500 Internal Server Error

Generic server crash.

502 Bad Gateway

Proxy received an invalid response upstream.

503 Service Unavailable

Server overloaded or under maintenance.

504 Gateway Timeout

Upstream server took too long to respond.

The Most Important Debugging Skill

Remember this rule:

4xx = fix the request
5xx = fix the server

That mental model alone saves developers hours.

Headers — The Hidden Metadata

Headers are key-value pairs.

They carry metadata about requests and responses.

Important Request Headers
Authorization

Used for authentication.

Two common formats:

Authorization: Basic base64(username:password)

and

Authorization: Bearer

Bearer tokens are heavily used in modern APIs.

Content-Type

Tells the server how to parse the body.

Examples:

application/json
multipart/form-data
application/x-www-form-urlencoded

If this header is wrong, your backend may fail to parse incoming data.

Cookie

Sends stored cookies to the server.

This powers traditional session authentication.

Important Response Headers
Set-Cookie

Tells the browser to store a cookie.

Cache-Control

Controls caching behavior.

Examples:

no-store
max-age=3600
public
private

Caching is one of the biggest performance optimizations on the web.

Access-Control-Allow-Origin

The famous CORS header.

Without it, browsers block cross-origin responses.

CORS — Why Every Developer Eventually Suffers

CORS confuses almost everyone initially.

Here’s the core idea:

Browsers enforce a Same-Origin Policy.

JavaScript running on:




cannot freely read responses from:



```api.otherdomain.com```



without permission.

Why?

Security.

Otherwise malicious websites could silently read sensitive data from sites where you’re logged in.

**How CORS Works**

When your frontend calls another origin, the browser may first send:

OPTIONS /api/users

This is called a preflight request.

The server must respond with headers like:

Access-Control-Allow-Origin: https://velto.io
Access-Control-Allow-Methods: GET, POST, PATCH
Access-Control-Allow-Headers: Authorization, Content-Type

If those headers are missing:

the request may still succeed
the server may still respond
but the browser blocks JavaScript from reading the response

That’s why CORS errors feel confusing.

It’s not usually the backend failing.

It’s the browser enforcing security rules.

**Authentication — The Real Problem It Solves**

HTTP is stateless.

The server forgets you after every request.

Authentication solves that memory problem.

There are three major approaches:

Sessions
JWT
OAuth

**Sessions — The Traditional Approach**

Sessions work like coat-check tickets.

You log in once.

The server creates a session record:

session_id → user_id

Then the server gives your browser a cookie:

Set-Cookie: sessionId=abc123

Your browser automatically sends it back later:

Cookie: sessionId=abc123

The server checks its session store and identifies you.

Why Sessions Are Still Great

Advantages:

instant logout
easy invalidation
simple security model
works naturally with browsers

Disadvantages:

server must store session state
scaling requires shared storage like Redis

But honestly?

For many applications, sessions are still the best option.

**JWT — JSON Web Tokens**

JWTs use a different philosophy.

Instead of storing session state on the server, the client carries signed identity data.

A JWT contains payload data like:

{
  "sub": "42",
  "role": "admin",
  "exp": 1716716400
}

The server signs it cryptographically.

Clients send it like:

Authorization: Bearer <token>

The server verifies the signature and trusts the contents.

No database lookup required.

The Big JWT Tradeoff

JWTs are stateless.

That’s their strength.

And their weakness.

If a JWT gets stolen, it stays valid until expiration.

You cannot instantly invalidate it unless you maintain some server-side blacklist.

This is why modern systems use:

short-lived access tokens
long-lived refresh tokens
Where Should JWTs Be Stored?
localStorage

Easy.

But vulnerable to XSS attacks.

httpOnly Cookies

Much safer.

JavaScript cannot read them.

Preferred for many web apps.

Memory

Most secure.

But disappears on refresh.

**Sessions vs JWT**

Use sessions when:

building traditional web apps
you need instant logout
security matters heavily

Use JWT when:

multiple services need auth
mobile apps consume your API
microservices need shared identity verification

Most applications do not need ultra-complex auth architecture.

Simplicity is often more secure.

**OAuth — “Login with Google”**

OAuth lets third parties authenticate users without sharing passwords.

When users click:

“Continue with Google”

your app never sees their Google password.

Google handles authentication.

Your app only receives trusted identity information.

Simplified OAuth Flow
User clicks login with Google
Redirect to Google
User logs in
Google asks permission
Google redirects back with a code
Your server exchanges the code for tokens
Your app logs the user in

The critical detail:

The token exchange happens server-to-server.

Not directly in the browser.

That prevents token leakage.

Password Storage — Never Store Plain Passwords

Passwords should always be hashed.

Use:

bcrypt
Argon2
scrypt

These are intentionally slow algorithms designed to resist brute-force attacks.

Never store raw passwords.

Ever.

The Full Modern Auth Flow

A modern app usually looks like this:

Registration
hash password
store user
issue session/token
Login
verify credentials
issue authentication
Authenticated Requests
client sends token/cookie
server validates identity
Token Refresh
expired access token replaced using refresh token
Logout
destroy session or invalidate refresh token
Password Reset
issue single-use time-limited reset token
email user
invalidate token after use
Final Thought

Frameworks change constantly.

Protocols last decades.

If you deeply understand:

HTTP
request/response cycles
headers
status codes
cookies
sessions
JWT
OAuth
CORS

then every backend framework becomes dramatically easier to learn.

Because underneath all the abstractions, the internet is still just:

A client sending text to a server.
A server sending text back.

Everything else is layers on top of that foundation.