You’re reading the free preview.Unlock every conversation for €2.99
FreeFree previewChapter 5

Chapter 5 · Free preview
APIs: The Contract
How Frontend and Backend Agree to Communicate
What you will understand
- Design a REST API with the right HTTP methods and status codes
- Explain the difference between path parameters, query parameters and the request body
- Compare session-based and JWT-based authentication
- Understand CORS and know how to configure it
- Recognise and prevent SQL injection, XSS and CSRF
Written by EduVerse for this preview; the slides below are the book’s own words.
Slides from the chapter
Each slide is a passage from the book with the figure or listing it talks about. Swipe, use the arrow keys or the buttons.
Slide 1 of 4
JWT: The Modern Approach (2010s)
5.7 · p. 116
Conversation from The Software Realm, Decoded
Chapter 5 · 5.7 JWT: The Modern Approach (2010s) · p. 116

Senior developer
Remember the festival last summer?

Peter
The fair? Yeah! They put a plastic wristband on me.

Senior developer
That’s JWT! Let me show you why it solves the scaling problem.
What the book shows with it
Example from The Software Realm, Decoded
Chapter 5 · 5.7.1 The Festival Wristband Model · p. 116
Explore this figure
Pick one to highlight it and read what the book says about it.
Other labels in the figure (8)
Description
Flow diagram: 'You at entrance' has an arrow labelled 'Pay €30' to 'Festival Entrance', which points down via 'Get wristband' to a 'Wristband:' box showing 'Color: Green' and 'Number: 12345'.
Description written by EduVerse; the figure itself is from the book.
You: *shows wristband*
Operator: *looks at wristband itself*
- Green color? (Adult and valid for the entire week)
- Not tampered with? (Intact plastic seal)
Operator: "Go ahead!"Explore this text diagram
Pick one to highlight it and read what the book says about it.
Other terms (7)
Sessions vs JWT: The Trade-offs
5.8 · p. 119
Figure from The Software Realm, Decoded
Chapter 5 · 5.8 Sessions vs JWT: The Trade-offs · p. 119
Explore this table
Pick one to highlight it and read what the book says about it.
Other cells in the table (23)
Description
Table: quick comparison of 'Sessions' and 'JWT' on database load, scaling, mobile apps, revocation, token size and info storage. Sessions: every request hits the database, which becomes a bottleneck; cookies can be complicated; easy revocation; small token; server-side info. JWT: signature check only, scales effortlessly, works perfectly on mobile, hard to revoke, larger token with readable, signed info inside.
Description written by EduVerse; the figure itself is from the book.
Peter summarizes:
Explore this figure
Pick one to highlight it and read what the book says about it.
Other labels in the figure (8)
Description
Two side-by-side summary boxes. 'Sessions = Library Card': 'Card ID points to your record', 'Every request → database lookup', 'More users = more lookups = bottleneck'. 'JWT = Festival Wristband': 'Wristband contains all info', 'Every request → verify signature only', 'More users = same low cost = scales!'
Description written by EduVerse; the figure itself is from the book.
HTTP Status Codes Peter Learns
5.9.3 · p. 121
Conversation from The Software Realm, Decoded
Chapter 5 · 5.9.3 HTTP Status Codes Peter Learns · p. 121

Peter’s confusion
401 says ‘Unauthorized’ but means not authenticated?

Senior developer
Yeah, the name is misleading. Historic mistake. Remember:
- 401: “Who are you?” (need to login)
- 403: “I know who you are, but you can’t do that”

Peter
So 401 is ‘you need to identify yourself’ and 403 is ‘I know who you are, and the answer is no’?

Senior developer
Exactly! You’ve got it.
Slide 1 of 4
Try it yourself
A simulation built by EduVerse around this chapter. It runs in your browser; nothing is sent anywhere.
The full chapter
This preview shows 5 of the chapter’s 84 passages. The full chapter has:
- 12 sections
- 41 conversations
- 7 figures and tables
- 3 What They Say boxes
- 7 knowledge-check questions
Sections in this chapter
- 5.1Peter's First API Problem
- 5.2APIs: The Big Picture
- 5.3Building Peter's First REST API
- 5.4Authentication: Who Are You?
- 5.5The Evolution: From Passwords Every Time to Modern Auth
- 5.6Session Cookies: The Original Solution (Early 2000s)
- 5.7JWT: The Modern Approach (2010s)
- 5.8Sessions vs JWT: The Trade-offs
- 5.9Authorization: What Can You Do?
- 5.10CORS: Peter's Deployment Disaster
- 5.11Security: Defending Against Attacks
- 5.12Peter's Takeaways