Skip to content
EduVerse

You’re reading the free preview.Unlock every conversation for €2.99

FreeFree previewChapter 5

Chapter 5 · Free preview

APIs: The Contract

How Frontend and Backend Agree to Communicate

Illustration from the book

What you will understand

  • Design a REST API with the right HTTP methods and status codes
  • Explain the difference between path parameters, query parameters and the request body
  • Compare session-based and JWT-based authentication
  • Understand CORS and know how to configure it
  • Recognise and prevent SQL injection, XSS and CSRF

Written by EduVerse for this preview; the slides below are the book’s own words.

Slides from the chapter

Each slide is a passage from the book with the figure or listing it talks about. Swipe, use the arrow keys or the buttons.

Slide 1 of 4

Session Cookies: The Original Solution (Early 2000s)

5.6 · p. 114

Conversation from The Software Realm, Decoded

Chapter 5 · 5.6 Session Cookies: The Original Solution (Early 2000s) · p. 114

The Senior developer, from the book cover

Senior developer

Think of it like a library card system.

Inspect
Figure · Session Cookies: The Original Solution (Early 2000s)From the book, p. 114

Explore this figure

Pick one to highlight it and read what the book says about it.

Other labels in the figure (7)
Description

Flow diagram: 'You (User)' sends 'Prove identity' to 'Librarian (Server)', who has a 'Check records' arrow toward a 'Card Records (Database)' cylinder. A 'Give card' arrow runs from the Librarian to a 'Library Card' with 'ID: 42'.

Description written by EduVerse; the figure itself is from the book.

The Senior developer, from the book cover

Senior developer

When you register, the librarian gives you a card with an ID number. Every time you borrow a book, you show your card. The librarian looks up your ID in their records to see who you are and what you can borrow.

Peter, from the book cover

Peter

So the card itself doesn’t have my information, just an ID that points to my record?

The Senior developer, from the book cover

Senior developer

Exactly! Same with sessions. Login once, get a session ID stored in a cookie. Browser sends it automatically. Server looks it up in database to find your user info.

Slide 1 of 4

Try it yourself

A simulation built by EduVerse around this chapter. It runs in your browser; nothing is sent anywhere.

Full book

The full chapter

This preview shows 5 of the chapter’s 84 passages. The full chapter has:

  • 12 sections
  • 41 conversations
  • 7 figures and tables
  • 3 What They Say boxes
  • 7 knowledge-check questions
Sections in this chapter
  1. 5.1Peter's First API Problem
  2. 5.2APIs: The Big Picture
  3. 5.3Building Peter's First REST API
  4. 5.4Authentication: Who Are You?
  5. 5.5The Evolution: From Passwords Every Time to Modern Auth
  6. 5.6Session Cookies: The Original Solution (Early 2000s)
  7. 5.7JWT: The Modern Approach (2010s)
  8. 5.8Sessions vs JWT: The Trade-offs
  9. 5.9Authorization: What Can You Do?
  10. 5.10CORS: Peter's Deployment Disaster
  11. 5.11Security: Defending Against Attacks
  12. 5.12Peter's Takeaways