Java practice in Backend Java
Browse the rooms before signing in. Opening a room requires an account and follows your existing access. Practice does not issue certificates.
Decode the Query
A search box sends `hello+world` and `%20` for spaces. Decode an encoded value so the search actually finds what the user typed.
query. Free room.
Name the Status
Browsers show reason phrases, not bare numbers. Map a status code to its category so the monitoring page can color 4xx red and 5xx black.
response. Free room.
Read the Verb
The new gateway logs every request's method. Pull the verb off the front of a raw request line so the dashboard can count GETs and POSTs.
request-line. Free room.
Split the Media Type
A Content-Type can carry parameters like `text/html; charset=utf-8`. Strip them off to get the bare media type the router branches on.
headers. Free room.
405, Not 404
A client sent DELETE to a read-only route. Return 405 when the path exists but the method does not, so the error tells them the verb is wrong, not the URL.
method. Account access required.
Escape the String
The serializer must turn a name containing a quote into safe JSON. Escape the quotes and backslashes so the output parses cleanly downstream.
serialize. Account access required.
Match the Route
The router needs to know whether `/users/:id` matches an incoming `/users/42`. Implement the segment match so requests reach the right handler.
params. Account access required.
Pull the ID
The route `/users/:id` matched, and the handler needs the number. Pull the id off the last path segment, returning -1 when it is not numeric, so a bad URL fails cleanly.
dispatch. Account access required.
Count the Hits
The team wants to know if the cache is worth its memory. Over a sequence of key lookups, count the cache hits (repeat accesses), so you can report the hit ratio.
cache-aside. Account access required.
Fill the Bucket
The API is getting hammered. Run a token-bucket limiter over a burst of requests and count how many are allowed, so you can prove the limiter holds the line.
token-bucket. Account access required.
Is It Fresh?
A cached page may be fresh, stale-but-servable, or fully expired. Classify an entry by its expiry and grace window so the CDN knows whether to revalidate.
ttl. Account access required.
Shed the Load
The server is at capacity. Shed low-priority requests once load passes 80 percent, but never drop a high-priority one, the controlled degradation that keeps the critical path alive.
resource-guard. Account access required.
Collect Every Error
The signup form returns only the first mistake, and users hate it. Validate a name and age and report ALL the failures at once, so they fix everything in one pass.
validation. Account access required.
Detect the Tamper
An attacker flipped role=user to role=admin but kept the old signature. Re-sign the payload and compare, so the forged token is rejected at the door.
tokens. Account access required.
Guard the Write
Reads are public but writes need a token. Return 401 when an unsafe method arrives without one, so the auth middleware protects the mutations.
pipeline. Account access required.
Scrub the Input
User text is about to render in a page. Escape the HTML-special characters so `<script>` shows up as text, not markup, the one-line defense against injection.
sanitize. Account access required.
Dispatch the Request
The router must turn a method and path into a handler verdict. Return the handler for a match, 405 for the wrong method, 404 for an unknown path, the heart of the framework.
dispatch. Account access required.
Run the Pipeline
Auth, then body validation, then handle, in that order. Return 401 if a write lacks a token, 400 if the POST body has no name, else 200. Get the order right.
pipeline. Account access required.
Ship the Response
The very end of the stack: turn a status and body into a raw HTTP response string with the right reason phrase and Content-Length. This is what goes on the wire.
end-to-end. Account access required.
Stamp the ETag
A conditional GET carries the client's cached fingerprint. Return 304 Not Modified when it matches the current ETag, else 200, the protocol-level cache that skips the body.
http-cache. Account access required.