Node.js, HTTP & APIs
Server runtimes, requests, authentication and API error diagnosis.
72 troubleshooting guides · Page 2 / 3
Why does fs.watch behave differently inside a container or network filesystem?
File watching depends on operating-system facilities and the underlying filesystem. Renames, replacement writes and virtualized mounts can produce different event patterns.
How can I tell a Node memory leak from normal garbage-collector growth?
Heap usage can rise between collections without implying a leak. Sustained retained growth after comparable workloads is more informative.
Why does setInterval not run exactly on schedule?
Timers schedule callbacks for a future opportunity; they do not reserve CPU at an exact wall-clock instant. Event-loop load and callback duration introduce delay.
Why are final console logs missing when process.exit is called?
A forced exit can terminate the process before pending asynchronous writes finish. Console output behavior also depends on its destination.
Why does changing DNS not immediately move all Node outbound traffic?
Existing keep-alive connections can continue using an old destination, and resolution behavior depends on the client, resolver and any configured cache. DNS TTL is not a command to close live sockets.
Why does changing an environment variable not affect a running Node process?
A process inherits its environment at startup. Changing a parent shell or deployment setting does not generally rewrite the environment of an already running process.
Why does npm ci fail when npm install worked locally?
Npm ci expects the dependency manifest and lockfile to agree and performs a clean, lockfile-driven installation. Local node_modules can hide missing or inconsistent declarations.
Why does a package file exist but importing its subpath fails?
A package can define exports that expose only selected entry points. Files present on disk are not automatically part of its public import interface.
Why does a circular CommonJS import see an incomplete object?
During a CommonJS cycle, one module may receive another module’s exports before its initialization has finished. The result depends on execution order.
Why does starting one Node worker from a preload script create more workers repeatedly?
Worker threads inherit command-line execution arguments unless execArgv is explicitly configured. A script loaded with `node -r` can therefore run again inside its own worker and launch another worker recursively.
How do I reject an oversized Node upload before memory is exhausted?
Buffering a request body without a limit lets an upload consume memory proportional to its size. Content-Length alone is not sufficient because it may be absent or untrusted.
How do I compare webhook signatures without ordinary string equality?
A signature verifier should compare validated, equal-length byte sequences with an appropriate constant-time primitive. Ordinary string comparison is not designed for that purpose.
Why should Node readiness differ from process liveness?
A running process can be alive but unable to serve useful traffic because initialization or a required dependency is unavailable. One health flag cannot always express both states.
How can an API prevent duplicate orders when a client retries a POST?
A lost response leaves the client unsure whether the server committed the operation. Repeating a create request can create a second order unless the server recognizes the original intent.
Which API failures should trigger an automatic retry?
Retry decisions depend on whether the operation is safe to repeat and whether failure is transient. A status code alone does not reveal whether a write already happened.
How should an API distinguish 401 from 403?
A 401 response concerns missing or unacceptable authentication and carries the appropriate authentication challenge. A 403 means the server refuses the request despite understanding it.
How can API errors remain useful without exposing stack traces?
Clients need a stable error contract, while stack traces and internal queries often reveal implementation details or private data. Those are different audiences.
How should an API communicate rate limiting to clients?
A controlled rate-limit response should tell clients to slow down without confusing the condition with an internal crash. The policy should also account for identity and resource cost.
How do ETag and If-Match prevent overwriting a newer resource version?
A client can submit an edit based on stale data. A conditional write lets the server reject the update when the representation has changed.
What is the difference between no-cache and no-store for API responses?
No-cache permits storage but requires validation before reuse under its rules. No-store instructs caches not to store the response. The names are easy to misread.
Why can a CDN serve the wrong language even though the origin uses Accept-Language?
If the response varies by a request header but the cache key does not, a shared cache can reuse one language’s representation for another request.
Why does an API return JSON text that clients treat as plain text or HTML?
The response representation and Content-Type may disagree, or a proxy error page may be arriving where JSON was expected. Parsing assumptions then fail.
Why should an API limit JSON nesting and complexity as well as byte size?
A relatively small payload can still trigger expensive parsing, deep recursion or a huge amount of downstream work. A byte cap controls only one dimension.
Should an API cursor be trusted because it is Base64 encoded?
Base64 is reversible encoding, not integrity protection or authorization. A client can edit the decoded cursor and encode it again.
Ask your own question · Sign in to post questions and answers.