KKitForma.

Language

EnglishEnglishTürkçeTurkishTool unavailable · open catalogDeutschGermanTool unavailable · open catalogEspañolSpanishTool unavailable · open catalogFrançaisFrenchTool unavailable · open catalogPortuguêsPortugueseTool unavailable · open catalogItalianoItalianTool unavailable · open catalogNederlandsDutchTool unavailable · open catalogPolskiPolishTool unavailable · open catalogРусскийRussianTool unavailable · open catalogУкраїнськаUkrainianTool unavailable · open catalogSvenskaSwedishTool unavailable · open catalogNorskNorwegianTool unavailable · open catalogDanskDanishTool unavailable · open catalogSuomiFinnishTool unavailable · open catalogČeštinaCzechTool unavailable · open catalogRomânăRomanianTool unavailable · open catalogΕλληνικάGreekTool unavailable · open catalogالعربيةArabicTool unavailable · open catalogעבריתHebrewTool unavailable · open catalogفارسیPersianTool unavailable · open catalogاردوUrduTool unavailable · open catalogहिन्दीHindiTool unavailable · open catalogবাংলাBengaliTool unavailable · open catalogதமிழ்TamilTool unavailable · open catalogతెలుగుTeluguTool unavailable · open catalogमराठीMarathiTool unavailable · open catalogગુજરાતીGujaratiTool unavailable · open catalog简体中文Chinese SimplifiedTool unavailable · open catalog繁體中文Chinese TraditionalTool unavailable · open catalog日本語JapaneseTool unavailable · open catalog한국어KoreanTool unavailable · open catalogTiếng ViệtVietnameseTool unavailable · open catalogไทยThaiTool unavailable · open catalogBahasa IndonesiaIndonesianTool unavailable · open catalogBahasa MelayuMalayTool unavailable · open catalogFilipinoFilipinoTool unavailable · open catalogKiswahiliSwahiliTool unavailable · open catalogAfrikaansAfrikaansTool unavailable · open catalogMagyarHungarianTool unavailable · open catalogБългарскиBulgarianTool unavailable · open catalogHrvatskiCroatianTool unavailable · open catalogSrpskiSerbianTool unavailable · open catalogSlovenčinaSlovakTool unavailable · open catalogSlovenščinaSlovenianTool unavailable · open catalogLietuviųLithuanianTool unavailable · open catalogLatviešuLatvianTool unavailable · open catalogEestiEstonianTool unavailable · open catalogCatalàCatalanTool unavailable · open catalogEuskaraBasqueTool unavailable · open catalog
← All topics and search

Node.js, HTTP & APIs

Server runtimes, requests, authentication and API error diagnosis.

72 troubleshooting guides · Page 3 / 3

  1. Why does webhook signature verification fail after JSON middleware parses the body?

    Many webhook signatures cover the exact received bytes. Parsing and reserializing JSON can change whitespace or key order while preserving its apparent meaning.

  2. How should a webhook handler deal with the same event arriving twice?

    Webhook delivery is often retried when acknowledgement is lost, so duplicate arrival is a normal reliability condition. Treating every delivery as a new business event can duplicate effects.

  3. Why must webhook processing tolerate events arriving out of order?

    Network retries and parallel delivery can change arrival order. The order observed by a handler is not necessarily the order in which the provider changed the resource.

  4. What should an OAuth callback validate before exchanging an authorization code?

    The callback must belong to the authorization attempt initiated by the current client. Accepting an arbitrary code without transaction binding can confuse or compromise login.

  5. What problem does PKCE solve in an OAuth authorization-code flow?

    PKCE binds the code exchange to a secret verifier created for that authorization attempt. It helps prevent an intercepted code from being redeemed by a different party.

  6. Is decoding a JWT enough to authenticate its claims?

    Decoding only reveals the payload. It does not prove the signature, issuer, audience or validity period.

  7. How can refresh-token rotation detect reuse without breaking normal clients?

    Rotation replaces a refresh token after use, allowing later reuse of an invalidated token to signal a problem. Concurrent legitimate refresh requests can complicate the design.

  8. Why should a session identifier change after login?

    Keeping a pre-authentication session identifier after privilege elevation can let a previously known identifier become an authenticated session. Rotation breaks that linkage.

  9. Why does deleting a browser cookie not always invalidate a stolen session?

    Deleting the local cookie removes one client’s copy. A copied bearer token may remain valid at the server until expiry or revocation.

  10. Why can a cookie-authenticated API need CSRF protection even when it returns JSON?

    Browsers can attach cookies automatically to requests. Returning JSON does not itself prove the request originated from the trusted application.

  11. How do I prevent a logged-in user from requesting another user’s document by ID?

    Authentication identifies the caller; it does not prove permission for the requested object. Guess-resistant IDs reduce guessing but are not authorization.

  12. Why should an API not copy every JSON property into a database model?

    A client can submit fields that the visible form never sends, such as ownerId, role or billing status. Blind assignment turns those hidden fields into an attack surface.

  13. How can a server safely offer fetch-from-URL without becoming an internal network proxy?

    A user-controlled URL can direct the server toward loopback, private services or cloud metadata. Redirects and DNS changes make a superficial string check insufficient.

  14. How do I validate a return URL after login?

    A return URL supplied by a user can become an open redirect if the application sends browsers to any requested destination after authentication.

  15. Why is trusting every X-Forwarded-For header unsafe?

    A direct client can supply forwarding headers unless a trusted proxy strips and rebuilds them. Using that untrusted value for security decisions lets clients impersonate network origins.

  16. How should an API set a downloadable filename containing Unicode?

    A download filename is response metadata, not a trusted filesystem path. Incorrect quoting or raw control characters can break headers.

  17. What must a download endpoint consider before supporting byte ranges?

    Range requests can resume or partially retrieve a representation, but the offsets must refer to the exact selected bytes. Compression and changing content complicate that contract.

  18. Why can a signed download URL still leak a private file?

    A signed URL is commonly a bearer capability: anyone holding it may use it until its restrictions expire. A signature prevents modification, not forwarding.

  19. How can password reset responses avoid revealing whether an email is registered?

    Different public messages, status codes or obvious timing behavior can let callers enumerate accounts. The reset flow should not expose account existence unnecessarily.

  20. How do I change an API field without breaking existing clients?

    Clients may depend on field names, types and even absence semantics. A server-side refactor can therefore become a public compatibility change.

  21. How should an API represent a job that continues after the request returns?

    A long task can exceed proxy timeouts, and returning success before durable ownership creates uncertainty if the process stops.

  22. How do I use request IDs without trusting attacker-controlled log content?

    Correlation IDs connect events across services, but a client-supplied value may contain oversized or misleading content. It should be validated before reuse.

  23. Why does one API request take longer than all configured downstream timeouts suggest?

    Sequential calls, retries, connection-pool waiting and cleanup can add together. Independent per-call timeouts do not automatically create one total request deadline.

  24. Why is disabling TLS certificate verification not a valid production fix?

    Verification establishes that the encrypted connection reaches the intended trusted endpoint. Disabling it can hide hostname, trust-chain or interception problems.

Ask your own question · Sign in to post questions and answers.