Contents

Web & Networking

HTTP

The request-response protocol behind the web and most APIs.

Backend Engineer track

Junior

Write correct code, ship small changes safely, ask good questions.

Core: start here

  • HTTPThe request-response protocol of the web.
  • HTTP HeadersMetadata attached to requests and responses.
  • HTTP MethodsGET, POST, PUT, PATCH, DELETE and what each one means.
  • HTTP Status CodesThree-digit codes grouped 1xx–5xx describing the result.
  • HTTPSHTTP encrypted with TLS.
  • Path vs Query Parameters/users/42 vs /users?id=42, and when to use each.
  • URLThe address of a resource: scheme, host, path, query and fragment.
13 more junior concepts
  • 2xx Success Codes200 OK, 201 Created, 204 No Content and friends.
  • 3xx Redirects301, 302, 307, 308 and when to use each one.
  • 4xx Client Errors400, 404, 409, 422, 429: the client did something wrong.
  • 5xx Server Errors500, 502, 503, 504: the server failed.
  • Content-TypeThe header declaring a body's format, like application/json.
  • CookieA small piece of data the server asks the browser to store and send back automatically on later requests.
  • HTTP RequestA method, URL, headers and an optional body.
  • HTTP ResponseA status code, headers and a body.
  • Query StringKey-value parameters after the ? in a URL.
  • RedirectSending a client to a different URL.
  • URL EncodingEscaping special characters in URLs as %XX.
  • User-AgentThe header identifying the client software.
  • WebhookAn HTTP callback: a service calls your URL when something happens.

Mid-level

Own a feature end to end without hand-holding.

Core: start here

  • CORSCross-Origin Resource Sharing: how a server lets browsers call it from other origins.
  • HTTP CachingCache-Control, ETag and Last-Modified for reusing responses.
19 more mid-level concepts
  • Cache-ControlThe header that directs how responses may be cached.
  • Content NegotiationClient and server agreeing on format and language through Accept headers.
  • ETagA version identifier used for conditional requests and caching.
  • HSTSA header telling browsers to always use HTTPS for a site.
  • HTTP Compressiongzip and Brotli shrinking responses on the wire.
  • HTTP ProxyAn intermediary that forwards HTTP requests.
  • HTTP/1.1The text-based HTTP version with one request at a time per connection.
  • HTTP/2Binary framing and many requests multiplexed over one connection.
  • Long PollingHolding a request open until the server has news.
  • multipart/form-dataThe encoding used to upload files from forms.
  • OriginScheme + host + port: the browser's security boundary.
  • Preflight RequestThe OPTIONS request a browser sends before certain cross-origin calls.
  • Reverse ProxyA server in front of your app that handles TLS, routing and caching.
  • Safe and Idempotent MethodsWhich HTTP methods shouldn't change state, and which can be retried safely.
  • Same-Origin PolicyThe browser rule that isolates content from different origins.
  • Server-Sent EventsA one-way stream of events from server to browser over HTTP.
  • Synchronous vs Asynchronous APIsReturning the result in the response vs accepting work and reporting later.
  • Webhooks vs PollingBeing notified when something changes vs repeatedly asking.
  • WebSocketA persistent, two-way connection between browser and server.

Senior

Own a system, its failure modes, and its trade-offs.

Staff

Shape how many teams build, across systems.

Nothing here yet.

Principal

Set technical direction for the organization.

Nothing here yet.

Data Analyst track

Junior

Write correct SQL, build trusted dashboards, ask good questions.

  • HTTPThe request-response protocol of the web.
  • HTTP Status CodesThree-digit codes grouped 1xx–5xx describing the result.
  • Query StringKey-value parameters after the ? in a URL.
  • URLThe address of a resource: scheme, host, path, query and fragment.

Mid-level

Own an analysis end to end, from vague question to recommendation.

  • HTTP MethodsGET, POST, PUT, PATCH, DELETE and what each one means.

Senior

Own experimentation and metrics design; call out bad numbers.

Nothing here yet.

Staff

Shape how the organization measures and decides.

Nothing here yet.

Principal

Set measurement strategy across the company.

Nothing here yet.

Data Engineer track

Junior

Build and fix pipelines from clear specs; write correct SQL.

Mid-level

Own pipelines and models end to end, including their quality.

Senior

Design the platform's storage, processing and modeling choices.

Staff

Shape how the whole organization produces and uses data.

Nothing here yet.

Principal

Set data strategy and architecture across the company.

Nothing here yet.

Frontend Engineer track

Junior

Build UI that works, ship small changes safely, ask good questions.

Core: start here

  • CookieA small piece of data the server asks the browser to store and send back automatically on later requests.
  • CORSCross-Origin Resource Sharing: how a server lets browsers call it from other origins.
  • HTTPThe request-response protocol of the web.
  • HTTP MethodsGET, POST, PUT, PATCH, DELETE and what each one means.
  • HTTP Status CodesThree-digit codes grouped 1xx–5xx describing the result.
  • HTTPSHTTP encrypted with TLS.
  • Path vs Query Parameters/users/42 vs /users?id=42, and when to use each.
  • Same-Origin PolicyThe browser rule that isolates content from different origins.
  • URLThe address of a resource: scheme, host, path, query and fragment.
13 more junior concepts

Mid-level

Own a feature end to end without hand-holding.

Core: start here

  • HTTP CachingCache-Control, ETag and Last-Modified for reusing responses.
18 more mid-level concepts
  • Cache-ControlThe header that directs how responses may be cached.
  • Content NegotiationClient and server agreeing on format and language through Accept headers.
  • ETagA version identifier used for conditional requests and caching.
  • HSTSA header telling browsers to always use HTTPS for a site.
  • HTTP Compressiongzip and Brotli shrinking responses on the wire.
  • HTTP ProxyAn intermediary that forwards HTTP requests.
  • HTTP/1.1The text-based HTTP version with one request at a time per connection.
  • HTTP/2Binary framing and many requests multiplexed over one connection.
  • Long PollingHolding a request open until the server has news.
  • multipart/form-dataThe encoding used to upload files from forms.
  • Preflight RequestThe OPTIONS request a browser sends before certain cross-origin calls.
  • Reverse ProxyA server in front of your app that handles TLS, routing and caching.
  • Safe and Idempotent MethodsWhich HTTP methods shouldn't change state, and which can be retried safely.
  • Server-Sent EventsA one-way stream of events from server to browser over HTTP.
  • Synchronous vs Asynchronous APIsReturning the result in the response vs accepting work and reporting later.
  • WebhookAn HTTP callback: a service calls your URL when something happens.
  • Webhooks vs PollingBeing notified when something changes vs repeatedly asking.
  • WebSocketA persistent, two-way connection between browser and server.

Senior

Own an app's architecture, performance, and failure modes.

Staff

Shape how many teams build, across apps.

Nothing here yet.

Principal

Set technical direction for the organization.

Nothing here yet.