API Design 1. 什么让一个 API 算 "RESTful"?实务中 teams 最常违反哪些 REST constraints?2. 哪些 HTTP methods 是 idempotent,为什么 idempotency 对 retry-safe 的 clients 重要?3. POST endpoint 创建 payment 或 order 时,你会怎么实现 idempotency keys?4. 什么时候返回 200 vs 201 vs 204?400 vs 401 vs 403 vs 404 vs 409 vs 422 呢?5. 比较 offset pagination 与 cursor-based pagination。为什么 offset 在大、频繁写入的 tables 上会退化?6. 设计一份一致的 error response format。见过 RFC 7807(Problem Details)吗,会采用吗?7. 比较 API versioning 策略(URL path、header、query param)。什么时候 versioning 真的必要,什么时候 additive 变更就能避开?8. Rate-limiting algorithms 有何不同(fixed window、sliding window、token bucket)?429 response 该带什么?9. REST vs GraphQL vs tRPC/RPC:各给一个它才是对的选择的具体场景。10. Endpoint 返回 nested resources 时,怎么避免 N+1 queries?Embed vs. link related resources —— tradeoffs?11. 比较 server-to-server APIs 的 API keys、OAuth 2.0 client credentials 与 JWT bearer tokens。12. 设计一套 webhook delivery 系统:signing、带 backoff 的 retries、ordering guarantees,以及 idempotent receivers。13. 怎么通过 HTTP 暴露一个 long-running operation(例如生成 report)?比较 202 + status polling vs. webhooks vs. WebSockets。14. PUT vs PATCH:语义差在哪,JSON Patch 与 JSON Merge Patch 又差在哪?15. ETag、Last-Modified 与 Cache-Control 如何启用 conditional requests 并省带宽?16. 你会怎么设计 API 里的 file upload/download —— multipart uploads vs. presigned S3 URLs?5MB vs 5GB 有什么变化?17. Multi-tenant API 里,tenant identity 该从哪来(subdomain、header、JWT claim),怎么保证 cross-tenant requests 被拒绝?18. Design-first(OpenAPI spec)vs code-first:tradeoffs,以及 contract testing 怎么卡进来?19. 怎么演进 API 而不打破可能永远不 update 的现有 mobile clients?20. Design exercise:一份 paginated、可 filter 的 audit-log API,给 multi-tenant healthcare SaaS,auditors 只能看见自己 tenant 的 data。 Backend Engineering 1. 走一遍 Node.js event loop 的 phases。setTimeout、setImmediate、process.nextTick 与已 resolve 的 promises 分别在哪跑?2. 什么时候不该选 Node.js?Node service 里怎么处理 CPU-bound 工作?3. 「stateless service」是什么意思,为什么它对 load balancer 后面的 horizontal scaling 重要?4. 什么时候该把 request 经 queue 异步处理,而不是在 request cycle 里同步做完?5. 解释 at-least-once 与 at-most-once delivery。给定 at-least-once semantics,怎么做一个 idempotent consumer?6. 给一个失败的 worker 设计 retry 策略:exponential backoff、jitter、max attempts 与 dead-letter queues。7. 比较 cache-aside、read-through、write-through 与 write-behind caching。什么是 cache stampede,怎么防止?8. 没有 distributed transactions,怎么让两个 services 的 state 保持 consistent?解释 saga 与 outbox patterns。9. 什么是 eventual consistency,怎么在它上面给用户 read-your-writes 行为?10. Application code 里的 optimistic vs pessimistic locking——各给一个具体例子。11. Database connection pool 怎么定大小?为什么 serverless / ECS-scale-out 架构会打爆 naive pooling,PgBouncer 怎么帮?12. Graceful shutdown 时发生什么?SIGTERM 上怎么 drain in-flight requests 与 queue consumers?13. 解释 observability 的三根支柱。Correlation IDs 怎么跨 services 与 queue hops 工作?14. Liveness vs readiness probes:各自该查什么?如果 readiness 去查 database 会出什么问题?15. 你在 4 个 ECS tasks 上跑 nightly cron job——怎么保证它 exactly once?16. Production 里 secrets 与 config 该怎么管理和 rotate?为什么纯 env vars 有时不够?17. 描述你的 backend testing 策略:unit vs integration vs e2e 各放什么,mocking 边界画在哪?18. 比较 shared-schema(tenant_id column)、schema-per-tenant 与 database-per-tenant multi-tenancy。到 1,000 个 tenants 时,operations 上会破什么?19. WebSockets vs SSE vs long polling——tradeoffs,以及怎么跨多个 server instances broadcast events?20. 设计练习:一个 webhook ingestion endpoint,必须扛住 10x traffic spike,既不丢 events 也不倒下。 Frontend Engineering 1. 什么会触发 React 的 re-render?解释 reconciliation,以及 list 里 key 的选择为什么重要。2. useEffect 正确的心智模型是什么?举出本应是 derived state 或 event handler 的 Effect 例子。3. useMemo 与 useCallback 什么时候真的有用,什么时候只是白加成本?4. 如何拆分 local state、server state 与 global client state?为什么 React Query / SWR 常常取代 Redux?5. React Server Components 如何改变 data fetching 与 bundle size?Next.js App Router 里 client/server boundary 在哪?6. 为营销页、药剂师 dashboard、面向患者的 prescription 页在 SSR、SSG、ISR 与 CSR 之间做选择。各自说明理由。7. 什么是 request waterfalls?如何 parallelize 或 hoist data fetching 来消除它们?8. 实现一次 optimistic update:mutation 失败时发生什么,如何干净地 roll back?9. Controlled vs uncontrolled form inputs:取舍是什么,如何让一份 50 字段的临床表单保持 performant?10. 解释 LCP、CLS 与 INP。各给出两个具体修复。11. 如何处理 bundle size:code splitting、route-level lazy loading,以及用 bundle analysis 找出该砍什么?12. 一张表必须流畅渲染 10,000 行——走一遍 list virtualization 及其取舍。13. Accessibility 在 ARIA 之外意味着什么?覆盖 semantic HTML、keyboard navigation,以及 modals 里的 focus management。14. Auth tokens 该放在哪——localStorage 还是 httpOnly cookies?把答案接到 XSS 与 CSRF 风险上。15. Service workers 与 Cache API 如何支持 offline?解释 stale-while-revalidate。16. Error boundaries 与 Suspense boundaries 如何组合?全局 error reporting 该收什么?17. 每一层测什么——unit(Vitest)、component(Testing Library)、e2e(Playwright)——以及你故意不测什么?18. 为共享 design system 设计一份 component API:props vs compound components、用 tokens theming、跨团队 versioning。19. 展示如何用 TypeScript generics 与 discriminated unions,安全地建模一份 fetch state machine(idle | loading | success | error)。20. 设计练习:一份实时 prescription-status dashboard,带 live updates、reconnection handling 与体面的 offline 行为。 Database 1. B-Tree index 内部怎么工作,为什么它让 equality 与 range lookups 变快?2. Composite index (tenant_id, status, created_at) 上,哪些 queries 能用它?解释 leftmost-prefix matching。3. 读这份 query plan:什么时候 sequential scan 其实比 index scan 更对?4. 给出 Postgres 忽略你 index 的四个原因(function on column、type mismatch、low selectivity、leading-wildcard LIKE)。5. 什么时候该伸手拿 GIN 而不是 B-Tree —— 例如 JSONB containment 或 full-text search?6. 简要解释 1NF–3NF,再给一个刻意 denormalize 才是对的 case。7. 走一遍四个 isolation levels,以及各自挡住的 read phenomena(dirty、non-repeatable、phantom)。Postgres 默认是什么?8. 为什么 long-running transactions 在 production 里危险(lock contention、vacuum bloat)?9. 两个 transactions 之间 deadlock 怎么发生,什么 coding practices 能防住?10. 怎么发现并修掉 N+1 queries —— joins、batching、DataLoader 式 patterns?11. 比较 SELECT ... FOR UPDATE 与 version-column optimistic lock。高 contention 的 inventory decrement 该用哪个?12. 为什么 connection pooling 重要,PgBouncer 的 transaction mode 与 session mode 差在哪?13. 设计一次 zero-downtime migration:给 1 亿行的 table 加一列带 default 的 NOT NULL column。为什么 indexes 要用 CONCURRENTLY?14. 为什么 OFFSET 100000 会变慢,keyset (cursor) pagination 在 SQL 层面怎么修?15. Streaming replication 怎么工作,read-replica lag 会给 read-your-writes 带来什么 bugs?16. Partitioning vs sharding:各自解决什么问题,一张 table 什么时候「够大」该 partition?17. OLTP vs OLAP:为什么要把 Postgres 数据 pipe 进 Redshift,而不是在 primary 上跑 analytics?18. 比较 Postgres Row-Level Security 与 application-level tenant filtering。各自的 failure modes 是什么?19. Soft delete vs hard delete:对 unique constraints、indexes(partial indexes)、以及 data-retention compliance 意味着什么。20. Design exercise:multi-tenant 药房系统的 schema —— prescriptions、不可变 audit trail、以及快的 per-tenant reporting。 Security 1. 解释 SQL injection 如何运作,以及为什么 parameterized queries 能修好它。ORMs 在哪些地方仍然会把你暴露出去?2. 比较 stored、reflected 与 DOM-based XSS。React 默认 escape 什么,什么时候 dangerouslySetInnerHTML 可以接受?3. CSRF 如何运作,SameSite cookies 与 CSRF tokens 如何缓解?JWT-in-localStorage 的 SPA 需要 CSRF 保护吗?4. Sessions vs JWTs:stateless tokens 如何处理 logout 与 revocation?解释 refresh token rotation。5. Passwords 应该怎么存?为什么 bcrypt/argon2 优于 SHA-256,salt 与 pepper 是什么?6. 走一遍带 PKCE 的 OAuth 2.0 authorization code flow。为什么 implicit flow 被 deprecated?7. 什么是 IDOR(broken object-level authorization),为什么它是经典的 multi-tenant 漏洞?怎么测?8. RBAC vs ABAC:为一家 pharmacy app 建模权限,pharmacists、admins 与 auditors 共用 endpoints。9. CORS 实际保护什么(以及不保护什么)?解释 preflight,以及把 Origin 连 credentials 一起 reflect 这类常见 misconfiguration。10. Content Security Policy 如何挡住 XSS?Nonce vs hash 策略,以及如何先用 report-only 推出 CSP?11. Secrets 如何漏进 client bundles 与 logs,什么 process/tooling 能挡住?12. 设计对抗 brute force 与 credential stuffing 的 login defenses:throttling、lockout、MFA、breached-password checks。13. Encryption at rest vs in transit:TLS 在你的架构里哪里 terminate,何时值得对 PHI 做 field-level encryption?14. 解释 SSRF,以及为什么 AWS metadata endpoint(169.254.169.254)是经典目标。如何缓解?15. 端到端保护一个 file-upload feature:type validation、storage isolation、malware scanning、presigned URLs、safe content disposition。16. 如何管理 npm dependencies 的 supply-chain risk —— lockfiles、audits、typosquatting、SBOMs?17. HSTS、frame-ancestors 与 Referrer-Policy headers 各自防什么?18. 对 HIPAA-style compliance,audit log 必须抓住什么,如何让它 tamper-evident?19. 点出 SQL 之外三种微妙的 cross-tenant data leaks:shared caches、queue messages、search indexes。各自如何隔离?20. Threat-modeling 练习:处方的 e-signature feature —— 找出前五个 threats,以及各自的 mitigation。 JavaScript (TypeScript) 1. var vs let vs const:hoisting、temporal dead zone,以及为什么 const 不是 deep immutability。2. 什么是 closure?给一个 production 用法和一个 leak。3. this 如何确定?Function vs arrow、call/apply/bind,以及 class fields vs prototype methods。4. Prototype chain vs class syntax。instanceof 何时失败?5. == vs === vs Object.is。NaN、-0 与 boxed primitives 如何表现?6. ToBoolean 与 ToPrimitive 如何在 APIs 里藏 bug —— plus、if (value),以及 query params?7. 语言里的 task vs microtask。queueMicrotask、Promise jobs 与 setTimeout 跑在哪里?8. Promise.all vs allSettled vs race vs any。Unhandled rejection 会发生什么?9. Sequential await vs Promise.all。Error handling、waterfalls 与 AbortSignal。10. Iterables、for...of vs for...in、generators,以及何时 async generator 是对的形状。11. ESM vs CommonJS:live bindings、default export interop、circular imports 与 tree-shaking。12. Shallow vs deep copy:spread、structuredClone,以及 JSON.parse(JSON.stringify) 的失败模式。13. 常见 JavaScript memory leaks:closures、timers、listeners 与无界 Maps。14. Structural typing vs nominal typing。Excess property checks,以及为什么经变量赋值会接受多余 fields。15. unknown vs any vs never vs void。16. TypeScript 如何 narrow:typeof、in、discriminated unions、type predicates 与 asserts?17. Generics、constraints、infer —— 以及何时 generic 不加任何安全。18. type vs interface、declaration merging,以及 mapped 或 conditional types。19. TypeScript 在 compile time 擦掉什么,为什么 HTTP 边界需要 Zod?20. Design exercise:一个 typed Result / Either,用于会失败的 parse-and-save path,带 exhaustive switch 且没有 any。 阅读下一篇笔记人生之诗