1---2name: http3description: Use HTTP correctly with proper methods, status codes, headers, and caching.4---56## Redirects (Often Confused)78- 307 vs 308: both preserve method; 307 temporary, 308 permanent—use these for POST/PUT redirects9- 301/302 may change POST to GET (browser behavior)—don't use for API redirects with body10- Include `Location` header with absolute URL—relative may fail in older clients11- Redirect loops: limit to 5-10 follows; infinite loops crash clients1213## Caching Combinations1415- `Cache-Control: no-store` for sensitive data—never written to disk16- `no-cache` still caches but revalidates every time—not "don't cache"17- `private, max-age=0, must-revalidate` for user-specific, always-fresh content18- `public, max-age=31536000, immutable` for versioned static assets19- `Vary: Accept-Encoding, Authorization` when response depends on these headers—forgetting Vary breaks caching2021## Conditional Requests2223- `ETag` + `If-None-Match`: prefer for APIs—content hash based24- Strong vs weak ETags: `"abc"` vs `W/"abc"`—weak allows semantically equivalent responses25- `If-Match` for optimistic locking: fail update if resource changed since read26- 412 Precondition Failed when `If-Match` fails—not 409 Conflict2728## CORS Preflight Triggers2930- Custom headers (anything not Accept, Accept-Language, Content-Language, Content-Type simple values)31- Content-Type other than: application/x-www-form-urlencoded, multipart/form-data, text/plain32- PUT, DELETE, PATCH methods—even to same origin if other conditions met33- ReadableStream body—triggers preflight34- Preflight cached per `Access-Control-Max-Age`—set to 86400 to reduce OPTIONS spam3536## Security Headers (Always Set)3738- `Strict-Transport-Security: max-age=31536000; includeSubDomains`—HSTS, once set can't easily undo39- `X-Content-Type-Options: nosniff`—prevents MIME sniffing attacks40- `X-Frame-Options: DENY` or `SAMEORIGIN`—prevents clickjacking41- `Content-Security-Policy`—complex but essential; start with report-only mode4243## Range Requests4445- `Accept-Ranges: bytes` signals support—clients can request partial content46- `Range: bytes=0-1023` requests first 1024 bytes; `bytes=-500` requests last 50047- Return 206 Partial Content with `Content-Range: bytes 0-1023/5000`48- 416 Range Not Satisfiable if range invalid—include `Content-Range: bytes */5000`4950## Error Response Best Practices5152- Structured JSON errors: `{"error": {"code": "VALIDATION_FAILED", "message": "...", "details": [...]}}`53- Include request ID in error response—enables log correlation54- Don't leak stack traces in production—log server-side, return generic message55- 409 Conflict for business rule violations (duplicate email, insufficient funds)—not just 4005657## Retry Patterns5859- Retry only idempotent methods by default—GET, PUT, DELETE, HEAD60- POST retry needs idempotency key—`Idempotency-Key: <client-generated-uuid>`61- Exponential backoff: 1s, 2s, 4s, 8s... with jitter—prevents thundering herd62- Respect `Retry-After` header—can be seconds or HTTP date63- Set reasonable timeout (30s typical)—don't wait forever6465## Headers Often Forgotten6667- `Vary`: must include headers that affect response—CORS without `Vary: Origin` breaks68- `Content-Disposition: attachment; filename="report.pdf"` for downloads69- `X-Request-ID`: generate if not present, propagate to downstream services70- `Accept-Language` for localized responses—respect with graceful fallback7172## Connection Behavior7374- HTTP/1.1 without `Content-Length` or chunked = connection close after response75- `Transfer-Encoding: chunked` for streaming—can't set Content-Length76- HTTP/2 is binary, multiplexed—no head-of-line blocking at HTTP level77- WebSocket upgrade: GET with `Connection: Upgrade`, `Upgrade: websocket`