What is GraphQL? Is it a replacement for the REST API?
The diagram below explains different aspects of GraphQL.
GraphQL is a query language for APIs and a runtime for executing those queries by using a type system you define for your data. It was developed internally by Meta in 2012 before being publicly released in 2015.
Unlike the more traditional REST API, GraphQL allows clients to request exactly the data they need, making it possible to fetch data from multiple sources with a single query. This efficiency in data retrieval can lead to improved performance for web and mobile applications.
GraphQL servers sit in between the client and the backend services. It can aggregate multiple REST requests into one query. GraphQL server organizes the resources in a graph.
GraphQL supports queries, mutations (applying data modifications to resources), and subscriptions (receiving notifications on schema modifications).
Benefits of GraphQL:
1. GraphQL is more efficient in data fetching.
2. GraphQL returns more accurate results.
3. GraphQL has a strong type system to manage the structure of entities, reducing errors.
4. GraphQL is suitable for managing complex microservices.
Disadvantages of GraphQL
- Increased complexity.
- Over fetching by design
- Caching complexity
โ
Subscribe to our weekly newsletter to get a Free System Design PDF (158 pages): https://t.co/uc5M7CdXXC
Introducing Sora, our text-to-video model.
Sora can create videos of up to 60 seconds featuring highly detailed scenes, complex camera motion, and multiple characters with vibrant emotions.
https://t.co/YYpOAcrXQ3
Prompt: โBeautiful, snowy Tokyo city is bustling. The camera moves through the bustling city street, following several people enjoying the beautiful snowy weather and shopping at nearby stalls. Gorgeous sakura petals are flying through the wind along with snowflakes.โ
Software Testing Basics
Testing is crucial in software development to verify applications operate as expected, meet requirements, and run reliably. Key testing methods:
1. Unit Testing: Validates individual code components in isolation to ensure they function properly.
2. Integration Testing: Verifies that different system components and modules interconnect and interact correctly.
3. System Testing: Evaluates the complete system against business and technical requirements. Confirms overall system functionality.
4. Load Testing: Examines system performance under anticipated peak usage levels to uncover bottlenecks.
5. Error Testing: Deliberately inputs invalid data to verify appropriate error handling and recovery.
6. Test Automation: Uses scripts to automate execution of test suites. Improves efficiency, consistency, and coverage.
Over to you: What approaches do you take when testing functionality in your software projects? Do you emphasize any specific testing methods or focus areas?
โ
Subscribe to our weekly newsletter to get a Free System Design PDF (158 pages): https://t.co/kNfv0DVDdf
What is the best way to learn SQL?
In 1986, SQL (Structured Query Language) became a standard. Over the next 40 years, it became the dominant language for relational database management systems. Reading the latest standard (ANSI SQL 2016) can be time-consuming. How can I learn it?
There are 5 components of the SQL language:
- DDL: data definition language, such as CREATE, ALTER, DROP
- DQL: data query language, such as SELECT
- DML: data manipulation language, such as INSERT, UPDATE, DELETE
- DCL: data control language, such as GRANT, REVOKE
- TCL: transaction control language, such as COMMIT, ROLLBACK
For a backend engineer, you may need to know most of it. As a data analyst, you may need to have a good understanding of DQL. Select the topics that are most relevant to you.
Over to you: What does this SQL statement do in PostgreSQL: โselect payload->ids->0 from eventsโ?
โ
Subscribe to our weekly newsletter to get a Free System Design PDF (158 pages): https://t.co/uc5M7CdXXC
This week we will cover:
โ SQL execution order
โ Edge computing vs cloud computing
โ DNS lookup
โ Serverless architecture best practices & pitfalls
Donโt want to miss out? Subscribe to our free newsletter for a weekly deep dive & content roundup: https://t.co/o8ShggS5mk
How SQL injections work, and how to protect your system from them.
SQL injection is a type of attack where the attacker runs damaging SQL commands by inserting malicious SQL code into an application input field or URL.
For example, imagine an app that returns all your information after logging in. That query may look like the following:
SELECT * FROM users
WHERE username = 'USER_INPUT';
If an attacker were to submit a malicious input, the query could change to the following:
SELECT * FROM users
WHERE username = '' OR '1'='1';
This query will return all users as '1'='1' will always return true.
๐ฌ๐ผ๐ ๐ฐ๐ฎ๐ป ๐ฝ๐ฟ๐ผ๐๐ฒ๐ฐ๐ ๐๐ผ๐๐ฟ ๐๐๐๐๐ฒ๐บ ๐ณ๐ฟ๐ผ๐บ ๐ฆ๐ค๐ ๐ถ๐ป๐ท๐ฒ๐ฐ๐๐ถ๐ผ๐ป ๐ฏ๐ ๐ฑ๐ผ๐ถ๐ป๐ด ๐๐ต๐ฒ ๐ณ๐ผ๐น๐น๐ผ๐๐ถ๐ป๐ด:
๐ญ. ๐จ๐๐ฒ ๐ฝ๐ฟ๐ฒ๐ฝ๐ฎ๐ฟ๐ฒ๐ฑ ๐๐๐ฎ๐๐ฒ๐บ๐ฒ๐ป๐๐ ๐ผ๐ฟ ๐ฝ๐ฎ๐ฟ๐ฎ๐บ๐ฒ๐๐ฒ๐ฟ๐ถ๐๐ฒ๐ฑ ๐พ๐๐ฒ๐ฟ๐ถ๐ฒ๐
User input cannot be executed because prepared statements and parameterized queries ensure a distinct separation between user input and SQL code.
๐ฎ. ๐ฉ๐ฎ๐น๐ถ๐ฑ๐ฎ๐๐ฒ ๐ฎ๐ป๐ฑ ๐ฐ๐น๐ฒ๐ฎ๐ป ๐ถ๐ป๐ฝ๐๐๐
Use expected formats and constraints to validate user input, and clean inputs to get rid of characters that may be interpreted as SQL code.
๐ฏ. ๐๐ผ๐น๐น๐ผ๐ ๐๐ต๐ฒ ๐น๐ฒ๐ฎ๐๐ ๐ฝ๐ฟ๐ถ๐๐ถ๐น๐ฒ๐ด๐ฒ ๐ฝ๐ฟ๐ถ๐ป๐ฐ๐ถ๐ฝ๐น๐ฒ
Limit the permissions for database accounts used by applications and services to only what is required for their functionality. This limits the system's vulnerability to SQL injection attacks.
๐ฐ)ย ๐ฆ๐ฒ๐ ๐ช๐ฒ๐ฏ ๐๐ฝ๐ฝ๐น๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป ๐๐ถ๐ฟ๐ฒ๐๐ฎ๐น๐น๐ (๐ช๐๐)
By setting up WAFs, common threats and attacks from HTTP/S traffic like SQL injections can be identified and blocked before they ever reach your application.
Learn more about API security here: https://t.co/nAmhUfSNvV
~~~
A big thank you to our partner Postman who keeps our content free to the community.
๐ฉย If you found this helpful, consider subscribing to our newsletter where we help you level up your engineering and system design skills: https://t.co/076cpzUaQo
Git Merge vs. Rebase vs. Squash Commit!
What are the differences?
When we ๐ฆ๐๐ซ๐ ๐ ๐๐ก๐๐ง๐ ๐๐ฌ from one Git branch to another, we can use โgit mergeโ or โgit rebaseโ. The diagram below shows how the two commands work.
๐๐ข๐ญ ๐๐๐ซ๐ ๐
This creates a new commit Gโ in the main branch. Gโ ties the histories of both main and feature branches.
Git merge is ๐ง๐จ๐ง-๐๐๐ฌ๐ญ๐ซ๐ฎ๐๐ญ๐ข๐ฏ๐. Neither the main nor the feature branch is changed.
๐๐ข๐ญ ๐๐๐๐๐ฌ๐
Git rebase moves the feature branch histories to the head of the main branch. It creates new commits Eโ, Fโ, and Gโ for each commit in the feature branch.
The benefit of rebase is that it has ๐ฅ๐ข๐ง๐๐๐ซ ๐๐จ๐ฆ๐ฆ๐ข๐ญ ๐ก๐ข๐ฌ๐ญ๐จ๐ซ๐ฒ.
Rebase can be dangerous if โthe golden rule of git rebaseโ is not followed.
๐๐ก๐ ๐๐จ๐ฅ๐๐๐ง ๐๐ฎ๐ฅ๐ ๐จ๐ ๐๐ข๐ญ ๐๐๐๐๐ฌ๐
Never use it on public branches!
--
Subscribe to our weekly newsletter to get a Free System Design PDF (158 pages): https://t.co/4QcX8btXGL
How do Search Engines Work?
The diagram below shows a high-level walk-through of a search engine.
โถ๏ธ Step 1 - Crawling
Web Crawlers scan the internet for web pages. They follow the URL links from one page to another and store URLs in the URL store. The crawlers discover new content, including web pages, images, videos, and files.
โถ๏ธ Step 2 - Indexing
Once a web page is crawled, the search engine parses the page and indexes the content found on the page in a database. The content is analyzed and categorized. For example, keywords, site quality, content freshness, and many other factors are assessed to understand what the page is about.
โถ๏ธ Step 3 - Ranking
Search engines use complex algorithms to determine the order of search results. These algorithms consider various factors, including keywords, pages' relevance, content quality, user engagement, page load speed, and many others. Some search engines also personalize results based on the user's past search history, location, device, and other personal factors.
โถ๏ธ Step 4 - Querying
When a user performs a search, the search engine sifts through its index to provide the most relevant results.
--
Subscribe to our weekly newsletter to get a Free System Design PDF (158 pages): https://t.co/uc5M7CdXXC
10 Good Coding Principles to improve code quality.
Software development requires good system designs and coding standards. We list 10 good coding principles in the diagram below.
๐น 01 Follow Code Specifications
When we write code, it is important to follow the industry's well-established norms, like โPEP 8โ, โGoogle Java Styleโ, adhering to a set of agreed-upon code specifications ensures that the quality of the code is consistent and readable.
๐น 02 Documentation and Comments
Good code should be clearly documented and commented to explain complex logic and decisions, and comments should explain why a certain approach was taken (โWhyโ) rather than what exactly is being done (โWhatโ). Documentation and comments should be clear, concise, and continuously updated.
๐น 03 Robustness
Good code should be able to handle a variety of unexpected situations and inputs without crashing or producing unpredictable results. Most common approach is to catch and handle exceptions.
๐น 04 Follow the SOLID principle
โSingle Responsibilityโ, โOpen/Closedโ, โLiskov Substitutionโ, โInterface Segregationโ, and โDependency Inversionโ - these five principles (SOLID for short) are the cornerstones of writing code that scales and is easy to maintain.
๐น 05 Make Testing Easy
Testability of software is particularly important. Good code should be easy to test, both by trying to reduce the complexity of each component, and by supporting automated testing to ensure that it behaves as expected.
๐น 06 Abstraction
Abstraction requires us to extract the core logic and hide the complexity, thus making the code more flexible and generic. Good code should have a moderate level of abstraction, neither over-designed nor neglecting long-term expandability and maintainability.
๐น 07 Utilize Design Patterns, but don't over-design
Design patterns can help us solve some common problems. However, every pattern has its applicable scenarios. Overusing or misusing design patterns may make your code more complex and difficult to understand.
๐น 08 Reduce Global Dependencies
We can get bogged down in dependencies and confusing state management if we use global variables and instances. Good code should rely on localized state and parameter passing. Functions should be side-effect free.
๐น 09 Continuous Refactoring
Good code is maintainable and extensible. Continuous refactoring reduces technical debt by identifying and fixing problems as early as possible.
๐น 10 Security is a Top Priority
Good code should avoid common security vulnerabilities. Especially code for financial applications must be free from SQL injection, cross-site scripting (XSS) and data leakage.
--
Subscribe to our newsletter to download the ๐ก๐ข๐ ๐ก-๐ซ๐๐ฌ๐จ๐ฅ๐ฎ๐ญ๐ข๐จ๐ง ๐๐ข๐๐ ๐ซ๐๐ฆ. After signing up, find the download link on the success page: https://t.co/m5hPsHqeSd
How do we incorporate Event Sourcing into the systems?
Event sourcing changes the programming paradigm from persisting states to persisting events. The event store is the source of truth. Let's look at three examples.
1. New York Times
The newspaper website stores every article, image, and byline since 1851 in an event store. The raw data is then denormalized into different views and fed into different ElasticSearch nodes for website searches.
2. CDC (Change Data Capture)
A CDC connector pulls data from the tables and transforms it into events. These events are pushed to Kafka and other sinks consume events from Kafka.
3. Microservice Connector
We can also use event event-sourcing paradigm for transmitting events among microservices. For example, the shopping cart service generates various events for adding or removing items from the cart. Kafka broker acts as the event store, and other services including the fraud service, billing service, and email service consume events from the event store. Since events are the source of truth, each service can determine the domain model on its own.
Over to you: Have you used event sourcing in production?
โ
Subscribe to our weekly newsletter to get a Free System Design PDF (158 pages): https://t.co/uc5M7CdXXC