Material

HTTP

Roadmap stageHTTP and API →

HTTP (Hypertext Transfer Protocol) is an application protocol for exchanging messages between clients and servers. It was originally created to transmit hypertext documents. In the OSI model, HTTP is classified as the application layer; in the TCP/IP stack - also to the application layer.

The HTTP protocol works on the principle client-server. The client application generates a request and sends it to the server, after which the server processes the request, generates a response and sends it back to the client. HTTP/1.1 request and response structures are similar: a start line, headers, and an optional message body.

  • The starting line of the request consists of the method, path and protocol version: GET /index.html HTTP/1.1 The starting line of the response consists of the protocol version, the response code and the text decryption of the response: HTTP/1.1 200 OK
  • Headers are a set of key-value pairs, e.g. Content-Type: text/html; charset=utf-8. The headers contain request/response metadata: user language, authorization, content type, etc.
  • The request or response body may be missing or contain text or binary data. In HTTP/1.1, it is separated from the headers by a blank line. The usual port for HTTP is 80, for HTTPS is 443. HTTPS is HTTP over TLS: TLS provides encryption, integrity, and server authentication. Today HTTP/1.1, HTTP/2 and HTTP/3 are used. HTTP/2 typically runs on top of TCP, while HTTP/3 runs on top of QUIC, which uses UDP. Features of HTTP/1.1:
  • persistent connections are used by default; title Connection: close reports that the connection should be closed after the response; HTTP/2 innovations:
  • binary framing: messages are transmitted as sequences of typed frames;
  • multiplexing: multiple request and response threads can use the same connection simultaneously;
  • header compression: HPACK format is used;
  • server push: The protocol allows for additional responses to be sent without a separate request, but browsers no longer support this feature as a practical optimization.

The HTTP/2 standard allows for operation without TLS, but modern browsers practically only use it over TLS.

HTTP methods

Scroll the table horizontally →

Method What does Endpoint example Safe Idempotent
POST sends data to the server /photos No No
PUT updates an existing resource, sometimes it can create a new one; you need to pass the full representation of the resource /photos/id No Yes
PATCH makes changes to a specific resource /photos/id No No
GET requests information /photos, /photos/id Yes Yes
HEAD identical to GET in semantics, but the server does not send the response body /photos, /photos/id Yes Yes
DELETE deletes a resource /photos/id No Yes
OPTIONS requests options for interaction with the target resource; often used for CORS preflight requests /photos Yes Yes
TRACE used to test and debug the connection between client and server /photos Yes Yes

Idempotency — a property of a method where the expected effect of several identical requests is the same as the effect of one request. Responses may differ. PATCH is not required to be idempotent, but a particular PATCH request can be designed to be idempotent.

Example request:

GET /index.html HTTP/1.1
Host: www.example.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: keep-alive
Upgrade-Insecure-Requests: 1

Example response:

HTTP/1.1 200 OK
Date: Mon, 27 Nov 2023 12:00:00 GMT
Server: Apache/2.4.29 (Unix)
Last-Modified: Wed, 01 Nov 2023 10:00:00 GMT
ETag: "a1f-5c001a1f364d8"
Accept-Ranges: bytes
Content-Type: text/html

<!DOCTYPE html>
<html>
<head>
    <title>Example Page</title>
</head>
<body>
    <h1>Hello, World!</h1>
    <p>This is an example page.</p>
</body>
</html>

Examples of response codes

  • 1xx - informational
  • 100 Continue - the request has been accepted and the client can continue sending requests
  • 101 Switching Protocols - sent in response to a client request containing the header Upgrade, and indicates that the server has switched to the agreed protocol
  • 2xx - successful
  • 200 OK - the request was processed successfully
  • 201 Created - the request completed and created one or more resources
  • 3xx - redirection
  • 304 Not Modified - a conditional GET or HEAD showed that the client's saved representation is still current
  • 307 Temporary Redirect - temporary redirect
  • 4xx - client error
  • 401 Unauthorized - authentication is required to obtain the requested response
  • 403 Forbidden - the client does not have permission to access the content
  • 404 Not Found - the server cannot find the requested resource
  • 5xx - server error
  • 500 Internal Server Error - the server encountered a situation it does not know how to handle
  • 504 Gateway Timeout - a server acting as a gateway or proxy did not receive a timely response from an upstream server

Primary sources

  • RFC 9110: HTTP Semantics
  • RFC 9112: HTTP/1.1
  • RFC 9113: HTTP/2
  • RFC 9114: HTTP/3
  • RFC 5789: PATCH Method for HTTP