Protective routes

Asked atBoston Consulting Group
1Give yourself 5 minutes
2Answer out loud, not in your head
3Then compare with the answer below
0
Stuck? Show a way to structure it+
  1. 01Clarify client versus server protection
  2. 02Identify identity and permissions
  3. 03Define deny and redirect behavior
  4. 04Enforce on the server
  5. 05Test direct URL access

Reference answer

Then expect these follow-ups

  • Why is a client guard insufficient?

    Tests: correctness reasoning

  • How would you prevent redirect loops?

    Tests: follow-up reasoning

Free to read · better with Enzo

Practice this out loud with Enzo

Enzo runs it as a mock interview, pushes back with follow-ups, and grades you on the rubric.

Next question