Skip to content

Design a URL Shortener, stage 3 of 9: break it

Debug: a customer got someone else's link

Use what you learned in the last stage. Find every line that can produce a wrong or shared code.

System so far· 5 parts
123CLIENTClickersSERVICERedirect serviceDATABASEPostgresSERVICELinks APICLIENTCustomerdashboard

Select a component to see what it is responsible for and which state it owns.

  1. 1Redirect service → Postgres: Look up code
  2. 2Customer dashboard → Links API: Create, edit, disable
  3. 3Links API → Postgres: Insert with unique code

What you need to know

0 of 1 checks done
  1. When reading code that creates something unique, ask three questions of every line:

    1. Where does the identity come from? Is it unique to this caller's thing, or could two callers produce the same one?
    2. What happens if it already exists? Is the existing thing really the caller's?
    3. What can happen between the check and the act? Another request can run in that gap.
  2. Check

    Two requests run findByCode(code) at the same moment, both get nothing back, and both call insert. Without a unique constraint on code, what's in the table?