Design a URL Shortener, stage 7 of 9: break it
Take down a malicious link everywhere
The database now says the link is disabled. But the redirect has been copied to other places.
System so far· 8 parts
Select a component to see what it is responsible for and which state it owns.
- 1Clickers → CDN edge: GET /aZ3kQ9x
- 2CDN edge → Redirect service: Cache miss
- 3Redirect service → Postgres: Look up code
- 4Customer dashboard → Links API: Create, edit, disable
- 5Links API → Postgres: Insert with unique code
- 6Redirect service → Click stream: Click event (fire and forget)
- 7Click aggregator → Click stream: Read click batches
- 8Click aggregator → Postgres: Upsert daily aggregates
- Request / response
- Asynchronous
What you need to know
0 of 2 checks done
Think first
List every place a copy of this redirect might still exist after the database row is disabled.A CDN purge removes a URL from its edge servers, usually within seconds. A short TTL is the backup: if a purge fails or misses a server, the copy still expires soon.
Work it out
The link gets 200,000 clicks an hour. With no purge and a 60-second CDN TTL, about how many more clicks could still reach the malware in the worst case?