Design a URL Shortener, stage 3 of 9: break it
Debug: a customer got someone else's link
Use what you learned in the last stage. Find every line that can produce a wrong or shared code.
System so far· 5 parts
Select a component to see what it is responsible for and which state it owns.
- 1Redirect service → Postgres: Look up code
- 2Customer dashboard → Links API: Create, edit, disable
- 3Links API → Postgres: Insert with unique code
What you need to know
0 of 1 checks done
When reading code that creates something unique, ask three questions of every line:
- Where does the identity come from? Is it unique to this caller's thing, or could two callers produce the same one?
- What happens if it already exists? Is the existing thing really the caller's?
- What can happen between the check and the act? Another request can run in that gap.
Check
Two requests runfindByCode(code)at the same moment, both get nothing back, and both callinsert. Without a unique constraint on code, what's in the table?