NETWORK FOUNDATIONS · 09
HTTP / HTTPS:連線建立後,Client 與 Server 怎麼交換意思
HTTP 是 application protocol:method、path、headers、body、status。HTTPS 則是在 HTTP 通訊外加入 TLS 提供傳輸加密與 server identity verification 等安全層。
Learning outcomes
- 能拆 request 的 method/path/headers/body。
- 能拆 response 的 status/headers/body。
- 能解釋 2xx/4xx/5xx 是不同 failure ownership。
- 能說明 HTTPS 與 HTTP 的關係。
1. Request
GET /courses HTTP/1.1
Host: example.com
Accept: application/jsonGET 是 method,/courses 是 target path;headers 帶 metadata。
2. Response
HTTP/1.1 200 OK
Content-Type: application/json
[
{"id":1,"title":"JavaScript"}
]Status code 先告訴 client request outcome 類型,body 承載資料或錯誤內容。
3. Status Families
| Range | 概念 |
|---|---|
| 2xx | request 成功處理 |
| 3xx | redirect / conditional flow |
| 4xx | client request/auth/resource 類問題 |
| 5xx | server-side failure |
4. HTTP Error Response ≠ Network Failure
HTTP 404
→ 已經收到 server response
Connection refused
→ transport connection 沒建立
DNS failure
→ hostname 還沒解析成功這三種 evidence 落在不同層。
5. HTTPS / TLS
HTTP semantics
↓
TLS encryption + authentication
↓
transport/networkHTTPS 不會讓 server business logic 自動正確,也不代表 request body 可以繞過 authorization;它主要保護傳輸通道與 server identity。
Project checkpoint:Request Journey Map v9
GET https://example.com/courses
↓ DNS
destination
↓ connect :443
TLS
↓
HTTP GET /courses
↓
HTTP 200 + JSON
↓
Browser receives bodyDebug evidence:DevTools Network
最先看:Request URL、method、status、response body、timing。不要只有畫面顯示「載入失敗」就猜 backend。
Knowledge check
- 404 是否代表「沒有連到 server」?
- HTTP request 的四個主要構成?
- HTTPS 多出的核心安全層是什麼?
- 用 DevTools 找一個 request,指出 method/status/content-type。