PHP
Syntax
PHP executes statements inside PHP tags; statements end with semicolons.
QUICK LOOKUP / PRACTICAL PATTERNS
Exact syntax. Short explanations. Common pitfalls.
Start with the assessment workflow →
150 references
PHP
PHP executes statements inside PHP tags; statements end with semicolons.
PHP
PHP has scalar, compound, and special types.
PHP
Variables begin with $ and can hold different values over time.
PHP
Arrays are ordered key/value maps.
PHP
Filter selects values; sorting changes their order.
PHP
Strings contain bytes; concatenation uses a dot.
PHP
Functions give a named operation explicit inputs and a return value.
PHP
Classes combine behavior with state.
PHP
An interface defines a contract that implementations must satisfy.
PHP
Traits reuse method implementations across classes.
PHP
Enums define a closed set of named values.
PHP
A constructor initializes an object; promotion declares and assigns properties.
PHP
public, protected, and private control access to members.
PHP
Static members belong to the class rather than an instance.
PHP
Exceptions interrupt execution until caught; Throwable covers Error and Exception.
PHP
Namespaces avoid name collisions and organize symbols.
PHP
Closures are anonymous functions that can capture outer values.
PHP
Arrow functions express one expression and capture outer variables by value.
PHP
Parameter, property, and return types express allowed values.
PHP
?? supplies a default for absent/null values; ?-> stops a chain on null.
PHP
match returns a value using strict comparisons.
PHP
Standard functions handle common collection, JSON, date, and validation tasks.
PHP
PDO provides parameterized database access in plain PHP.
Laravel
Laravel separates routes, HTTP handling, models, views, and database changes.
Laravel
Artisan is Laravel’s command-line interface.
Laravel
Routes map HTTP methods and paths to handlers.
Laravel
Controllers coordinate HTTP input, application actions, and responses.
Laravel
Request provides input, headers, files, and authenticated identity.
Laravel
A Form Request packages authorization and validation.
Laravel
Validation checks input shape, bounds, and allowed values.
Laravel
An Eloquent model maps a table to application behavior.
Laravel
Eloquent offers model-based query and persistence methods.
Laravel
Relationships describe model associations.
Laravel
The query builder builds parameterized SQL without full models.
Laravel
Migrations version database schema changes.
Laravel
Seeders insert known initial or development data.
Laravel
Factories create variable test fixtures.
Laravel
A transaction groups changes into an atomic database unit.
Laravel
Middleware inspects requests before/after the handler.
Laravel
Authentication establishes who is making the request.
Laravel
Authorization decides whether the actor may perform this operation.
Laravel
Policies group authorization rules for a model.
Laravel
Laravel’s container supplies concrete constructor or method dependencies.
Laravel
A service holds a cohesive business operation outside HTTP concerns.
Laravel
Configuration centralizes application settings.
Laravel
Environment files provide deployment-specific settings.
Laravel
Logging records diagnostic events with useful context.
Laravel
Laravel translates uncaught exceptions into HTTP responses.
Laravel
Resources define explicit serialization independent of storage.
Laravel
Responses contain a status, headers, and a body.
Laravel
Laravel JSON responses set the content type and encode data.
Laravel
Pagination bounds query results and supports navigation.
Laravel
Queues run deferred work outside the request.
Laravel
Caching reuses derived data for a bounded time.
Laravel
Feature tests exercise HTTP and persistence; unit tests isolate rules.
SQL
SELECT projects columns from rows.
SQL
INSERT creates rows.
SQL
UPDATE changes matching rows.
SQL
DELETE removes matching rows.
SQL
WHERE filters individual rows before grouping.
SQL
JOIN combines rows using related keys.
SQL
GROUP BY collects rows for aggregate calculations.
SQL
ORDER BY defines result ordering.
SQL
LIMIT bounds rows returned.
SQL
Aggregates compute count, sum, min, max, or average.
SQL
A subquery nests a query inside another query.
SQL
Constraints enforce integrity independently of application code.
SQL
A primary key uniquely identifies a row.
SQL
Foreign keys require referenced records to exist.
SQL
Unique constraints prevent duplicate keys at the database boundary.
SQL
Indexes accelerate selected reads at a write/storage cost.
SQL
Transactions commit or roll back a set of writes.
SQL
Isolation controls how concurrent transactions observe/interfere with each other.
SQL
ACID means atomicity, consistency, isolation, and durability.
HTTP / API
Methods communicate the operation’s intended semantics.
HTTP / API
Status codes summarize the HTTP outcome.
HTTP / API
HTTP messages carry headers and an optional body.
HTTP / API
REST-style interfaces use resource URLs and HTTP semantics.
HTTP / API
JSON is a text format for structured data.
HTTP / API
API authentication establishes an actor from trusted credentials.
HTTP / API
API authorization restricts records and operations for the actor.
HTTP / API
Paginated APIs return bounded data and navigation information.
HTTP / API
A predictable error envelope helps clients handle failure safely.
HTTP / API
Idempotency means repeating an operation has the same intended effect.
HTTP / API
API validation rejects malformed shape and invalid fields.
Security
Validation constrains data shape, ranges, and allowed values.
Security
Injection happens when input changes SQL structure instead of remaining data.
Security
XSS lets attacker-controlled text execute as script in a browser.
Security
CSRF exploits browser credentials on unwanted cross-site mutations.
Security
Authentication identifies the actor; authorization determines permitted actions.
Security
Secure authentication verifies credentials and manages sessions safely.
Security
RBAC assigns capabilities via roles, combined with resource scope.
Security
Password hashes allow verification without storing plaintext.
Security
Sessions associate a browser with authenticated server-side state.
Security
Rate limits bound abusive request frequency.
Security
Mass assignment writes many model attributes from an array.
Security
Response headers can reduce browser-side exposure.
Security
Secrets include credentials, tokens, and encryption keys.
Security
Security logs record relevant events without unnecessary sensitive data.
Security
Audit records document who did what, when, and to which entity.
Security
Least privilege grants only the access necessary for a task.
Security
Safe errors reveal useful client information without internal details.
Security
Uploads introduce untrusted bytes, names, and storage paths.
Security
ISO/IEC 27001 concerns an organizational information security management system.
Engineering
Requirements describe outcomes, rules, and constraints.
Engineering
Domain models name business concepts and their behavior.
Engineering
Entities have stable identity through changing attributes.
Engineering
Schema design makes relationships and integrity explicit.
Engineering
Architecture organizes responsibilities and dependencies.
Engineering
Separate HTTP, business rules, storage, and presentation responsibilities.
Engineering
SOLID encourages cohesive responsibilities and replaceable collaborators.
Engineering
Error handling distinguishes invalid input, conflicts, and unexpected failure.
Engineering
Logs explain execution and failure in operational terms.
Engineering
Tests prove requirements, invariants, and failure behavior.
Engineering
Concurrency means operations overlap and can act on stale state.
Engineering
A transaction boundary defines which database changes succeed together.
Engineering
Reliability means preserving correct outcomes despite expected failures.
Engineering
Observability uses logs, metrics, and traces to explain system behavior.
Assessment Methodology
Restate requested outcomes. Mark must-have behavior and acceptance criteria.
Assessment Methodology
List who interacts with the system: customer, administrator, operator, external provider.
Assessment Methodology
Write actor + action + outcome. Cover reads and mutations, not only creation.
Assessment Methodology
Name persistent identities and value objects; describe relationships.
Assessment Methodology
Turn prose into invariants: bounds, ownership, valid states, currency, duplicate behavior.
Assessment Methodology
Record time, language, database, offline requirements, scale, and forbidden dependencies.
Assessment Methodology
Choose primary/foreign keys, nullability, uniqueness, indexes, retention, and amounts.
Assessment Methodology
Define input, output, status codes, authorization, and errors for each use case.
Assessment Methodology
Use routes, controllers, models, and focused services only when warranted.
Assessment Methodology
Check validation, identity, permissions, encoding, secrets, audit needs, and least privilege.
Assessment Methodology
List missing records, invalid state, insufficient funds, duplicates, database failures, and unknown outcomes.
Assessment Methodology
Complete one vertical path with validation, persistence, response, and tests before extras.
Assessment Methodology
Prove each acceptance criterion with realistic data and expected persisted results.
Assessment Methodology
Check zero, negative, maximum, missing, malformed, unauthorized, duplicate, and concurrent inputs.
Assessment Methodology
Recheck every mutation and read boundary; inspect raw SQL, mass assignment, errors, and logs.
Assessment Methodology
Check naming, responsibilities, duplication, configuration, and whether the next reader can follow the flow.
Assessment Methodology
State assumptions, choices, limitations, alternatives, and what you would change with more time.
Financial-system patterns
Integer minor units avoid common binary floating-point representation errors.
Financial-system patterns
Explicit states distinguish pending, successful, failed, and unknown outcomes.
Financial-system patterns
Atomic operations either apply completely or have no effect.
Financial-system patterns
Database transactions group related local financial writes.
Financial-system patterns
Persisted idempotency prevents a repeated logical request from producing a second effect.
Financial-system patterns
Duplicate handling defines behavior when the same action arrives again.
Financial-system patterns
Financial audit records should explain state changes with actor and correlation data.
Financial-system patterns
Immutable financial history is amended with new compensating records.
Financial-system patterns
Reconciliation compares independent records and surfaces discrepancies.
Financial-system patterns
Financial authorization checks ownership, capabilities, limits, and separation of duties.
Financial-system patterns
Concurrent financial operations can both act on an old balance.
Financial-system patterns
Optimistic locking updates only if a version has not changed.
Financial-system patterns
Pessimistic locking holds database locks while checking and changing state.
Financial-system patterns
Consistency preserves invariants across records and systems.
Financial-system patterns
Financial failure handling distinguishes rejected, failed, and unknown outcomes.