← HTTP/HTTPS: applications and diagnosis
08 / 8 · 60 MIN

Redirects and transfer integrity

Compare the actual request, HTTP status and byte completeness before declaring a job recovered.

Observe the complete chain

A final 200 does not describe the journey by itself. The client may have sent POST to an operation, received Location and then requested a receipt or login page. Record statuses and targets per hop, the method and fields needed to explain the difference. With real data, bound collection and avoid publishing credentials. In the lab, every body is fictional and server events allow comparison of what actually reached each endpoint, rather than inferring the request solely from the initial command.

Compare 303 and 307 using a controlled body

The runner sends amount=7 using --data-binary and follows redirects using -L. For 303, it observes POST with a body followed by GET without that body. For 307, it observes POST with the same body at both endpoints. This confirms client choice on that path. It does not demonstrate exactly-once business execution: the contract must explain effects at the first endpoint and destination. Before replacing a redirect code to fix an integration, check whether the change could resend an action that already took effect.

The effect of forcing the method

Adding -X POST looks redundant but changes the observed 303 result. In this curl 8.7.1, the second request keeps the word POST and drops the initial body. The receipt therefore receives an empty POST, neither a GET nor a complete replay of the submission. The manual explains that -X changes the method word without redefining all client behavior. Compare events before increasing buffers or blaming network loss. New options in the current manual must not be assumed available in the installed version.

Separate HTTP failure from transfer failure

The maintenance endpoint sends 503 and a short body. Without a special option, curl exits zero; with --fail-with-body it exits 22 and retains content. In another test, the server sends 200, declares ten bytes and closes after abc. The client exits 18 because the transfer is incomplete. These are different problems: a service can correctly communicate unavailability, while another response begins successfully and fails during the body. Monitoring needs HTTP status, exit code and functional criteria, with bounded content handling.

Do not publish an artifact before validating it

In a file pipeline, writing directly to the path consumed by the next step exposes partial bytes. Prepare a temporary area, validate the transfer result and agreed file criteria, and only then publish the artifact. Do not append the next response to the partial file without a resumption mechanism checking version and range. The exercise does not implement a universal checksum or atomic-publication policy; it asks you to identify controls required by the consumer contract. A 200 alone does not meet that contract.

Limits, versions and experiment conclusion

The /loop cycle ends with exit 47 after a limit of two redirects, totaling three requests. That limit bounds the experiment; correction requires investigating Location and the rule creating the cycle. Overall, nine observations were executed using curl 8.7.1 and HTTP/1.1 on loopback. The consulted manual identifies 8.23.0. TLS, HTTP/2, HTTP/3, NGINX and browser caches were not executed, nor were requests made to real systems. Local evidence helps formulate authorized tests but does not replace production-path validation.

# Re-run the isolated fixture:
python3 content/labs/http-conditions/run.py
# redirect303: POST(body) -> GET(empty)
# redirect307: POST(body) -> POST(body)
# forcedMethod: POST(body) -> POST(empty)
# partialTransfer: HTTP 200, curl exit 18
IN PRACTICE

Fictional case: a download returns 200 but closes before completing Content-Length. The job keeps the partial file outside the published path, records exit 18 and recovers a complete copy before reconciliation.

Common pitfalls

Avoid habitual -X use, POST replay without a contract, unbounded loops and accepting a partial file merely because the first header said 200.

Related topics: Methods, statuses, and controlled retries · Caching, variants, and validation · Diagnosis and time budgets

Take this idea with you

Useful evidence includes what reached each target and what remained usable at the end, with client version and options recorded.

Create account

Reference: curl command-line manual · BigSavant HTTP/HTTPS 2026-09; HTTP RFCs 9110–9114; selected TLS 1.3 and NGINX/curl guidance