Cheat Sheet
| Question | Core Idea | Senior Signal |
|---|---|---|
| Q261 | Secure APIs | Validate input, enforce ownership server-side, shape responses intentionally, and make risky mutations idempotent. |
| Q262 | OIDC + PKCE | Use authorization code with PKCE, verify state and nonce, and avoid long-lived browser-readable tokens. |
| Q263 | Refresh | Deduplicate refresh calls, retry once, sync logout across tabs, and separate expired from forbidden states. |
| Q264-Q265 | Permissions and embeds | Ask for powerful APIs after intent, sandbox embeds, validate postMessage origins and payloads. |