CodeZettaInterview Hub

JavaScript · Browser APIs · Tech Lead · Architecture

How would you choose a service worker caching strategy for an authenticated SPA?

Short Interview Answer

Cache static shell aggressively; use network-first or stale-while-revalidate for APIs carefully; never cache sensitive personalized responses without explicit rules.

Detailed Explanation

App shell: cache-first for hashed assets. API data: often network-first with fallback, or SWR for non-sensitive feeds. Auth: avoid caching private JSON in shared caches; respect `Cache-Control`; prefer session-bound strategies; beware multi-user browsers. Version caches and purge on activate. Handle updates (`skipWaiting` trade-offs) so users aren't stuck on old clients. Coordinate with backend ETags. Provide offline UX messaging. Lead discussion includes threat model (XSS reading cache), storage quotas, and rollback.

Interview Tip

Separate static assets from authenticated API policy.

Common Mistake

Cache-first for personalized API responses.

Did you know this answer?