InterviewDB
Experience
Desensitized URL: Strip PII and Sensitive Parameters from URLs for Safe Logging on Android
phone
Interview Experience
Problem
On a mobile client, URLs often contain sensitive data in query parameters (auth tokens, user IDs, emails). Write a function that strips or masks a configurable set of parameter names before the URL is written to logs.
kotlin
// Android (Kotlin)
fun desensitizeUrl(
url: String,
sensitiveKeys: Set<String> = setOf("token", "email", "uid", "password"),
mask: String = "***"
): String
Example:
desensitizeUrl("<a href="https://api.example.com/user?uid=42&token=abc123&page=2" target="_blank" rel="noopener" class="text-emerald-400 hover:text-emerald-300 underline">https://api.example.com/user?uid=42&token=abc123&page=2</a>")
-> "<a href="https://api.example.com/user?uid=***&token=***&page=2" target="_blank" rel="noopener" class="text-emerald-400 hover:text-emerald-300 underline">https://api.example.com/user?uid=***&token=***&page=2</a>"
desensitizeUrl("<a href="https://example.com/no-params" target="_blank" rel="noopener" class="text-emerald-400 hover:text-emerald-300 underline">https://example.com/no-params</a>")
-> "<a href="https://example.com/no-params" target="_blank" rel="noopener" class="text-emerald-400 hover:text-emerald-300 underline">https://example.com/no-params</a>"
Follow-ups
- How do you handle URL-encoded parameter values (e.g.,
email=user%40example.com)? - What edge cases arise with repeated parameters (e.g.,
tag=a&tag=b&token=x)? - How would you extend this to mask sensitive path segments (e.g.,
/users/{uid}/profile)? - Should you mask or omit sensitive parameters entirely? What are the trade-offs for debugging?
Full Details
Problem
On a mobile client, URLs often contain sensitive data in query parameters (auth tokens, user IDs, emails). Write a function that strips or masks a configurable set of parameter names before the URL is written to logs.
kotlin
// Android (Kotlin)
fun desensitizeUrl(
url: String,
sensitiveKeys: Set<String> = setOf("token", "email", "uid", "password"),
mask: String = "***"
): String
Example:
desensitizeUrl("<a href="https://api.example.com/user?uid=42&token=abc123&page=2" target="_blank" rel="noopener" class="text-emerald-400 hover:text-emerald-300 underline">https://api.example.com/user?uid=42&token=abc123&page=2</a>")
-> "<a href="https://api.example.com/user?uid=***&token=***&page=2" target="_blank" rel="noopener" class="text-emerald-400 hover:text-emerald-300 underline">https://api.example.com/user?uid=***&token=***&page=2</a>"
desensitizeUrl("<a href="https://example.com/no-params" target="_blank" rel="noopener" class="text-emerald-400 hover:text-emerald-300 underline">https://example.com/no-params</a>")
-> "<a href="https://example.com/no-params" target="_blank" rel="noopener" class="text-emerald-400 hover:text-emerald-300 underline">https://example.com/no-params</a>"
Follow-ups
- How do you handle URL-encoded parameter values (e.g.,
email=user%40example.com)? - What edge cases arise with repeated parameters (e.g.,
tag=a&tag=b&token=x)? - How would you extend this to mask sensitive path segments (e.g.,
/users/{uid}/profile)? - Should you mask or omit sensitive parameters entirely? What are the trade-offs for debugging?
Free preview. Unlock all Nextdoor questions →
About This Question
This is a candidate experience report from a nextdoor interview during the phone round.
It covers the following topics: Android, Coding, Phone, Strings .
More Nextdoor Interview Questions
1p3a
nextdoor software engineer tech phone screen interview overview
LeetCode
#56 Merge Intervals
InterviewDB
Comment Tree: Build and Traverse a Nested Comment Thread Like Reddit's
InterviewDB
Nextdoor SWE Onsite - Letter Combinations
1p3a
Nextdoor Full-Time SDE Tech Phone Screen Interview Questions