Resta saysFiltering and sorting refine list endpoints via query parameters.
Let clients narrow results with query params: ?status=active&role=admin filters, ?sort=-created_at sorts (a - prefix often means descending), and ?fields=id,name trims the payload. Define a consistent grammar across endpoints so clients learn it once. This keeps responses small and lets the server do the work efficiently.
Power-ups you unlock
?filter params narrow results
?sort=field (- for descending)
?fields= trims the payload
Consistent grammar across endpoints
The 401 Bandit attacks — common mistakes
Ad-hoc, inconsistent filter syntax per endpoint
No limit on filterable fields (perf)
Filtering client-side after over-fetching
Boss battleDesign query params to list active users sorted by newest, name + email only.