Security
Securing Your Node.js API: A Production Checklist
October 9, 202611 min read
Securing Your Node.js API: Production Checklist
Security is not optional. Here's a comprehensive checklist for securing your Node.js API.
Authentication & Authorization
- Use JWT with short expiration (15 min access tokens)
- Implement refresh token rotation
- Role-based access control (RBAC)
- Rate limiting on auth endpoints
## Input Validation & Sanitization
``typescript
import { z } from 'zod';
const userSchema = z.object({
email: z.string().email(),
password: z.string().min(8).max(100),
});
`
## HTTP Security Headers
Use helmet.js to set security headers:
- Content Security Policy
- X-Frame-Options
- X-Content-Type-Options
- HSTS
## Rate Limiting
`typescript
import rateLimit from 'express-rate-limit';
const limiter = rateLimit({
windowMs: 15 * 60 * 1000,
max: 100,
});
``
## Database Security
- Never store plaintext passwords (use bcrypt)
- Validate all database inputs
- Use least-privilege DB accounts
- Enable MongoDB Atlas IP whitelisting
## Additional Measures
- Dependency auditing (npm audit)
- Secrets management (never in code)
- CORS configuration
- Request size limits
- SQL/NoSQL injection prevention
- Use JWT with short expiration (15 min access tokens)
- Implement refresh token rotation
- Role-based access control (RBAC)
- Rate limiting on auth endpoints
## Input Validation & Sanitization
``
typescript
import { z } from 'zod';
const userSchema = z.object({
email: z.string().email(),
password: z.string().min(8).max(100),
});
`
## HTTP Security Headers
Use helmet.js to set security headers:
- Content Security Policy
- X-Frame-Options
- X-Content-Type-Options
- HSTS
## Rate Limiting
`typescript
import rateLimit from 'express-rate-limit';
const limiter = rateLimit({
windowMs: 15 * 60 * 1000,
max: 100,
});
``## Database Security
- Never store plaintext passwords (use bcrypt)
- Validate all database inputs
- Use least-privilege DB accounts
- Enable MongoDB Atlas IP whitelisting
## Additional Measures
- Dependency auditing (npm audit)
- Secrets management (never in code)
- CORS configuration
- Request size limits
- SQL/NoSQL injection prevention
SecurityNode.jsAPIBackend
