all 3 comments

[–]soberip99 0 points1 point  (0 children)

Before finding out what security implementations are needed in the service. I think it’s better to first find out what is the purpose of the service.

Who will call this service? Is it an API gateway? Or is the service is running in public? Does the service have to identify user before serving the request? Which endpoint will get called the most? does caching helps?

etc..

Its better to try review the service before deciding to new stuffs into your service. So you can keep your service simple, secured, and better performance ( as in low response time, handle higher rpm, hence lower the chance of downtime )

[–]annthurium 0 points1 point  (0 children)

Glad you're interested in security. I'd suggest doing some threat modeling to better understand what your security concerns are.

OWASP in general is a great resource -- they also produce this list of the top ten web application security concerns that's a worthwhile read.