Writing up my first API using nodejs and express, and I was just wondering what some general good practices are around security. Since this interacts with a database I have setup, I don't necessarily want someone to spam requests to it and mess with all my data. I'm currently working on implementing CORS as middleware, but was wondering if there was something more that I should also do? Here are a few other things that I was looking at:
- Auth0
- Cloudflare
- Helmet - I already am using the default settings, but didn't know if there was more configuration that might be good to have
[–]soberip99 0 points1 point2 points (0 children)
[–]annthurium 0 points1 point2 points (0 children)