Back to Projectssoftware • In Development

Secure Task API

Production-style REST API with JWT auth, RBAC, and security hardening — exploring authentication, validation, and CI/CD.

Overview

A Node.js + Express REST API built to practice production patterns: authentication with JWT (access + refresh), role-based authorization, input validation, rate limiting, and containerized deployment. Focus on OWASP API Top 10 mitigations.

Problem

Needed a realistic backend to practice secure API design beyond tutorials — auth, authorization, and deployment as one system.

Solution

Built an Express API with modular routes, middleware for auth/validation/rate-limit, and Docker Compose for local parity. Tests cover authz edge cases.

Architecture

[Client]
  ↓
[Next.js Frontend]
  ↓
[API — Express + Validation]
  ↓
[Auth — JWT / RBAC]
  ↓
[Service Layer]
  ↓
[PostgreSQL]   [Redis — Rate Limit]

Technology

Node.jsExpressPostgreSQLDockerJWT

Engineering Decisions

  • •PostgreSQL for relational integrity + row-level ownership checks
  • •JWT stored httpOnly cookie for refresh, Bearer for access — mitigates XSS token theft
  • •Zod for runtime validation at API boundary

Security

  • •JWT authentication with short-lived access tokens + refresh rotation
  • •Server-side authorization checks on every resource (BOLA/IDOR prevention)
  • •Input validation + output encoding, rate limiting on auth endpoints

Testing

Unit tests for services, integration tests for authz (IDOR probes, privilege escalation attempts), manual testing with Postman + Burp Suite.

Deployment

Docker image built in CI, deployed to VPS with Caddy (TLS), env via secrets, healthcheck endpoint.

Lessons Learned

Authorization must be enforced server-side per resource — never trust client-supplied IDs without ownership check.