1
00:00:00,240 --> 00:00:06,370
All right, so far, all our apps were nice and quiet, since we only use them in local setup, but

2
00:00:06,510 --> 00:00:09,260
with this project, things are about to get interesting.

3
00:00:09,750 --> 00:00:14,990
You see, this app will actually host on Hiroku, basically deployed on the cloud.

4
00:00:15,390 --> 00:00:21,720
And what that means that we also need to think about security, essentially how we can protect our API

5
00:00:22,020 --> 00:00:23,550
from some bad actors.

6
00:00:23,970 --> 00:00:26,480
And the good news is that with the help of community.

7
00:00:26,700 --> 00:00:33,740
So think NPM and more specifically, NPM packages, we really don't need to do that much, just intel

8
00:00:33,750 --> 00:00:36,900
some packages and add them as middleware in our app.

9
00:00:37,200 --> 00:00:38,430
And we're good to go.

10
00:00:38,580 --> 00:00:40,470
Yes, it is that simple.

11
00:00:40,950 --> 00:00:44,340
Now, is our app going to be safe from any possible attack?

12
00:00:44,670 --> 00:00:45,180
We'll know.

13
00:00:45,330 --> 00:00:46,200
Most likely not.

14
00:00:46,500 --> 00:00:50,000
Remember, our biggest security hotspot is still our user.

15
00:00:50,430 --> 00:00:53,130
Yes, of course we should be protecting our API.

16
00:00:53,550 --> 00:00:58,830
But how are you going to stop the user from storing a token in a unsecure manner?

17
00:00:59,220 --> 00:01:00,740
There's really no package for that.

18
00:01:01,320 --> 00:01:07,050
And as far as the packages we're going to use, well, first we are going to use helmet, arguably the

19
00:01:07,050 --> 00:01:14,500
most popular security package out there, which sets various headers to prevent numerous possible attacks.

20
00:01:14,910 --> 00:01:20,490
In fact, how it is so popular, it's actually used in many other packages as an dependancy.

21
00:01:20,910 --> 00:01:27,960
After that, we want to implement course library, which just ensures that our API is accessible from

22
00:01:27,960 --> 00:01:28,940
different domain.

23
00:01:29,340 --> 00:01:34,890
If you don't have course installed, you'll only be able to access the data from the same domain.

24
00:01:35,160 --> 00:01:40,880
If you remember in the previous project, we did that in JavaScript file located in the public folder.

25
00:01:41,250 --> 00:01:48,570
And if you try to access our previous APIs from any other front end apps, you'll get a courser.

26
00:01:48,960 --> 00:01:58,440
Now, Cause stands for cross origin resource sharing and it is a mechanism to allow or restrict requested

27
00:01:58,440 --> 00:02:06,780
resources on a Web server depending on where the request was initiated by installing and implementing

28
00:02:06,780 --> 00:02:07,620
the course package.

29
00:02:07,860 --> 00:02:11,810
Essentially, we make our API accessible to the public.

30
00:02:12,240 --> 00:02:20,200
After that, we want to use X as clean library, which sanitizes the user input in that regard.

31
00:02:20,220 --> 00:02:27,960
Query and Rugg programs and as a result protects us from Crossette scripting attacks where the attacker

32
00:02:27,960 --> 00:02:30,590
tries to inject some malicious code.

33
00:02:30,840 --> 00:02:34,230
And lastly, we want to limit the amount of requests the user can make.

34
00:02:34,620 --> 00:02:38,340
And we'll do that with the help of Express Right Limit Library.

35
00:02:38,850 --> 00:02:43,350
If you're using the star, all libraries already installed and ready to go.

36
00:02:43,740 --> 00:02:48,900
But if you want to use it for your own project, of course, just install them by running NPM install

37
00:02:49,170 --> 00:02:50,840
and then the name of the library.

38
00:02:51,150 --> 00:02:57,960
And also if you want to get more info on any of them, a library is a very good place to start.

39
00:02:58,320 --> 00:03:03,180
And later projects we might use some additional libraries or config options.

40
00:03:03,510 --> 00:03:09,300
But in general, as far as the standard security, this setup is a very good place to start.

