1
00:00:00,330 --> 00:00:05,760
Lastly, since we will deploy our app on Heroku, it's also very wise to add some security packages.

2
00:00:06,210 --> 00:00:13,740
We'll start with express a rate limiter in order to limit requests made from each IP address.

3
00:00:14,190 --> 00:00:25,710
How to set security related a ship a response headers x ask clean to sanitize user input, express Mongo,

4
00:00:25,710 --> 00:00:33,490
sanitize to protect against MongoDB injection and cause to allow access from different domains.

5
00:00:33,720 --> 00:00:41,680
But when it comes to course, keep in mind one thing we are sending JWT with cookies, correct?

6
00:00:41,730 --> 00:00:47,700
And remember, they will only work if the front end is on the same domain.

7
00:00:48,210 --> 00:00:49,320
Just be aware of that.

8
00:00:49,590 --> 00:00:54,570
And lastly, if you want to find out more info about any of the packages, please utilize the library

9
00:00:54,600 --> 00:00:55,010
docs.

10
00:00:55,320 --> 00:00:57,720
But in general, it's really not that complex.

11
00:00:58,230 --> 00:01:01,350
Just install the package and you're good to go.

12
00:01:01,650 --> 00:01:03,270
So let's start working on that.

13
00:01:03,690 --> 00:01:10,500
And before I type anything in the app, Josh, I want you to take a look at the package JSON.

14
00:01:10,890 --> 00:01:17,250
And if you do not see the express Hmong or sanitise since I added this one later, then we'll have to

15
00:01:17,250 --> 00:01:18,180
install it together.

16
00:01:18,360 --> 00:01:20,130
So let me stop the server.

17
00:01:20,520 --> 00:01:28,430
I'm going to go with an RPM install, install the package and then we can go to our address.

18
00:01:28,440 --> 00:01:31,340
And I guess before we do that, I'll start the server.

19
00:01:31,980 --> 00:01:36,810
Then back in the app, Jess, you want to require all of the packages.

20
00:01:37,830 --> 00:01:40,230
And it doesn't really matter where we do that.

21
00:01:40,680 --> 00:01:44,580
But I think I'm going to go right off 30 file uploads, so one by one.

22
00:01:44,880 --> 00:01:46,860
Let's start with rate limiter.

23
00:01:46,980 --> 00:01:49,260
Since we use that one first rate.

24
00:01:50,170 --> 00:01:51,980
The matter is equal to require.

25
00:01:52,930 --> 00:02:01,000
And the package was expressed right remit when we want to do the same thing with helmet.

26
00:02:02,250 --> 00:02:04,510
So here we're looking for a helmet.

27
00:02:05,500 --> 00:02:07,210
Run the package name is.

28
00:02:08,360 --> 00:02:11,290
I met houses that we want to look for X.

29
00:02:11,740 --> 00:02:15,340
S s, so let me go here with X.

30
00:02:15,670 --> 00:02:19,270
And this one was x ss queen.

31
00:02:21,090 --> 00:02:23,700
Clean package when we want to get the course.

32
00:02:25,330 --> 00:02:33,700
Of course, I'm the same name for the package and also we want to get express mango scientists have

33
00:02:33,700 --> 00:02:35,320
gone mango.

34
00:02:36,350 --> 00:02:44,240
And it does not as equal to acquire Nine, we're looking for express Mongo sanitize.

35
00:02:45,270 --> 00:02:48,810
Once we have all the imports, we want to scroll down.

36
00:02:49,730 --> 00:02:55,340
And I think I'm going to set them up above the Morgan and express Jason.

37
00:02:55,760 --> 00:03:02,060
We'll start with Alright Ltd and remember if it's behind the proxy, then we need to set that set trust

38
00:03:02,180 --> 00:03:04,370
proxy in line one.

39
00:03:05,450 --> 00:03:13,760
I've met let's set up that rate limiter so that years, and let's just go here with a rate limiter and

40
00:03:13,760 --> 00:03:21,290
then we'll right away pass in the object with windows in milliseconds property and also equal to 15

41
00:03:21,290 --> 00:03:21,830
minutes.

42
00:03:23,460 --> 00:03:24,940
So let's set up here.

43
00:03:24,990 --> 00:03:27,720
Times six the Times.

44
00:03:28,660 --> 00:03:34,570
One thousand and then as far as the requests going to go with Max and 60.

45
00:03:34,990 --> 00:03:40,540
So keep it just like we have in the jobs API project.

46
00:03:41,110 --> 00:03:48,010
After that, I want to go with helmet cause and Mongo sanitize and we just go about years helmet.

47
00:03:48,520 --> 00:03:49,450
We invoke it.

48
00:03:49,720 --> 00:03:50,740
Copy and paste.

49
00:03:51,340 --> 00:03:56,250
Let's because Velcade access advocate.

50
00:03:56,810 --> 00:03:59,710
And the same goes for Mongo Sanitize.

51
00:04:00,070 --> 00:04:03,070
And with this in place, we already deploy our application.

