Secure Task API
Production-style REST API with JWT auth, RBAC, and security hardening — exploring authentication, validation, and CI/CD.
Overview
A Node.js + Express REST API built to practice production patterns: authentication with JWT (access + refresh), role-based authorization, input validation, rate limiting, and containerized deployment. Focus on OWASP API Top 10 mitigations.
Problem
Needed a realistic backend to practice secure API design beyond tutorials — auth, authorization, and deployment as one system.
Solution
Built an Express API with modular routes, middleware for auth/validation/rate-limit, and Docker Compose for local parity. Tests cover authz edge cases.
Architecture
[Client] ↓ [Next.js Frontend] ↓ [API — Express + Validation] ↓ [Auth — JWT / RBAC] ↓ [Service Layer] ↓ [PostgreSQL] [Redis — Rate Limit]
Technology
Engineering Decisions
- •PostgreSQL for relational integrity + row-level ownership checks
- •JWT stored httpOnly cookie for refresh, Bearer for access — mitigates XSS token theft
- •Zod for runtime validation at API boundary
Security
- •JWT authentication with short-lived access tokens + refresh rotation
- •Server-side authorization checks on every resource (BOLA/IDOR prevention)
- •Input validation + output encoding, rate limiting on auth endpoints
Testing
Unit tests for services, integration tests for authz (IDOR probes, privilege escalation attempts), manual testing with Postman + Burp Suite.
Deployment
Docker image built in CI, deployed to VPS with Caddy (TLS), env via secrets, healthcheck endpoint.
Lessons Learned
Authorization must be enforced server-side per resource — never trust client-supplied IDs without ownership check.