Api Security Hardening

by secondsky88378361314fMIT227 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 10 days ago

REST API security hardening with authentication, rate limiting, input validation, security headers. Use for production APIs, security audits, defense-in-depth, or encountering vulnerabilities, injection attacks, CORS issues.

Instructions onlySecurity
AI-generated overview

Guides hardening of REST APIs with authentication, rate limiting, input validation and security headers.

What it does
Provides guidance and code patterns for hardening REST APIs against common vulnerabilities using layered defenses. It covers an Express middleware stack with Helmet, rate limiting and sanitization, input validation with express-validator, security header configuration, and a security checklist. It also points to a reference file for Python FastAPI middleware, Pydantic validation, Nginx SSL/TLS configuration and HTTP parameter pollution prevention.
When to use it
Use it when preparing production REST APIs, running security audits, or applying defense-in-depth. It is also relevant when addressing vulnerabilities, injection attacks or CORS issues.
Requirements
No scripts are shipped; it is instructions only. The examples assume Node.js with Express and packages such as helmet, express-rate-limit, express-mongo-sanitize, express-validator and escape-html, plus optional Python FastAPI and Nginx setups described in the reference file.

API Security Hardening

Protect REST APIs against common vulnerabilities with multiple security layers.

Security Middleware Stack (Express)

javascript
const helmet = require('helmet');const rateLimit = require('express-rate-limit');const mongoSanitize = require('express-mongo-sanitize');
app.use(helmet());app.use(mongoSanitize());// For input sanitization, see the `xss-prevention` skill — do NOT use the// deprecated `xss-clean` package (unmaintained since 2018; its own README// recommends migrating off it).
app.use('/api/', rateLimit({  windowMs: 15 * 60 * 1000,  max: 100}));
app.use('/api/auth/', rateLimit({  windowMs: 15 * 60 * 1000,  max: 5}));

Input Validation

javascript
const { body, validationResult } = require('express-validator');const escapeHtml = require('escape-html');
app.post('/users',  body('email').isEmail().normalizeEmail(),  body('password').isLength({ min: 8 }).matches(/[A-Z]/).matches(/[0-9]/),  // express-validator v7+ removed the built-in .escape() sanitizer; use a  // customSanitizer backed by `escape-html` to HTML-escape the value.  body('name').trim().isLength({ max: 100 }).customSanitizer(v => escapeHtml(v)),  (req, res) => {    const errors = validationResult(req);    if (!errors.isEmpty()) {      return res.status(400).json({ errors: errors.array() });    }    // Process request  });

Security Headers

javascript
app.use((req, res, next) => {  res.setHeader('Content-Security-Policy', "default-src 'self'");  res.setHeader('X-Frame-Options', 'DENY');  res.setHeader('X-Content-Type-Options', 'nosniff');  res.setHeader('Strict-Transport-Security', 'max-age=31536000; includeSubDomains');  res.setHeader('X-XSS-Protection', '1; mode=block');  next();});

Security Checklist

  • HTTPS everywhere
  • Authentication on all protected routes
  • Input validation and sanitization
  • Rate limiting enabled
  • Security headers configured
  • CORS restricted to allowed origins
  • No stack traces in production errors
  • Audit logging enabled
  • Dependencies regularly updated

Additional Implementations

See references/python-nginx.md [blocked] for:

  • Python FastAPI security middleware
  • Pydantic input validation with password rules
  • Nginx SSL/TLS and security headers configuration
  • HTTP Parameter Pollution prevention

Never Do

  • Trust user input without validation
  • Return detailed errors in production
  • Store secrets in code
  • Use GET for state-changing operations
  • Disable security for convenience

Source and attribution

Source:secondsky/claude-skillsinplugins/api-security-hardening/skills/api-security-hardeningat commit8837836

License: MIT

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal