Lesson 21 / 25

Security: Helmet & Rate Limiting

Harden an Express API with Helmet security headers, express-rate-limit and a small request body size limit.

Helmet and rate limiting

helmet sets protective HTTP headers and express-rate-limit caps requests per client.

import helmet from 'helmet';
import rateLimit from 'express-rate-limit';

app.use(helmet());
app.use(express.json({ limit: '100kb' }));
app.use(rateLimit({ windowMs: 15 * 60 * 1000, limit: 100 }));
app.disable('x-powered-by'); // helmet does this too

Behind a proxy or load balancer set app.set('trust proxy', 1) so rate limits use the real client IP, and always validate input.

Quick check

Quick check: What does the helmet package do?

  • Sets protective HTTP security headers
  • Parses JSON bodies
  • Connects to MongoDB
  • Compresses images
Answer

Sets protective HTTP security headers — Helmet applies a set of secure default headers.