Lesson 21 / 25
Security: Helmet & Rate Limiting
Harden an Express API with Helmet security headers, express-rate-limit and a small request body size limit.
Helmet and rate limiting
helmet sets protective HTTP headers and express-rate-limit caps requests per client.
import helmet from 'helmet';
import rateLimit from 'express-rate-limit';
app.use(helmet());
app.use(express.json({ limit: '100kb' }));
app.use(rateLimit({ windowMs: 15 * 60 * 1000, limit: 100 }));
app.disable('x-powered-by'); // helmet does this tooBehind a proxy or load balancer set app.set('trust proxy', 1) so rate limits use the real client IP, and always validate input.
Quick check
Quick check: What does the helmet package do?
- Sets protective HTTP security headers
- Parses JSON bodies
- Connects to MongoDB
- Compresses images
Answer
Sets protective HTTP security headers — Helmet applies a set of secure default headers.