firasrg / autocare-rest-api

AutoCare is a well-organized REST API sample app
GNU Affero General Public License v3.0
1 stars 2 forks source link

Implement Security Layers #23

Open firasrg opened 2 months ago

firasrg commented 2 months ago

It's important to address security concerns that are often overlooked in any REST API development. This issue aims to implement security layers to protect the application and its data from unauthorized access.

NOTE ⚠️: Currently, the Car Services REST API is not deployed on a public server, so this issue will apply to the DEV environment only. However, when the app is deployed on a server, having proper protection will be essential. Also, while this project is a sample and not intended for storing real data, implementing security layers is crucial. It provides a practical example of how to configure security in real-world projects.

Examples of potentials threats against APIs :

Documentation

After implementing the security layers, please document the configuration and explain the steps taken. This will help others learn how to apply similar security measures in their own projects.