Learn to secure a Node.js API end to end — hash passwords with bcrypt, issue and verify JWTs, protect routes with auth middleware, manage sessions and cookies safely, and harden the app with helmet, CORS, rate limiting and input validation. You walk away able to take an unprotected Express API and make it genuinely safe against the common OWASP attacks.
Watch the free preview
Why plaintext and encryption both fail for passwords — free to watch, no account needed.
What you'll learn
- Secure a Node API against the common OWASP authentication and access-control attacks
- Store credentials safely by hashing passwords with bcrypt and verifying them on login
- Issue, sign and verify JSON Web Tokens and gate protected routes with auth middleware
- Manage server-side sessions and cookies with secure flags and CSRF protection
- Harden an Express app with helmet, CORS, rate limiting and strict input validation
Syllabus
Storing Credentials Safely
Why plaintext and encryption both fail for passwordsFree preview
Hashing and verifying with bcrypt
Token-Based Authentication with JWT
Issuing signed JSON Web Tokens
Verifying tokens and protecting routes
Sessions, Cookies and CSRF
Server-side sessions with express-session
Secure cookies and CSRF protection
Hardening the API against OWASP Risks
Helmet, CORS and rate limiting
Input validation and common OWASP pitfalls
Lab — 10 Exercises & Solutions
Exercises 1–5
Exercises 6–10