25장. Security
인증, RBAC, network private, TLS, at-rest encryption, auditing, field-level encryption 요구를 구분한다. application은 root 역할을 쓰지 않는다. connection string secret을 로그에 남기지 않는다.
NoSQL injection은 operator가 포함된 untrusted object를 query에 전달할 때 생긴다. DTO allowlist와 type validation을 둔다.