WEBBOOK CHAPTER

NestJS 11, 시작부터 런칭까지: 13장. 보안 기본값

13장. 보안 기본값

Helmet 계열 header, CORS exact allowlist, body size, rate limit, secure cookie 조건을 둔다. validation이 SQL injection, SSRF, file upload, authorization을 모두 해결하지 않는다.

관리 endpoint와 Swagger 공개 범위를 제한한다. production source map과 error stack 접근 정책을 정한다.