Monday 13 November 2017

Anything new for security best practices in 2017 for express?

Currently creating a new boiler-plate with express to help start projects. For the security side of things, is everyone using Helmut and/or Lusca? Lusca seems to be the better option as it has more features.Am I missing anything?SSL/TLS using NGINX as proxy severLusca for CSRF, XSS, clickjacking and a bunch of other thingsPassport for logins.User-access - still not sure what to use here. Previously I always used sessions and cookies.Anything else? Doesn't seem like much has changed over the past few years.Thanks!

Submitted November 13, 2017 at 05:17PM by dangerzone2

No comments:

Post a Comment