feat(security): pengerasan keamanan API internify-be (CORS, Rate Limiting, Helmet, Multer, Cookie)

This commit is contained in:
Rafi Athallah
2026-08-04 22:07:26 +07:00
parent 326de3f929
commit 3acd41e1f7
9 changed files with 148 additions and 11 deletions
+4 -3
View File
@@ -2,7 +2,8 @@ const express = require('express');
const { authController } = require('../modules/auth');
const { verifyJWT } = require('../middleware/verifyJWT');
const multer = require('../middleware/multer');
const { multerErrorHandler } = require('../middleware/multer');
const { multerErrorHandler, checkFileSizes } = require('../middleware/multer');
const { authLimiter } = require('../middleware/rateLimiter');
const router = express.Router();
@@ -44,7 +45,7 @@ const router = express.Router();
* 500:
* description: Internal server error
*/
router.post("/login", authController.login);
router.post("/login", authLimiter, authController.login);
/**
* @swagger
@@ -318,6 +319,6 @@ router.get("/me", verifyJWT, authController.me);
* 500:
* description: Internal server error
*/
router.patch('/update-profile', verifyJWT, multer.single('profile_picture'), multerErrorHandler, authController.updateProfile);
router.patch('/update-profile', verifyJWT, multer.single('profile_picture'), checkFileSizes, multerErrorHandler, authController.updateProfile);
module.exports = router;