Chapter 8. Backend Security Considerations
The security of your app is going to be one of the top concerns for the dev team, the Product team, and the whole organization. You never want an unintended entity to gain access they aren’t supposed to have. That’s why you’ll need to look at the app from all angles, such as authentication, authorization, validation, common attacks, and external dependencies.
Security is a topic with so much depth and breadth that entire books are dedicated to it. I’m going to keep this chapter focused on what you can do on the backend specifically, but there are far more areas covered by security. You may be lucky enough to work with a Security team. They go through every part of the company’s technical infrastructure, all the way down to what you can install on your laptop.
In this chapter, you will learn about:
-
Authentication methods and when to use them
-
Authorization for users to give them different levels of access to the functionality and data in the app
-
Why you should typically go with an out-of-the-box solution
-
The parts of the Open Web Application Security Project (OWASP) Top 10 that apply to the backend
-
Best security practices, regulations, and where to learn more about different areas of security
I’m just touching the surface of this topic in this chapter, and I’ll leave you with plenty of resources to learn all the details. But you will see how to implement some good, practical security practices here. Then you can build off that ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access