← Back to Portfolio
WEB SECURITY

Website Security Hardening

Security work applied across the web apps I've built and deployed — authentication, sessions, forms, and headers hardened against the common attack surface.

Status Ongoing Scope Auth, sessions, forms, headers Stack Node / Express

Headers & Content Security Policy

Helmet + Content-Security-Policy

Audited every inline <script> block and inline event-handler attribute (onclick=, onerror=) out of the codebase, then enabled a strict CSP with Helmet.

Subresource Integrity

Added integrity= hashes and crossorigin="anonymous" to every third-party CDN script tag.

Forms & Sessions

CSRF protection

Implemented a double-submit token pattern on every mutating form and route.

Rate limiting

Applied express-rate-limit to login and every route that's cheap to abuse: forms, uploads, password reset requests.

Secure session cookies

Configured cookies with secure: true, sameSite: 'lax', httpOnly: true, and set up correct trust proxy config to run cleanly over HTTPS behind a reverse proxy.

Authentication

Argon2id password hashing

Hashed passwords with Argon2id plus a server-side pepper stored in an environment variable, kept separate from the database.

TOTP 2FA

Added optional TOTP two-factor authentication with a trusted-device cookie for repeat logins.

// session cookie config I use across projects app.use(session({ cookie: { secure: true, httpOnly: true, sameSite: 'lax' } }));