Crash Courses · Masters
Rate Limiting & Security
Protect REST APIs from abuse with rate limiting, CORS, and input validation.
10 min read+175 XP on completionCert: REST APIs Crash Course
Tap any word in the text below to start reading from there.
Rate Limiting & Security
Public APIs need protection. Rate limiting, CORS, and security headers are the baseline for production APIs.
Rate Limiting (Vercel + upstash/ratelimit)
import { Ratelimit } from '@upstash/ratelimit'
import { Redis } from '@upstash/redis'
const ratelimit = new Ratelimit({
redis: Redis.fromEnv(),
limiter: Ratelimit.slidingWindow(10, '10s'), // 10 req per 10s
})
export async function POST(req: NextRequest) {
const ip = req.headers.get('x-forwarded-for') ?? '127.0.0.1'
const { success, reset } = await ratelimit.limit(ip)
if (!success) {
return NextResponse.json(
{ error: 'Rate limit exceeded' },
{
status: 429,
headers: { 'Retry-After': String(Math.ceil((reset - Date.now()) / 1000)) },
}
)
}
// process request...
}CORS Headers
// next.config.ts — global CORS headers
async headers() {
return [{
source: '/api/:path*',
headers: [
{ key: 'Access-Control-Allow-Origin', value: 'https://yourdomain.com' },
{ key: 'Access-Control-Allow-Methods', value: 'GET,POST,PATCH,DELETE,OPTIONS' },
{ key: 'Access-Control-Allow-Headers', value: 'Content-Type,Authorization' },
],
}]
}
// Route Handler for OPTIONS preflight
export async function OPTIONS() {
return new NextResponse(null, {
status: 200,
headers: {
'Access-Control-Allow-Origin': '*',
'Access-Control-Allow-Methods': 'GET,POST,OPTIONS',
'Access-Control-Allow-Headers': 'Content-Type,Authorization',
},
})
}Security Headers
// next.config.ts
async headers() {
return [{
source: '/:path*',
headers: [
{ key: 'X-Frame-Options', value: 'DENY' },
{ key: 'X-Content-Type-Options', value: 'nosniff' },
{ key: 'Referrer-Policy', value: 'strict-origin-when-cross-origin' },
{ key: 'Permissions-Policy', value: 'camera=(), microphone=(), geolocation=()' },
],
}]
}Reading progress
0% read
In this module
Rate limiting
CORS
Input sanitization
Security headers
0%