Phase 4 · Authentication & SecurityModule 30~60 min read

Rate Limits, Secrets & Supply-Chain Security

Protect high-risk operations with layered throttling, secret management, dependency review, audit response, and secure configuration.

What you'll learn

Protect expensive and identity-sensitive operations with layered limits, keep secrets out of artifacts and logs, and treat third-party packages as production code with an update and incident process.

By the end of this lesson, you'll be able to:

  • Design risk-based rate limits
  • Manage secret lifecycle
  • Pin and review dependencies
  • Respond to compromised credentials or packages

Core mental model

Node.js becomes easier when you separate the JavaScript language from the runtime and the operating-system capabilities it exposes. Use this table as a decision guide.

ConceptWhat it meansDecision rule
Rate dimensionThe identity used to count attemptsCombine account, IP, tenant, and endpoint where appropriate
SecretA credential granting authorityInject at runtime, scope narrowly, rotate, and never log
LockfileThe resolved dependency graphCommit it and use reproducible clean installs

Professional workflow

Build and verify Node.js programs from the terminal in small, observable steps.

  1. Define the abuse and secret control boundary: inputs, outputs, invariants, ownership, and expected failures.
  2. Design the data or message contract before choosing implementation details.
  3. Implement the smallest correct path with dependencies passed explicitly.
  4. Add validation, failure translation, cleanup, and concurrency behavior.
  5. Verify the boundary with realistic data and at least one adversarial case.
  6. Measure or observe the behavior before optimizing or extracting abstractions.

Keep the feedback loop short

Run the smallest useful command after every meaningful change. Read the complete error message before editing again, and keep inputs and outputs visible while you learn.

Guided code lab

Limit by the risk-bearing identity

Login defense tracks both normalized account and network so IP rotation or account spraying alone does not bypass controls.

login-limit.js
const accountKey = 'login:account:' + normalizeEmail(email);
const networkKey = 'login:ip:' + request.ip;
const [account, network] = await Promise.all([
  limiter.consume(accountKey, 1),
  limiter.consume(networkKey, 1),
]);
if (!account.allowed || !network.allowed) throw new TooManyRequestsError();

Production practice

Contract

Every sensitive endpoint declares cost, abuse identity, limit, response, recovery, and audit behavior; every secret has owner, scope, and rotation path.

Verification

Test boundary counts, parallel attempts, store outage, proxy IP trust, secret redaction, clean npm installs, and vulnerable-package response.

Operations

Use centralized limits for replicas, alert on abnormal denials, scan dependencies and images, rotate secrets, and keep an emergency revocation runbook.

Common failure mode

A single per-IP limit punishes shared networks and is easy to bypass. Match counters to the protected asset and abuse pattern.

Independent workshop

Harden login, password reset, exports, and dependency delivery.

Your finished workshop must include:

  • Endpoint risk table
  • Layered rate limits
  • Trusted proxy policy
  • Secret inventory
  • Reproducible install
  • Incident runbook

Definition of done

Run the happy path and at least two edge cases, keep responsibilities separated, and add a short README explaining how to run the program.

Recap & quick check

Key takeaways

  • Limits follow abuse cases
  • Secrets need lifecycle ownership
  • Lockfiles support reproducibility
  • Dependencies expand trust
  • Failure behavior needs design

Quick check

1. What should a login limit protect?

2. Where should production secrets live?

3. Why use npm ci?

Next: Secure File Uploads & Object Storage