BACK
API SECURITY

API ๋ณด์•ˆ ๊ฐ€์ด๋“œ

REST ๋ฐ GraphQL API๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ์„ค๊ณ„ํ•˜๊ณ  ์šด์˜ํ•˜๊ธฐ ์œ„ํ•œ ๊ฐ€์ด๋“œ์ž…๋‹ˆ๋‹ค.

์ธ์ฆ & ์ธ๊ฐ€

OAuth 2.0, JWT, API Key ๋“ฑ ์ ์ ˆํ•œ ์ธ์ฆ ๋ฉ”์ปค๋‹ˆ์ฆ˜์„ ๊ตฌํ˜„ํ•˜๊ณ , ์—”๋“œํฌ์ธํŠธ๋ณ„ ๊ถŒํ•œ์„ ์„ธ๋ถ„ํ™”ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ž…๋ ฅ๊ฐ’ ๊ฒ€์ฆ

๋ชจ๋“  API ์ž…๋ ฅ๊ฐ’์— ๋Œ€ํ•ด ํƒ€์ž…, ๊ธธ์ด, ํ˜•์‹์„ ์—„๊ฒฉํ•˜๊ฒŒ ๊ฒ€์ฆํ•˜์—ฌ Injection ๊ณต๊ฒฉ์„ ๋ฐฉ์ง€ํ•ฉ๋‹ˆ๋‹ค.

Rate Limiting

API ํ˜ธ์ถœ ํšŸ์ˆ˜๋ฅผ ์ œํ•œํ•˜์—ฌ ๋ธŒ๋ฃจํŠธํฌ์Šค ๊ณต๊ฒฉ๊ณผ ๋ฆฌ์†Œ์Šค ๋‚จ์šฉ์„ ๋ฐฉ์ง€ํ•ฉ๋‹ˆ๋‹ค.

์Šคํ‚ค๋งˆ ๊ฒ€์ฆ

OpenAPI/Swagger ์Šคํ‚ค๋งˆ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ์š”์ฒญ/์‘๋‹ต ๊ตฌ์กฐ๋ฅผ ์ž๋™ ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค.

๊ด€๋ จ ๋ฌธ์„œ