sanitization to all api routes
This commit is contained in:
@@ -67,6 +67,7 @@ const {
|
||||
addRequestId,
|
||||
sanitizeError,
|
||||
} = require("./middleware/security");
|
||||
const { sanitizeInput } = require("./middleware/validation");
|
||||
const { generalLimiter } = require("./middleware/rateLimiter");
|
||||
const errorLogger = require("./middleware/errorLogger");
|
||||
const apiLogger = require("./middleware/apiLogger");
|
||||
@@ -134,6 +135,9 @@ app.use(
|
||||
})
|
||||
);
|
||||
|
||||
// Apply input sanitization to all API routes (XSS prevention)
|
||||
app.use("/api/", sanitizeInput);
|
||||
|
||||
// Serve static files from uploads directory with CORS headers
|
||||
app.use(
|
||||
"/uploads",
|
||||
|
||||
Reference in New Issue
Block a user