API Security
Security Headers (Helmet)
- X-Content-Type-Options: nosniff
- X-Frame-Options: DENY
- X-XSS-Protection: 1; mode=block
- Content-Security-Policy configured
CORS
Allowed origins:
statux.iostatuspage.statux.ioalerts.statux.iosynthetics.statux.iolocalhost(development)
Rate Limiting
- 100 requests per 60 seconds (default)
- Applied globally via NestJS Throttler
Input Validation
- Global
ValidationPipewithwhitelist: true - Unknown properties stripped
- DTOs enforce structure