Is it safe to open the Nodejs server port to the world?

Viewed 164

A React app and Nodejs server which is used to retrieve and manipulate the data are running on the same server. When accessing the app locally it workes fine, but when accessed externally the app is visible but without data. The reason behind this is that the port on which the application is running is open but the port on which the Nodejs server is running is not.

My question is this, what is the best way to solve this issue? The simplest solution would be to open up the other port, but I am assuming that is not the most secure solution.

Any suggestions would be appreciated.

2 Answers

Open to port for the outside world and implement a token-based request verification system.

You can implement CSRF token verification. It always checks that request comes from a trusted source only.

Do this using a reverse proxy server, like nginx, to listen to the open https port. The reverse proxy will handle the https encryption, rather than burdening your nodejs code with it. nginx is multithreaded and can do https efficiently.

The reverse proxy passes along requests to your http://localhost:3000 nodejs. In my experience, this arrangement works very well at large scale.

Explaining how to do this is too much for a stack overflow answer. But you'll find plenty of online advice.

Related