What is a good strategy for creating an API where each registered user only has access to their data

Viewed 12

A user should be able to register, submit their own data to be stored in mongoDB and when they use the API endpoints such as "/data", they only get the data they created as opposed to the data created by every user.

I understand authentication up to level 5 security and only studying OAuth now.

Ideas I have in designing this is maybe finding a way to have the endpoints require and the username and any created data store the username.

So /usernamedata gives the person their data and that way, other people's data stays safe? Cause I don't imagine a user would somehow be capable of hacking into my DB and with restrictive endpoints they'd only have access to their own data.

I'd love some feedback on my strategy!

0 Answers
Related