A user should be able to register, submit their own data to be stored in mongoDB and when they use the API endpoints such as "/data", they only get the data they created as opposed to the data created by every user.
I understand authentication up to level 5 security and only studying OAuth now.
Ideas I have in designing this is maybe finding a way to have the endpoints require and the username and any created data store the username.
So /usernamedata gives the person their data and that way, other people's data stays safe? Cause I don't imagine a user would somehow be capable of hacking into my DB and with restrictive endpoints they'd only have access to their own data.
I'd love some feedback on my strategy!