How to protect your API from developers who knows your API?

Viewed 94

I'm a fullstack developer trainee in a company. I'm working on Online book store project. My manager asked a question.

He asked "If someone i.e other developer knows your code or API they can change the code or API in your project and adds themself as an admin or can remove some user from the DB and also performs CRUD operations by changing your API. So how can you solve this?".

My suggestion: Rather than having codes in the local machine we can put our code in some server.

plz suggest your opinion and correct answer.

2 Answers

I would suggest you to use a code repository like github or gitlab. After uploading your project as a repository, change the setting of the repository such that no one else is allowed to update the code (No other Contributors). Your project code in production should be deployed based on this repository. Not just update, you could also make your repository private so that no one could see your code.

I believe your question is mostly related to the runtime behavior or control over a rest service. Thats where the security comes in to play. Gateway plays a role by filtering the resource path. The API endpoint he knows can be filtered or remapped at Gateway. Securing the application via Authentication and Authorization adds another layer of protection. for example. Person A can only access the application if he/she is authenticated. Once Authenticated, person A can add him/herself only if the person is of category SystemAdmin etc.

If its related to the Code Management then repository management comes in to play. Set rights to few individuals for pushing the changes to the Master branch. All developers logically should be working on Forked branch and will create a Pull Request to push the changes to the Master branch. This will give the opportunity to the moderators of Master branch to review the code and filter it out.

Related