SpringBoot Web Application Security for apis working on static token?

Viewed 14

I have one Spring boot Web application which has few apis facing internet, deployed on aws, they work on JWT token, they're fairly secure. But there are few apis that work on static token validation. They are used for asynchronous operation such as sending emails from lambda etc. These type of apis seems to be somewhat vulnerable, if token gets leaked somehow. What else can be applied as security measures on these type of apis? Token rotation is one way but it has become tedious because there are multiple services that need this type of operation and tokens are stored at multiple places. I'm thinking one additional layer of ip whitelisting that we receive in x-forwarded-for http request. But I tried to overwrite it from Postman and x-forwarded-for header became a comma seperated list ['ip_that_i_put_in_header', 'my_machines_public_ip']. So I guess this can be overwritten. I think it is useless. Even if I do IP whitelisting,how to get CIDR from aws that should be whitelisted? Anything else that I can do?

0 Answers
Related