Sergei
3a20d5cc08
Add security middleware to backend
Security features:
- Helmet: Security headers (XSS, clickjacking protection)
- CORS: Whitelist only allowed domains
- Rate Limiting: 100 req/15min general, 5 req/15min for auth
- Stripe webhook signature verification (already had)
- Admin API key protection (already had)
Allowed origins:
- wellnuo.smartlaunchhub.com
- wellnuo.com
- localhost (dev)
- Expo dev URLs
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
2025-12-19 09:50:27 -08:00
..
2025-12-19 09:49:24 -08:00
2025-12-19 09:49:24 -08:00
2025-12-19 09:50:27 -08:00
2025-12-19 09:49:24 -08:00
2025-12-19 09:49:24 -08:00
2025-12-19 09:50:27 -08:00
2025-12-19 09:50:27 -08:00
2025-12-19 09:49:24 -08:00