Body:
helmet is present but needs definite production configuration. Ensure trust proxy is configured behind proxies, set strict security header policies, and tune rate limits per sensitive routes.
Acceptance Criteria:
helmet is configured with strict defaults for production.
trust proxy is documented and configurable.
- Rate limits are applied to public endpoints and documented.
Body:
helmetis present but needs definite production configuration. Ensuretrust proxyis configured behind proxies, set strict security header policies, and tune rate limits per sensitive routes.Acceptance Criteria:
helmetis configured with strict defaults for production.trust proxyis documented and configurable.