This question checks understanding of common security practices for web APIs built with Node.js.
01
01
Understand the problem
securityapiauthenticationauthorization
02
02
Attempt it yourself
Sketch your approach before reading the solution — that's what interviews test.
Stuck? AI Nudge Available
Get a conceptual hint to guide your logic without spoiling the final implementation.
03
03
Study the solution
The solution is waiting
Give it an honest attempt first — then compare your thinking with the full walkthrough.
04
04
Read the code
Auth + role guard + validation
const requireRole = (role) => (req, res, next) =>
req.user?.roles?.includes(role) ? next() : res.status(403).end();
app.post('/admin/users',
authenticate, // who? sets req.user
requireRole('admin'), // allowed?
validate(CreateUserSchema), // input ok?
createUserHandler,
);05
05
Join the discussion
Discussion (0)
Sign in to join the discussion.
No responses yet. Be the first to share what you think.