Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

backend-notes-api

Secure personal notes REST API with JWT authentication, HttpOnly cookies, MongoDB persistence, and strict user ownership.

Features

  • User registration, login, and logout
  • JWT authentication stored in an HttpOnly cookie
  • Create, list, read, update, and delete notes
  • Every note is scoped to its owner
  • Input validation and safe error responses
  • Helmet security headers and rate limiting
  • Configurable CORS with credentials
  • Standard API response URLs and request logs
  • Automated in-process API tests

Requirements

  • Node.js 18 or newer
  • MongoDB running locally or a hosted MongoDB connection

Setup

npm install
copy .env.example .env

Set a real MongoDB URI and a random JWT_SECRET with at least 32 characters in .env.

Run

npm run dev

The default port is 1198.

Environment variables

Variable Required Description
PORT No Server port, defaults to 1198
MONGO_URI Yes MongoDB connection string
JWT_SECRET Yes Random secret, minimum 32 characters
NODE_ENV No Use production to enable Secure cookies
CLIENT_ORIGINS No Comma-separated trusted frontend origins
COOKIE_SAME_SITE No Cookie policy, defaults to lax

API endpoints

Method Endpoint Access Purpose
GET / Public API status
GET /health Public Health response
POST /api/auth/register Public Register a user and set cookie
POST /api/auth/login Public Login and set cookie
POST /api/auth/logout Public Clear auth cookie
POST /api/notes Authenticated Create a note
GET /api/notes Authenticated List the current user's notes
GET /api/notes/:id Authenticated Read an owned note
PUT /api/notes/:id Authenticated Update an owned note
DELETE /api/notes/:id Authenticated Delete an owned note

All JSON responses include apiUrl as the first field. Browser clients must use credentials: "include" for cookie-based requests.

License

MIT. See LICENSE.

Author

Ashish Ranjan

Full-Stack Web Developer

Links

Support

About

Secure backend API for personal notes CRUD with user ownership using Node.js, Express, MongoDB, JWT, and HttpOnly cookies.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages