Skip to content

Latest commit

Β 

History

14 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ Web Application Firewall (WAF) + JWT Authentication

A security-focused full-stack application that detects and blocks malicious HTTP requests while providing JWT-based authentication and protected API access.

This project implements a custom Web Application Firewall (WAF) that inspects incoming HTTP requests before they reach application routes.

It detects threats such as SQL injection, XSS, path traversal, and suspicious requests, while also providing dynamic IP blocking, rate limiting, security logging, and JWT authentication.


πŸš€ Live Demo

Frontend:
https://waf-jwt-frontend.vercel.app

Backend API:
https://waf-jwt.onrender.com


πŸ“‹ Overview

The WAF operates as middleware within the Express.js backend and analyzes incoming HTTP requests before they reach application routes.

Suspicious or malicious requests can be blocked automatically, with the source IP temporarily added to a dynamic block list.

The application also includes JWT-based authentication, protected routes, and refresh-token handling.


πŸ—οΈ Architecture

User
  β”‚
  β–Ό
React Frontend
(Vercel)
  β”‚
  β–Ό
Express Server
(Render)
  β”‚
  β–Ό
Custom WAF Middleware
  β”‚
  β”œβ”€β”€ Request Inspection
  β”œβ”€β”€ Threat Detection
  β”œβ”€β”€ Rate Limiting
  └── IP Blocking
  β”‚
  β–Ό
JWT Authentication
  β”‚
  β–Ό
MongoDB Atlas

✨ Features

πŸ›‘οΈ WAF Security

  • SQL Injection detection
  • XSS detection
  • Path traversal protection
  • Suspicious user-agent detection
  • Request payload inspection
  • Dynamic IP blocking
  • Rate limiting
  • Security logging

πŸ” Authentication

  • JWT access tokens
  • Refresh token system
  • Protected API routes
  • Automatic token refresh using Axios interceptors

βš™οΈ Backend

  • Express REST API
  • Middleware-based WAF filtering
  • MongoDB user storage
  • Helmet security headers
  • CORS protection

πŸ’» Frontend

  • React + Vite
  • Login and registration pages
  • Axios interceptors for authentication
  • Protected dashboard route

πŸ› οΈ Tech Stack

Frontend

  • React
  • Vite
  • Axios
  • React Router

Backend

  • Node.js
  • Express.js
  • MongoDB
  • Mongoose
  • JWT

Deployment

  • Vercel β€” Frontend
  • Render β€” Backend
  • MongoDB Atlas β€” Database

πŸ”Œ API Endpoints

Authentication

POST /api/auth/register
POST /api/auth/login
POST /api/auth/logout
POST /api/auth/refresh

User

GET /api/users/me

Health Check

GET /health

πŸ§ͺ WAF Protection Examples

The WAF inspects incoming requests for suspicious patterns associated with common web attacks.

SQL Injection

Example malicious input:

' OR 1=1 -- UNION SELECT DROP TABLE

XSS

Example:

<script> onerror= javascript:

Path Traversal

Example:

../
%2E%2E

When a malicious request is detected, the request can be blocked:

{
  "ok": false,
  "reason": "malicious_payload"
}

πŸ”„ Request Security Flow

Incoming Request
      β”‚
      β–Ό
WAF Middleware
      β”‚
      β–Ό
Request Inspection
      β”‚
      β”œβ”€β”€ Malicious ──► Block / Log
      β”‚
      └── Safe
           β”‚
           β–Ό
    JWT Authentication
           β”‚
           β–Ό
      Protected Route
           β”‚
           β–Ό
        Database

πŸš€ Local Setup

1. Clone the repository

git clone https://github.com/Developer-Sohail786/WAF-JWT.git
cd WAF-JWT

2. Install backend dependencies

cd Backend
npm install

3. Install frontend dependencies

Open another terminal:

cd Frontend
npm install

4. Configure backend environment variables

Create:

Backend/.env

Add:

MONGO_URL=your_mongodb_uri

ACCESS_TOKEN_SECRET=your_secret
REFRESH_TOKEN_SECRET=your_secret

ACCESS_TOKEN_EXPIRY=1d
REFRESH_TOKEN_EXPIRY=7d

WAF_ENABLED=true

5. Run the backend

npm start

6. Run the frontend

Inside the Frontend directory:

npm run dev

πŸ“ Project Structure

WAF-JWT/
β”‚
β”œβ”€β”€ Backend/
β”‚   β”œβ”€β”€ ...
β”‚   └── ...
β”‚
β”œβ”€β”€ Frontend/
β”‚   β”œβ”€β”€ ...
β”‚   └── ...
β”‚
└── README.md

πŸ”’ Security Components

The project combines multiple security mechanisms:

  • Custom WAF middleware
  • SQL injection detection
  • XSS detection
  • Path traversal protection
  • Dynamic IP blocking
  • Rate limiting
  • Security logging
  • JWT authentication
  • Refresh tokens
  • Protected routes
  • Helmet security headers
  • CORS protection

πŸ‘¨β€πŸ’» Author

Sohail Khan

Full-Stack Developer | Backend | Web Security


πŸ“œ License

This project is licensed under the MIT License.

About

Security-focused full-stack application with a custom WAF for SQL injection, XSS, path traversal detection, JWT authentication, rate limiting, IP blocking, and security logging.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages