Perancangan Middleware Modular Autentikasi dan Hak Akses pada RESTFUL API Node.js (Studi Kasus Aplikasi Insightku)
Abstract
Keamanan sistem RESTful API menjadi perhatian penting seiring meningkatnya penggunaan arsitektur layanan web pada aplikasi modern. Penelitian ini merancang dan mengimplementasikan enam middleware modular untuk autentikasi dan hak akses pada RESTful API berbasis Node.js dengan studi kasus aplikasi manajemen keuangan Insightku. Analisis awal menemukan sepuluh permasalahan, termasuk ketiadaan Role-Based Access Control (RBAC), duplikasi middleware authenticateToken sebanyak 18 kali, tidak adanya proteksi brute force, validasi input terpusat, dan audit trail. Menggunakan metode Research and Development (R&D) dengan model ADDIE serta pengujian Black Box Testing, dikembangkan enam middleware: authenticateToken, checkRole, errorHandler, rateLimiter, validateRequest, dan requestLogger. Pengujian pada 14 skenario menunjukkan tingkat keberhasilan 100% dengan overhead response time 2–22 ms. Duplikasi kode berkurang 94,4% dan solusi yang dikembangkan mampu memitigasi 9 dari 10 ancaman OWASP API Security Top 10. Validasi menghasilkan skor rata-rata 4,67/5,00 (Sangat Baik).
The security of RESTful API systems has become increasingly important with the growing adoption of web service architectures in modern applications. This study designs and implements six modular middlewares for authentication and access control in a Node.js-based RESTful API, using the Insightku personal finance application as a case study. Initial analysis identified ten issues, including the absence of Role-Based Access Control (RBAC), 18 duplicated authenticateToken middleware instances, and the lack of brute force protection, centralized input validation, and audit trails. Using the Research and Development (R&D) methodology with the ADDIE model and Black Box Testing, six middlewares were developed: authenticateToken, checkRole, errorHandler, rateLimiter, validateRequest, and requestLogger. Testing across 14 scenarios achieved a 100% success rate with a response time overhead of 2–22 ms. Code duplication was reduced by 94.4%, and the solution mitigates 9 of the 10 OWASP API Security Top 10 threats. Validation resulted in an average score of 4.67/5.00 (Very Good).
Downloads
References
S. A. B. Cahyono, S. Sucipto, and R. Firliana, "Implementasi otentikasi website Node.js Express menggunakan Passport," Jurnal Infra, vol. 10, no. 1, pp. 50-57, 2022.
OWASP, "OWASP API Security Top 10," Open Web Application Security Project, 2023. [Online]. Available: https://owasp.org/API-Security/editions/2023/en/0x11-t10/
M. Jones, J. Bradley, and N. Sakimura, "JSON Web Token (JWT)," RFC 7519, IETF, 2015. [Online]. Available: https://www.rfc-editor.org/info/rfc7519
E. Edy, F. Ferdiansyah, W. Pramusinto, and S. Waluyo, "Pengamanan RESTful API menggunakan JWT untuk aplikasi sales order," Jurnal Teknik Informatika dan Sistem Informasi, vol. 6, no. 1, pp. 1-10, 2019.
S. Dalimunthe, E. H. Putra, and M. A. F. Ridha, "RESTful API security using JWT with HMAC-SHA512 algorithm in session management," International Journal of Computer Applications, vol. 184, no. 15, 2023.
R. Sandhu, E. J. Coyne, H. L. Feinstein, and C. E. Youman, "Role-based access control models," IEEE Computer, vol. 29, no. 2, pp. 38-47, 1996.
J. S. Utama and A. D. Indriyanti, "Pengamanan RESTful API web service menggunakan JSON Web Token," Jurnal Teknologi dan Sistem Komputer, vol. 11, no. 1, pp. 33-40, 2023.
Express.js, "Using middleware," 2024. [Online]. Available: https://expressjs.com/en/guide/using-middleware.html
G. J. Myers, C. Sandler, and T. Badgett, The Art of Software Testing, 3rd ed. Hoboken, NJ: John Wiley & Sons, 2011.
R. Gunawan and A. Rahmatulloh, "JSON Web Token (JWT) untuk authentication pada interoperabilitas arsitektur berbasis RESTful Web Service," Jurnal Edukasi dan Penelitian Informatika (JEPIN), vol. 5, no. 1, pp. 74-80, 2019.
Sugiyono, Metode Penelitian dan Pengembangan (Research and Development/R&D). Bandung: Alfabeta, 2019.
R. M. Branch, Instructional Design: The ADDIE Approach. New York: Springer, 2009.
A. Gupta and R. Sharma, "Secure RESTful API development using Node.js and Express framework," International Journal of Advanced Computer Science and Applications, vol. 13, no. 9, pp. 45-52, 2022.
R. T. Fielding, "Architectural styles and the design of network-based software architectures," Ph.D. dissertation, Univ. of California, Irvine, 2000.
I. Sommerville, Software Engineering, 10th ed. Boston: Pearson Education, 2016.
A. Rahman and K. Ali, "Implementation of role-based access control in RESTful API using Node.js and JWT," International Journal of Computer Applications, vol. 183, no. 5, pp. 12-19, 2024.
A. B. Prasetyo and I. Suharjo, "Backend API data protection menggunakan JWT token dan algoritma AES 256-bit dengan bahasa pemrograman Golang," Jurnal Informatika dan Teknik Elektro Terapan (JITET), vol. 13, no. 1, pp. 682-693, Jan. 2025, doi: 10.23960/jitet.v13i1.5699.

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.



