Securing an Admin Panel: HMAC Sessions, Rate Limiting & Magic-Byte Validation


An admin panel is a website's back door — and the back door must be stronger than the front. Three layers of defense I apply:
First, stateless HMAC-based sessions. No session table in the database, no server-side state. The token carries a payload plus an HMAC signature; the server only needs to verify the signature to know the token is genuine. Tokens expire absolutely after 12 hours, and 30 minutes of idleness logs out automatically.
// the idea: payload.signature, the server just verifies const valid = verifyHMAC(payload, signature, SECRET); if (!valid || expired(payload)) return 401;
Second, rate limiting on the login endpoint: max 10 attempts per 10 minutes per IP. Brute force becomes impractical without an annoying CAPTCHA.
Third, upload validation down to the magic-byte level. Checking file extensions is not enough — file.type from the browser can be faked. Every uploaded file gets its first bytes inspected: JPEG must be FF D8 FF, PNG 89 50 4E 47. Plus a 5MB cap and an allowed MIME list.
The result: an admin panel with no session-store dependency, resistant to brute force, and immune to faked files.
