Cover
Foto profil

Bembi Pramudya

@beemind

I'm Bembi, also known as beemind, a web developer based in Indonesia. I spend my free time experimenting with AI, diving into networks and privacy-focused web tools, and listening to music

DeveloperIndonesiahaibem.cc
Web

Securing an Admin Panel: HMAC Sessions, Rate Limiting & Magic-Byte Validation

Bembi Pramudya
Bembi PramudyaOct 6, 2026 · 1 min read
Securing an Admin Panel: HMAC Sessions, Rate Limiting & Magic-Byte Validation

An admin panel is a website's back door — and the back door must be stronger than the front. Three layers of defense I apply:

First, stateless HMAC-based sessions. No session table in the database, no server-side state. The token carries a payload plus an HMAC signature; the server only needs to verify the signature to know the token is genuine. Tokens expire absolutely after 12 hours, and 30 minutes of idleness logs out automatically.


// the idea: payload.signature, the server just verifies
const valid = verifyHMAC(payload, signature, SECRET);
if (!valid || expired(payload)) return 401;

Second, rate limiting on the login endpoint: max 10 attempts per 10 minutes per IP. Brute force becomes impractical without an annoying CAPTCHA.

Third, upload validation down to the magic-byte level. Checking file extensions is not enough — file.type from the browser can be faked. Every uploaded file gets its first bytes inspected: JPEG must be FF D8 FF, PNG 89 50 4E 47. Plus a 5MB cap and an allowed MIME list.

The result: an admin panel with no session-store dependency, resistant to brute force, and immune to faked files.