- Add express-rate-limit: login limiter (10 req/15m) and global limiter (100 req/m) - Add helmet: secure HTTP headers with custom CSP configuration - Remove manual header settings in favor of helmet