Middleware that rejects requests whose referer or origin header does not identify them as having come from a specified domain
npm install check-refererjavascript
var checkReferer = require('check-referer');
var checkRefererMw = ;
app.post('/api/endpoint', checkReferer('mydomain.com'), function(req, res) {
// Requests from other platforms will return 403
res.send('Hi!');
});
// You can also pass an array to allow multiple domains
checkReferer(['mydomain.com', 'anotherdomain.net']);
``