What is a sane rate limit design for a public API?
Token bucket per key and per IP, with the limit expressed in the response headers so clients can behave. The subtle part is what you do on limit: a 429 with Retry-After is cooperative, silently dropping is what turns one misbehaving client into a retry storm.
Do I need CSRF protection if I use bearer tokens?
Not if the token lives in memory and is sent in a header, because the browser will not attach it automatically. The moment it moves into a cookie for convenience, CSRF is back, and SameSite=Lax becomes load-bearing.
How often should a small project bump dependencies?
Monthly for a project with a test suite, immediately for anything with a published advisory. Batch the routine bumps into a single change so the diff is reviewable, and keep security updates separate so they can go out without waiting for a release.
What is the most common way people get this wrong?
Doing it once and never verifying. The setup is the visible part, so it gets attention, and the check that would catch a silent failure never gets written.
