Author here. I've compiled various sources and considerations into one checklist to simplify hardening of REST-based webapp. I believe that the list like this should be eyeballed by as many people as possible, therefore I submit it here and will be very grateful for comments or critic.
Hope it will be useful for others, too.