npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@concepta/nestjs-password

v8.0.0-alpha.12

Published

Rockets NestJS Password

Readme

@concepta/nestjs-password

Password utilities module for NestJS using DDD/CQRS. Provides password hashing, strength validation, current password enforcement, and history checking via four domain services and a configurable policy.

Project

NPM Latest NPM Downloads GH Last Commit GH Contrib NestJS Dep

Table of Contents

Installation

yarn add @concepta/nestjs-password @nestjs/common @nestjs/config @nestjs/core

Requirements: the package is ESM-only (no CommonJS build), targets Node.js >= 22.12, and runs on NestJS 12.

Dependencies

| Package | Notes | | --- | --- | | @concepta/nestjs-core | RuntimeException base class, reference types, utilities | | bcrypt | Password hashing | | zxcvbn | Password strength evaluation |

Peer Dependencies

| Package | Required | Notes | | --- | --- | --- | | @nestjs/common | Yes | NestJS 12 framework | | @nestjs/core | Yes | Required by @nestjs/cqrs | | @nestjs/config | Yes | Configuration module | | @nestjs/cqrs | No | Optional peer — required in practice, the command bus |

Module Registration

Synchronous

import { PasswordModule, PasswordStrengthEnum } from '@concepta/nestjs-password';

@Module({
  imports: [
    PasswordModule.register({
      settings: {
        minPasswordStrength: PasswordStrengthEnum.Strong,
        requireCurrentToUpdate: true,
      },
    }),
  ],
})
export class AppModule {}

Asynchronous

import { PasswordModule, PasswordStrengthEnum } from '@concepta/nestjs-password';

@Module({
  imports: [
    PasswordModule.registerAsync({
      useFactory: async () => ({
        settings: {
          minPasswordStrength: PasswordStrengthEnum.Strong,
        },
      }),
    }),
  ],
})
export class AppModule {}

register() / registerAsync() register the module locally (scoped to the importing module).

forRoot() / forRootAsync() register the module globally.

forFeature() creates a standalone set of password providers (policy, services, command handlers) for use in sub-modules.

Options

interface PasswordOptionsInterface {
  settings?: PasswordSettingsInterface;
}

interface PasswordSettingsInterface {
  minPasswordStrength?: PasswordStrengthEnum;  // Minimum zxcvbn score
  requireCurrentToUpdate?: boolean;            // Require current password on update
}

Architecture Overview

Application (Commands)
  |
Domain (Services, Policy, Exceptions, CryptUtil)
  |
Infrastructure (Config)
  • Domain -- PasswordPolicy (configurable policy), four domain services, domain exceptions, CryptUtil (bcrypt abstraction; internal — not exported from the package barrel)
  • Application -- 4 commands dispatched via @nestjs/cqrs
  • Infrastructure -- Configuration with environment variable support

Password primitives are defined and exported by this package: PasswordPlainInterface, PasswordPlainCurrentInterface, PasswordStorageInterface, PasswordUpdateInterface, and the isPasswordStorage type guard.

Password Policy

PasswordPolicy encapsulates configurable password rules (its settings constructor argument is typed as PasswordPolicySettings, also exported). It is registered as a NestJS provider and injected into services.

| Property | Type | Default | Description | | --- | --- | --- | --- | | minPasswordStrength | PasswordStrengthEnum | None (production: VeryStrong) | Minimum zxcvbn score (0-4) | | requireCurrentToUpdate | boolean | false | Require current password when updating |

PasswordStrengthEnum

| Value | Score | Description | | --- | --- | --- | | None | 0 | No strength requirement | | Weak | 1 | Weak password | | Medium | 2 | Medium strength | | Strong | 3 | Strong password | | VeryStrong | 4 | Very strong password |

Domain Services

Each service has a matching exported contract interface: PasswordCreationServiceInterface, PasswordStorageServiceInterface, PasswordValidationServiceInterface, and PasswordStrengthServiceInterface — implement one of these to swap in a custom provider.

PasswordCreationService

Orchestrates password creation with policy enforcement.

| Method | Signature | Description | | --- | --- | --- | | create | (password: string) => Promise<PasswordStorageInterface> | Hash password after strength check | | validateCurrent | (options) => Promise<boolean> | Validate current password (throws PasswordCurrentRequiredException if required and missing) | | validateHistory | (options) => Promise<boolean> | Check password against history (throws PasswordUsedRecentlyException on match) |

PasswordStorageService

Handles password hashing via bcrypt.

| Method | Signature | Description | | --- | --- | --- | | hash | (password: string) => Promise<PasswordStorageInterface> | Hash a plain password | | hashObject | (object, options?) => Promise<...> | Hash the password field of an object, returning the object with passwordHash replacing password |

PasswordValidationService

Validates a plain password against a stored hash.

| Method | Signature | Description | | --- | --- | --- | | validate | (options: PasswordValidateOptionsInterface) => Promise<boolean> | Compare plain password against hash |

PasswordStrengthService

Evaluates password strength using zxcvbn.

| Method | Signature | Description | | --- | --- | --- | | isStrong | (password: string) => boolean | Returns true if zxcvbn score meets minPasswordStrength |

Commands

| Command | Input | Returns | Description | | --- | --- | --- | --- | | CreatePasswordCommand | password | PasswordStorageInterface | Create and hash a password (with strength check) | | ValidatePasswordCommand | PasswordValidateOptionsInterface | boolean | Validate plain password against hash | | ValidateCurrentPasswordCommand | password, target | boolean | Validate current password against stored credentials | | ValidatePasswordHistoryCommand | password, targets[] | boolean | Check password against credential history |

Dispatching a Command

import { CommandBus } from '@nestjs/cqrs';
import {
  CreatePasswordCommand,
  ValidatePasswordCommand,
  PasswordStorageInterface,
} from '@concepta/nestjs-password';

// Create a hashed password
const storage = await this.commandBus.execute<
  CreatePasswordCommand,
  PasswordStorageInterface
>(new CreatePasswordCommand('my-secure-password'));

// Validate a password against a hash
const isValid = await this.commandBus.execute<
  ValidatePasswordCommand,
  boolean
>(new ValidatePasswordCommand({
  password: 'my-secure-password',
  passwordHash: storage.passwordHash,
}));

Exceptions

| Exception | Description | | --- | --- | | PasswordException | Base password exception | | PasswordNotStrongException | Password does not meet minimum strength | | PasswordRequiredException | Password field is required but missing | | PasswordCurrentRequiredException | Current password required by policy but not provided | | PasswordUsedRecentlyException | Password matches a recent credential in history |

All exceptions extend PasswordException, which extends RuntimeException from @concepta/nestjs-core. RuntimeException extends Nest's HttpException, so no exception filter registration is needed — password exceptions render on the wire as { statusCode, message, errorCode, error? } bodies (errorCode PASSWORD_ERROR unless a subclass overrides it).

Environment Variables

| Variable | Default | Description | | --- | --- | --- | | PASSWORD_MIN_PASSWORD_STRENGTH | 0 (production: 4) | Minimum zxcvbn score (0-4) | | PASSWORD_REQUIRE_CURRENT_TO_UPDATE | false | Require current password on update |

Entry Points

| Import Path | Contents | | --- | --- | | @concepta/nestjs-password | Module, policy, services, commands, command handlers, exceptions, enums, interfaces |