@nathapp/nestjs-app
v4.1.0
Published
this package is to shorten up nestjs app instantiate
Readme
@nathapp/nestjs-app
Shorten and standardize NestJS application bootstrap.
Global guards
useAppGlobalGuards(...guards) registers, in order: the JWT guard, the permission
guard, then guards. The JWT guard is resolved as:
.setJwtAuthGuard(...)if specifiedJwtMsAuthGuardif@nathapp/nestjs-microservicesis installed- else
JwtAuthGuard
To place a guard between the JWT and permission guards (e.g. resolve a tenant from the verified principal), use the ordered API with slot tokens:
import { AppFactory, GLOBAL_GUARD } from '@nathapp/nestjs-app';
const nathApp = AppFactory.useApp(app);
nathApp.useAppGlobalGuardsOrdered(
GLOBAL_GUARD.JWT,
new TenantGuard(), // runs after JWT, before permission
GLOBAL_GUARD.PERMISSION,
);GLOBAL_GUARD.JWT and GLOBAL_GUARD.PERMISSION are placeholders resolved to the
configured built-ins at that position. Guards not using slots run exactly where
listed.
Note: guards are resolved and registered when
useAppGlobalGuards()/useAppGlobalGuardsOrdered()is called. CallingsetJwtAuthGuard(...)orsetPermissionGuard(...)after registration has no effect and logs a warning — always set custom guards before registering global guards.
Important:
APP_GUARDproviders are added by NestJS during application creation and always run before any guard registered viauseGlobalGuards/useAppGlobalGuards*. A guard that must run after JWT or after the custom position must be passed touseAppGlobalGuardsOrdered(...), not registered as anAPP_GUARD.
Validation
useAppGlobalPipes() registers a global validation pipe with the defaults:
{ forbidUnknownValues: false, stopAtFirstError: true, whitelist: true }whitelist: true strips any request-body property that is not declared (and
decorated) on the target DTO — unknown fields such as isAdmin never reach your
handlers, preventing mass-assignment. This is a behavior change from earlier
versions, which let unknown properties through: DTOs must now expose (and
decorate) every property they accept.
To opt out or customize, call setValidationPipeOptions(...) before
useAppGlobalPipes() — explicit options override the defaults:
nathApp
.setValidationPipeOptions({ whitelist: false })
.useAppGlobalPipes();