nestjs-rbac-lib
v1.0.0
Published
A pluggable RBAC/ACL module for NestJS with role-based access control, permission guards, and API-level authorization.
Maintainers
Readme
nestjs-rbac-lib
A pluggable RBAC/ACL module for NestJS with role-based access control, permission guards, and API-level authorization.
Installation
npm install nestjs-rbac-libPeer dependencies: @nestjs/common, @nestjs/core, @nestjs/typeorm, typeorm, class-validator, class-transformer
Usage
Register the module
import { RbacModule } from 'nestjs-rbac-lib';
@Module({
imports: [
RbacModule.register(),
],
})
export class AppModule {}Use the guard
import { RbacGuard, Public } from 'nestjs-rbac-lib';
import { APP_GUARD } from '@nestjs/core';
// Register globally
providers: [{ provide: APP_GUARD, useClass: RbacGuard }]
// Skip auth on specific endpoints
@Public()
@Get('health')
health() { return 'ok'; }REST endpoints (auto-registered)
GET /rbac/metadata— list all ACL categories with their actionsGET /rbac/permissions/:userId?categoryKey=— get user's resolved permissionsGET /rbac/role/:roleId/acl— get role's ACL mappingsPUT /rbac/role/:roleId/acl— update role's ACL mappings (body:{ aclIds: number[] })
Database tables
| Entity | Table |
|--------|-------|
| Role | roles |
| UserRole | user_role |
| AclAction | acl_actions |
| AclCategory | acl_categories |
| AclCategoryActionMap | acl_category_action_map |
| AclCategoryActionApiMap | acl_category_action_api_map |
| RoleAclCategoryActionMap | role_acl_category_action_map |
How it works
Permissions are resolved through a 3-level chain: Role → Category+Action → API Route. The guard checks whether any of the user's roles have a mapping that covers the current HTTP method + path.
