feat(02-01): AuthModule with Passport strategies, guards, and decorators

- Create LocalStrategy (username/password via argon2) and JwtStrategy (cookie extractor)
- Create JwtAuthGuard with @Public() decorator support for route opt-out
- Create RolesGuard checking SUPER_ADMIN/ADMIN/USER roles per D-12
- Create AuthService with validateUser, login (30-day httpOnly cookie), logout
- Create AuthController with POST /auth/login, POST /auth/logout, GET /auth/me
- Create LoginDto with class-validator decorators
- Create @Public, @Roles, @CurrentUser decorators
- Update main.ts with ValidationPipe, CORS credentials, cookie-parser
- Install cookie-parser for httpOnly JWT cookie support
This commit is contained in:
2026-06-18 13:24:59 +02:00
parent d0b36c8f22
commit 6190f3dd39
14 changed files with 358 additions and 1 deletions
+2
View File
@@ -20,6 +20,7 @@
"argon2": "^0.44.0",
"class-transformer": "^0.5.1",
"class-validator": "^0.15.1",
"cookie-parser": "^1.4.7",
"passport": "^0.7.0",
"passport-jwt": "^4.0.1",
"passport-local": "^1.0.0",
@@ -28,6 +29,7 @@
},
"devDependencies": {
"@nestjs/cli": "^11.0.0",
"@types/cookie-parser": "^1.4.10",
"@types/express": "^5.0.0",
"@types/node": "^22.0.0",
"@types/passport-jwt": "^4.0.1",