feat(02-01): AuthModule with Passport strategies, guards, and decorators
- Create LocalStrategy (username/password via argon2) and JwtStrategy (cookie extractor) - Create JwtAuthGuard with @Public() decorator support for route opt-out - Create RolesGuard checking SUPER_ADMIN/ADMIN/USER roles per D-12 - Create AuthService with validateUser, login (30-day httpOnly cookie), logout - Create AuthController with POST /auth/login, POST /auth/logout, GET /auth/me - Create LoginDto with class-validator decorators - Create @Public, @Roles, @CurrentUser decorators - Update main.ts with ValidationPipe, CORS credentials, cookie-parser - Install cookie-parser for httpOnly JWT cookie support
This commit is contained in:
+24
-1
@@ -1,10 +1,33 @@
|
||||
import { ValidationPipe } from '@nestjs/common';
|
||||
import { ConfigService } from '@nestjs/config';
|
||||
import { NestFactory } from '@nestjs/core';
|
||||
import cookieParser from 'cookie-parser';
|
||||
import { AppModule } from './app.module';
|
||||
|
||||
async function bootstrap() {
|
||||
const app = await NestFactory.create(AppModule);
|
||||
const configService = app.get(ConfigService);
|
||||
|
||||
app.enableCors({ origin: true });
|
||||
// Cookie parser for JWT httpOnly cookies
|
||||
app.use(cookieParser());
|
||||
|
||||
// Global validation pipe with whitelist and transform
|
||||
app.useGlobalPipes(
|
||||
new ValidationPipe({
|
||||
whitelist: true,
|
||||
transform: true,
|
||||
}),
|
||||
);
|
||||
|
||||
// CORS with credentials for cross-origin cookie support (Pitfall 4)
|
||||
const corsOrigin = configService.get<string>(
|
||||
'CORS_ORIGIN',
|
||||
'http://localhost:3000',
|
||||
);
|
||||
app.enableCors({
|
||||
origin: corsOrigin,
|
||||
credentials: true,
|
||||
});
|
||||
|
||||
await app.listen(3001);
|
||||
console.log('Tessera API running on port 3001');
|
||||
|
||||
Reference in New Issue
Block a user