import { Injectable, UnauthorizedException } from '@nestjs/common'; import { PassportStrategy } from '@nestjs/passport'; import { Strategy } from 'passport-local'; import { AuthService } from '../auth.service'; import type { LoginUser } from '../types/auth-user'; @Injectable() export class LocalStrategy extends PassportStrategy(Strategy) { constructor(private authService: AuthService) { super({ usernameField: 'username' }); } async validate(username: string, password: string): Promise { const user = await this.authService.validateUser(username, password); if (!user) { // T-02-01: Generic error message - never reveal whether username or password is wrong throw new UnauthorizedException('Invalid credentials'); } return user; } }