6190f3dd39
- Create LocalStrategy (username/password via argon2) and JwtStrategy (cookie extractor) - Create JwtAuthGuard with @Public() decorator support for route opt-out - Create RolesGuard checking SUPER_ADMIN/ADMIN/USER roles per D-12 - Create AuthService with validateUser, login (30-day httpOnly cookie), logout - Create AuthController with POST /auth/login, POST /auth/logout, GET /auth/me - Create LoginDto with class-validator decorators - Create @Public, @Roles, @CurrentUser decorators - Update main.ts with ValidationPipe, CORS credentials, cookie-parser - Install cookie-parser for httpOnly JWT cookie support
37 lines
929 B
TypeScript
37 lines
929 B
TypeScript
import { ValidationPipe } from '@nestjs/common';
|
|
import { ConfigService } from '@nestjs/config';
|
|
import { NestFactory } from '@nestjs/core';
|
|
import cookieParser from 'cookie-parser';
|
|
import { AppModule } from './app.module';
|
|
|
|
async function bootstrap() {
|
|
const app = await NestFactory.create(AppModule);
|
|
const configService = app.get(ConfigService);
|
|
|
|
// Cookie parser for JWT httpOnly cookies
|
|
app.use(cookieParser());
|
|
|
|
// Global validation pipe with whitelist and transform
|
|
app.useGlobalPipes(
|
|
new ValidationPipe({
|
|
whitelist: true,
|
|
transform: true,
|
|
}),
|
|
);
|
|
|
|
// CORS with credentials for cross-origin cookie support (Pitfall 4)
|
|
const corsOrigin = configService.get<string>(
|
|
'CORS_ORIGIN',
|
|
'http://localhost:3000',
|
|
);
|
|
app.enableCors({
|
|
origin: corsOrigin,
|
|
credentials: true,
|
|
});
|
|
|
|
await app.listen(3001);
|
|
console.log('Tessera API running on port 3001');
|
|
}
|
|
|
|
bootstrap();
|