feat: add some security packages

This commit is contained in:
2026-07-08 07:46:37 +03:30
parent 03ba4ceabe
commit b4570f6df9
5 changed files with 58 additions and 1 deletions
+15 -1
View File
@@ -13,7 +13,7 @@ import { RedisModule } from './common/modules/redis/redis.module';
import path from 'path';
import jwtConfig from './config/jwt.config';
import redisConfig from './config/redis.config';
import { APP_FILTER } from '@nestjs/core';
import { APP_FILTER, APP_GUARD } from '@nestjs/core';
import { GlobalExceptionFilter } from './common/filters/global-exception.filter';
import { ScheduleModule } from '@nestjs/schedule';
import { TestsModule } from './modules/tests/tests.module';
@@ -21,6 +21,8 @@ import { QuestionsModule } from './modules/questions/questions.module';
import { SubmissionsModule } from './modules/submissions/submissions.module';
import { ScoringModule } from './modules/scoring/scoring.module';
import { AdminModule } from './modules/admin/admin.module';
import { ThrottlerModule } from '@nestjs/throttler';
import { AppThrottlerGuard } from './common/guards/app-throttler.guard';
const ENV = process.env.NODE_ENV;
@@ -68,6 +70,14 @@ const ENV = process.env.NODE_ENV;
// Schedule
ScheduleModule.forRoot(),
// Throttler
ThrottlerModule.forRoot([
{ name: 'default', limit: 100, ttl: 60_000 },
{ name: 'login', limit: 5, ttl: 60_000 },
{ name: 'otp', limit: 3, ttl: 300_000 },
{ name: 'admin', limit: 30, ttl: 60_000 },
]),
/**
* Local Modules
*/
@@ -87,6 +97,10 @@ const ENV = process.env.NODE_ENV;
provide: APP_FILTER,
useClass: GlobalExceptionFilter,
},
{
provide: APP_GUARD,
useClass: AppThrottlerGuard,
},
],
})
export class AppModule {}
+13
View File
@@ -0,0 +1,13 @@
import { HttpStatus } from '@nestjs/common';
import { ThrottlerGuard } from '@nestjs/throttler';
import { AppException } from '../exceptions/app.exception';
export class AppThrottlerGuard extends ThrottlerGuard {
protected throwThrottlingException(): Promise<void> {
throw new AppException(
'common.errors.tooManyRequests',
HttpStatus.TOO_MANY_REQUESTS,
{ minutes: 1 },
);
}
}
+3
View File
@@ -3,6 +3,7 @@ import { AppModule } from './app.module';
import { I18nValidationExceptionFilter, I18nValidationPipe } from 'nestjs-i18n';
import { SwaggerModule, DocumentBuilder } from '@nestjs/swagger';
import { ResponseInterceptor } from './common/interceptors/response.interceptor';
import helmet from 'helmet';
async function bootstrap() {
const app = await NestFactory.create(AppModule);
@@ -36,6 +37,8 @@ async function bootstrap() {
credentials: true,
});
app.use(helmet());
const config = new DocumentBuilder()
.setTitle('Borna API')
.setDescription('Borna API Documentation')