feat: add some security

This commit is contained in:
2026-07-11 17:34:18 +03:30
parent f80cf95f65
commit f399ec4a04
10 changed files with 69 additions and 9 deletions
@@ -2,8 +2,10 @@ import { Body, Controller, HttpCode, HttpStatus, Post } from '@nestjs/common';
import { AdminAuthService } from './providers/admin-auth.service';
import { AdminLoginDTO } from './dtos/admin-login.dto';
import { Public } from '@/modules/auth/decorators/public.decorator';
import { Throttle } from '@nestjs/throttler';
@Controller('admin/auth')
@Throttle({ login: {} })
export class AdminAuthController {
constructor(
/**
@@ -17,9 +17,11 @@ import {
Post,
Query,
} from '@nestjs/common';
import { Throttle } from '@nestjs/throttler';
@Controller('admin/choices')
@Roles(Role.SUPERUSER, Role.ADMIN)
@Throttle({ admin: {} })
export class AdminChoicesController {
constructor(
/**
@@ -21,9 +21,11 @@ import {
Post,
Query,
} from '@nestjs/common';
import { Throttle } from '@nestjs/throttler';
@Controller('admin/questions')
@Roles(Role.SUPERUSER, Role.ADMIN)
@Throttle({ admin: {} })
export class AdminQuestionsController {
constructor(
/**
@@ -15,9 +15,11 @@ import {
Post,
Query,
} from '@nestjs/common';
import { Throttle } from '@nestjs/throttler';
@Controller('admin/scoring')
@Roles(Role.SUPERUSER, Role.ADMIN)
@Throttle({ admin: {} })
export class AdminScoringController {
constructor(
/**
@@ -17,9 +17,11 @@ import {
Post,
Query,
} from '@nestjs/common';
import { Throttle } from '@nestjs/throttler';
@Controller('admin/tests')
@Roles(Role.SUPERUSER, Role.ADMIN)
@Throttle({ admin: {} })
export class AdminTestsController {
constructor(
/**
+4
View File
@@ -4,6 +4,7 @@ import { AuthService } from './providers/auth.service';
import { VerifyOtpDTO } from './dtos/verify-otp.dto';
import { Public } from './decorators/public.decorator';
import { RefreshTokenDTO } from './dtos/refresh-token.dto';
import { Throttle } from '@nestjs/throttler';
@Controller('auth')
export class AuthController {
@@ -17,6 +18,7 @@ export class AuthController {
@Public()
@Post('login')
@HttpCode(HttpStatus.OK)
@Throttle({ login: {} })
public async logIn(@Body() loginDto: LoginDTO) {
return await this.authService.logIn(loginDto);
}
@@ -24,6 +26,7 @@ export class AuthController {
@Public()
@Post('verify-otp')
@HttpCode(HttpStatus.OK)
@Throttle({ otp: {} })
public async verifyOTP(@Body() verifyOtpDto: VerifyOtpDTO) {
return await this.authService.verifyOTP(verifyOtpDto);
}
@@ -31,6 +34,7 @@ export class AuthController {
@Public()
@Post('refresh')
@HttpCode(HttpStatus.OK)
@Throttle({ login: {} })
public async refreshToken(@Body() refreshTokenDto: RefreshTokenDTO) {
return await this.authService.refreshToken(refreshTokenDto);
}