NestJS 用 Better Auth:@AllowAnonymous、@OptionalAuth、@Session 付きグローバルガード
コード3 ファイルコンテキスト約 369 トークンスキャン合格
インストール
$
genpm add @yohangel/auth-nest含まれるもの
- src/lib/auth-nest/ にソースコード(3 ファイル)。 (3.3 KB)
- src/lib/auth-nest/AGENTS.md に AI ルール、加えて IDE 用のルールファイル。
- @yohangel/auth を自動で解決します。
README
このパッケージには README がありません。
約 369 トークン→ src/lib/auth-nest/AGENTS.md→ .cursor/rules/genpm-yohangel-auth-nest.mdc
これは AI が src/lib/auth-nest で作業するときに読む内容そのものです。それ以外はコンテキストに追加されません。
@yohangel/auth-nest — rules for AI agents
Purpose
Connects @yohangel/auth to NestJS (Express platform) through @thallesp/nestjs-better-auth: Better Auth routes on /api/auth/* and a GLOBAL guard — every route requires a session unless marked otherwise.
Module map
index.ts—authModule(opts), and the decoratorsAllowAnonymous,OptionalAuth,Session, typeUserSession,AuthGuard.
Integration (do this after installing)
main.ts:const app = await NestFactory.create(AppModule, { bodyParser: false });(required).app.module.ts:imports: [authModule({ sendEmail })].- Public routes:
@AllowAnonymous()on the handler or controller. Optional session:@OptionalAuth(). - Read the user:
me(@Session() session: UserSession) { return session.user; }. - Fastify is not supported by this package; use the Express platform.
Conventions
- Default-deny: new controllers are private automatically; mark public ones explicitly and review every
@AllowAnonymous(). - System roles need Better Auth's
admin()plugin (createAuth({ plugins: [admin()] })) and@Roles(['admin'])from@thallesp/nestjs-better-auth; organization roles use@OrgRoles— never mix them.
Don't
- Don't re-enable Nest's body parser globally (
bodyParser: true): it breaks Better Auth. - Don't disable the global guard to "make it work"; add
@AllowAnonymous()where intended. - Don't return the session token or
sessionobject to clients.
# @yohangel/auth-nest — rules for AI agents
## Purpose
Connects `@yohangel/auth` to NestJS (Express platform) through `@thallesp/nestjs-better-auth`: Better Auth routes on `/api/auth/*` and a GLOBAL guard — every route requires a session unless marked otherwise.
## Module map
- `index.ts` — `authModule(opts)`, and the decorators `AllowAnonymous`, `OptionalAuth`, `Session`, type `UserSession`, `AuthGuard`.
## Integration (do this after installing)
1. `main.ts`: `const app = await NestFactory.create(AppModule, { bodyParser: false });` (required).
2. `app.module.ts`: `imports: [authModule({ sendEmail })]`.
3. Public routes: `@AllowAnonymous()` on the handler or controller. Optional session: `@OptionalAuth()`.
4. Read the user: `me(@Session() session: UserSession) { return session.user; }`.
5. Fastify is not supported by this package; use the Express platform.
## Conventions
- Default-deny: new controllers are private automatically; mark public ones explicitly and review every `@AllowAnonymous()`.
- System roles need Better Auth's `admin()` plugin (`createAuth({ plugins: [admin()] })`) and `@Roles(['admin'])` from `@thallesp/nestjs-better-auth`; organization roles use `@OrgRoles` — never mix them.
## Don't
- Don't re-enable Nest's body parser globally (`bodyParser: true`): it breaks Better Auth.
- Don't disable the global guard to "make it work"; add `@AllowAnonymous()` where intended.
- Don't return the session token or `session` object to clients.
.genpmignore 適用後に組み込まれる正確なツリーです。固定先:
このパッケージは MCP サーバーを宣言していません。
| バージョン | コミット | 公開日 | スキャン |
|---|---|---|---|
| 1.0.0 | 7145b9d | 2 時間前 | ✔ スキャン合格 |
- 提案
- GenPM は npm コマンドを提案し、あなたが承認した場合にのみ実行します。
- スキャン
- スキャン合格 · 指摘 0 件
- コミット
- auth-nest@1.0.0 → 7145b9d58055b5145085782c958b7577f1d65276 · 取得後に検証済み
- スクリプト
- なし。GenPM はパッケージのコードを実行しません。
- ライセンス
- MIT
- 報告
- 問題を見つけましたか?