NestJS용 Better Auth: @AllowAnonymous, @OptionalAuth, @Session을 갖춘 전역 가드
코드파일 3개컨텍스트약 369토큰검사 통과
설치
$
genpm add @yohangel/auth-nest포함 내용
- src/lib/auth-nest/에 소스 코드, 파일 3개. (3.3kB)
- src/lib/auth-nest/AGENTS.md에 AI 규칙, 그리고 IDE 규칙 파일.
- @yohangel/auth을(를) 자동으로 해결합니다.
README
이 패키지에는 README가 없습니다.
약 369토큰→ src/lib/auth-nest/AGENTS.md→ .cursor/rules/genpm-yohangel-auth-nest.mdc
이것이 AI가 src/lib/auth-nest에서 작업할 때 읽는 내용 그대로입니다. 그 외에는 컨텍스트에 아무것도 추가되지 않습니다.
@yohangel/auth-nest — rules for AI agents
Purpose
Connects @yohangel/auth to NestJS (Express platform) through @thallesp/nestjs-better-auth: Better Auth routes on /api/auth/* and a GLOBAL guard — every route requires a session unless marked otherwise.
Module map
index.ts—authModule(opts), and the decoratorsAllowAnonymous,OptionalAuth,Session, typeUserSession,AuthGuard.
Integration (do this after installing)
main.ts:const app = await NestFactory.create(AppModule, { bodyParser: false });(required).app.module.ts:imports: [authModule({ sendEmail })].- Public routes:
@AllowAnonymous()on the handler or controller. Optional session:@OptionalAuth(). - Read the user:
me(@Session() session: UserSession) { return session.user; }. - Fastify is not supported by this package; use the Express platform.
Conventions
- Default-deny: new controllers are private automatically; mark public ones explicitly and review every
@AllowAnonymous(). - System roles need Better Auth's
admin()plugin (createAuth({ plugins: [admin()] })) and@Roles(['admin'])from@thallesp/nestjs-better-auth; organization roles use@OrgRoles— never mix them.
Don't
- Don't re-enable Nest's body parser globally (
bodyParser: true): it breaks Better Auth. - Don't disable the global guard to "make it work"; add
@AllowAnonymous()where intended. - Don't return the session token or
sessionobject to clients.
# @yohangel/auth-nest — rules for AI agents
## Purpose
Connects `@yohangel/auth` to NestJS (Express platform) through `@thallesp/nestjs-better-auth`: Better Auth routes on `/api/auth/*` and a GLOBAL guard — every route requires a session unless marked otherwise.
## Module map
- `index.ts` — `authModule(opts)`, and the decorators `AllowAnonymous`, `OptionalAuth`, `Session`, type `UserSession`, `AuthGuard`.
## Integration (do this after installing)
1. `main.ts`: `const app = await NestFactory.create(AppModule, { bodyParser: false });` (required).
2. `app.module.ts`: `imports: [authModule({ sendEmail })]`.
3. Public routes: `@AllowAnonymous()` on the handler or controller. Optional session: `@OptionalAuth()`.
4. Read the user: `me(@Session() session: UserSession) { return session.user; }`.
5. Fastify is not supported by this package; use the Express platform.
## Conventions
- Default-deny: new controllers are private automatically; mark public ones explicitly and review every `@AllowAnonymous()`.
- System roles need Better Auth's `admin()` plugin (`createAuth({ plugins: [admin()] })`) and `@Roles(['admin'])` from `@thallesp/nestjs-better-auth`; organization roles use `@OrgRoles` — never mix them.
## Don't
- Don't re-enable Nest's body parser globally (`bodyParser: true`): it breaks Better Auth.
- Don't disable the global guard to "make it work"; add `@AllowAnonymous()` where intended.
- Don't return the session token or `session` object to clients.
.genpmignore 적용 후 주입될 정확한 트리입니다. 고정 대상:
// @yohangel/auth-nest — Better Auth en NestJS (plataforma Express) vía @thallesp/nestjs-better-auth.
// Registra un AuthGuard GLOBAL: toda ruta exige sesión salvo @AllowAnonymous() u @OptionalAuth().
// main.ts: `NestFactory.create(AppModule, { bodyParser: false })` (Better Auth lee el cuerpo; el módulo vuelve a
// activar json/urlencoded para el resto de rutas).
import { AuthModule } from '@thallesp/nestjs-better-auth';
import { type CreateAuthOptions, createAuth } from '../auth/index.js';
/** `imports: [authModule()]` en tu AppModule. */
export function authModule(opts: CreateAuthOptions = {}) {
return AuthModule.forRoot({ auth: createAuth(opts) });
}
export {
AllowAnonymous,
AuthGuard,
OptionalAuth,
Session,
type UserSession,
} from '@thallesp/nestjs-better-auth';
이 패키지는 MCP 서버를 선언하지 않습니다.
| 버전 | 커밋 | 게시일 | 검사 |
|---|---|---|---|
| 1.0.0 | 7145b9d | 3시간 전 | ✔ 검사 통과 |
- 제안됨
- GenPM은 npm 명령을 제안하고, 동의한 경우에만 실행합니다.
- 검사
- 검사 통과 · 문제 0건
- 커밋
- auth-nest@1.0.0 → 7145b9d58055b5145085782c958b7577f1d65276 · 가져온 뒤 검증됨
- 스크립트
- 없음. GenPM은 패키지 코드를 절대 실행하지 않습니다.
- 라이선스
- MIT
- 신고
- 문제가 있나요?