Better Auth para NestJS: guard global com @AllowAnonymous, @OptionalAuth e @Session
Código3 arquivosContexto~369 tokensanálise aprovada
Instalar
$
genpm add @yohangel/auth-nestO que você recebe
- Código em src/lib/auth-nest/, 3 arquivos. (3,3 kB)
- Regras de IA em src/lib/auth-nest/AGENTS.md, mais arquivos de regras da IDE.
- Resolve @yohangel/auth para você.
README
Este pacote não tem README.
~369 tokens→ src/lib/auth-nest/AGENTS.md→ .cursor/rules/genpm-yohangel-auth-nest.mdc
Isto é exatamente o que sua IA lê quando trabalha em src/lib/auth-nest. Nada mais é adicionado ao contexto dela.
@yohangel/auth-nest — rules for AI agents
Purpose
Connects @yohangel/auth to NestJS (Express platform) through @thallesp/nestjs-better-auth: Better Auth routes on /api/auth/* and a GLOBAL guard — every route requires a session unless marked otherwise.
Module map
index.ts—authModule(opts), and the decoratorsAllowAnonymous,OptionalAuth,Session, typeUserSession,AuthGuard.
Integration (do this after installing)
main.ts:const app = await NestFactory.create(AppModule, { bodyParser: false });(required).app.module.ts:imports: [authModule({ sendEmail })].- Public routes:
@AllowAnonymous()on the handler or controller. Optional session:@OptionalAuth(). - Read the user:
me(@Session() session: UserSession) { return session.user; }. - Fastify is not supported by this package; use the Express platform.
Conventions
- Default-deny: new controllers are private automatically; mark public ones explicitly and review every
@AllowAnonymous(). - System roles need Better Auth's
admin()plugin (createAuth({ plugins: [admin()] })) and@Roles(['admin'])from@thallesp/nestjs-better-auth; organization roles use@OrgRoles— never mix them.
Don't
- Don't re-enable Nest's body parser globally (
bodyParser: true): it breaks Better Auth. - Don't disable the global guard to "make it work"; add
@AllowAnonymous()where intended. - Don't return the session token or
sessionobject to clients.
# @yohangel/auth-nest — rules for AI agents
## Purpose
Connects `@yohangel/auth` to NestJS (Express platform) through `@thallesp/nestjs-better-auth`: Better Auth routes on `/api/auth/*` and a GLOBAL guard — every route requires a session unless marked otherwise.
## Module map
- `index.ts` — `authModule(opts)`, and the decorators `AllowAnonymous`, `OptionalAuth`, `Session`, type `UserSession`, `AuthGuard`.
## Integration (do this after installing)
1. `main.ts`: `const app = await NestFactory.create(AppModule, { bodyParser: false });` (required).
2. `app.module.ts`: `imports: [authModule({ sendEmail })]`.
3. Public routes: `@AllowAnonymous()` on the handler or controller. Optional session: `@OptionalAuth()`.
4. Read the user: `me(@Session() session: UserSession) { return session.user; }`.
5. Fastify is not supported by this package; use the Express platform.
## Conventions
- Default-deny: new controllers are private automatically; mark public ones explicitly and review every `@AllowAnonymous()`.
- System roles need Better Auth's `admin()` plugin (`createAuth({ plugins: [admin()] })`) and `@Roles(['admin'])` from `@thallesp/nestjs-better-auth`; organization roles use `@OrgRoles` — never mix them.
## Don't
- Don't re-enable Nest's body parser globally (`bodyParser: true`): it breaks Better Auth.
- Don't disable the global guard to "make it work"; add `@AllowAnonymous()` where intended.
- Don't return the session token or `session` object to clients.
A árvore exata que será injetada, após o .genpmignore. Fixada em
Este pacote não declara servidores MCP.
| Versão | Commit | Publicado | Análise |
|---|---|---|---|
| 1.0.0 | 7145b9d | há 2 horas | ✔ análise aprovada |
- proposto
- O GenPM propõe o comando npm e só o executa se você disser sim.
- análise
- análise aprovada · 0 achados
- commit
- auth-nest@1.0.0 → 7145b9d58055b5145085782c958b7577f1d65276 · verificado após o download
- scripts
- Nenhum. O GenPM nunca executa código de pacotes.
- licença
- MIT
- denúncia
- Viu algo errado?