生活与工具
#security
nestjs-security
Implement JWT authentication, RBAC guards, Helmet hardening, and Argon2 hashing in NestJS. Use when adding auth strategies, role-based access control, CSRF protection, or security headers.
DeepseekModel
官方收录技能
质量 优秀 · 90
v1.0.0
获取
https://deepseekmodel.com/api/download.php?id=hoangnguyen0403-agent-skills-standard-skills-nestjs-nestjs-security-skill-md&format=skill
下载 .skill
标准格式,含 system_prompt 与 model_config,导入任意 Agent 框架即可使用
.skill 文件中 system_prompt 字段的实际内容。
name nestjs-security description Implement JWT authentication, RBAC guards, Helmet hardening, and Argon2 hashing in NestJS. Use when adding auth strategies, role-based access control, CSRF protection, or security headers. metadata {"triggers":{"files":["**/*.guard.ts","**/*.strategy.ts","**/auth/**"],"keywords":["Passport","JWT","AuthGuard","CSRF","Helmet"]}} NestJS Security Standards Priority: P0 (CRITICAL) Workflow: Secure NestJS Application Add Helmet — app.use(helmet()) in main.ts for HSTS, CSP headers. Configure JWT strategy — Use passport-jwt with RS256; validate iss and aud claims. Bind global AuthGuard — Register as APP_GUARD ; use @Public() for open routes. Add throttling — Enable @nestjs/throttler with Redis store for rate limiting. Hash with Argon2id — Replace bcrypt with argon2.hash(password, { type: argon2.argon2id }) . Verify — Run npm audit --prod and test that unauthenticated requests return 401. Global Auth Guard Example See implementation examples Argon2id Hashing Example See implementation examples Authentication (JWT) Strategy : Use @nestjs/passport with passport-jwt . Algorithm : Enforce RS256 (preferred) or HS256 . Reject none . Claims : Validate iss and aud . Tokens : Short access (15m), Long httponly refresh (7d). MFA : Require 2FA for admin panels. Authorization (RBAC) Deny by default : Bind AuthGuard globally (APP_GUARD). Bypass : Create @Public() decorator for open routes. Roles : Use Reflector.getAllAndOverride for Method/Class merge. Cryptography Hashing : Use Argon2id , not Bcrypt. See implementation . Encryption : Use AES-256-GCM with KMS rotation. See implementation . Hardening Helmet : Mandatory. Enable HSTS, CSP. CORS : Explicit origins only. No * . Throttling : Use Redis-backed @nestjs/throttler in production. CSRF : Required for cookie-based auth. See implementation . Data Protection Sanitization : Use ClassSerializerInterceptor + @Exclude() . Validation : ValidationPipe({ whitelist: true }) to prevent mass assignment. Audit : Log mutations (Who, What, When). See implementation . Secrets Management CI/CD : Run npm audit --prod in pipelines. Runtime : Inject via vault (AWS Secrets Manager / HashiCorp Vault), not .env . Anti-Patterns No Shadow APIs : Audit routes regularly; disable /docs in production. No SSRF : Allowlist domains for all outgoing HTTP requests. No SQLi : Use ORM; avoid raw query() with string concatenation. No XSS : Sanitize HTML input with dompurify . References Implementation Examples common/security-standards
Agent 识别该技能的关键词,点击任意一个即可复制。
该技能未提供触发词。
下载的 .skill 包内含以下字段。
| 字段 | 说明 |
|---|---|
| format | 格式标识(skill/v1) |
| skill_id | 技能唯一 ID |
| name | 技能名称 |
| version | 版本号 |
| description | 技能描述 |
| category | 所属分类(数组) |
| trigger_words | 触发词列表 |
| tags | 标签列表 |
| source | 来源标识 |
| source_url | 来源链接(本页地址) |
| exported_at | 导出时间(每次下载生成) |
| system_prompt | 系统提示词正文 |
| model_config | 模型参数:provider / model / temperature / max_tokens / top_p |
| examples | 示例 |
| install_guide | 各平台导入说明(Coze / Dify / Claude / 自定义框架) |