Security
The generated app includes a baseline security stack: rate limiting, CSRF protection, Helmet headers, CORS, global validation, and a global exception filter. These are wired in main.ts and the SecurityModule.
Rate limiting
Section titled “Rate limiting”RateLimitingModule registers a global ThrottlerGuard using Redis storage. The limits are read from app.config.ts and apply to all routes unless explicitly skipped.
ThrottlerModule.forRootAsync({ useFactory: (configService, redisConf) => ({ storage: new ThrottlerStorageRedisService({ host: redisConf.host, port: redisConf.port, db: 2, }), throttlers: [ { name: 'global', limit: configService.throttler.limit, ttl: configService.throttler.ttl, blockDuration: configService.throttler.blockDuration, ignoreUserAgents: configService.throttler.ignoreUserAgents, }, ], }),})Use @SkipThrottle() to bypass it for specific routes or controllers.
CSRF protection
Section titled “CSRF protection”main.ts applies doubleCsrf from csrf-csrf. It uses the session ID to generate a double-submit cookie token. The client must send the token back in a header or form field for mutating requests.
The cookie name is __Host-psifi.x-csrf-token. The current configuration is set for development (secure: false). Change this to secure: true and sameSite: 'strict' or 'lax' in production.
Helmet and CORS
Section titled “Helmet and CORS”Helmet sets security headers including a content security policy. CORS is configured to allow the frontend URL from the FRONTEND_URL environment variable. Update both for production.
Global validation
Section titled “Global validation”ValidationPipe is registered globally with:
whitelist: true— strips unknown properties.transform: true— transforms payloads to DTO instances.forbidUnknownValues: true— rejects unknown nested objects.
Exception filter
Section titled “Exception filter”HttpExceptionFilter catches HttpException and returns a consistent JSON error response:
{ "statusCode": 401, "message": "Unauthorized", "success": false, "timestamp": "2025-..."}Cookie parser
Section titled “Cookie parser”cookie-parser is installed and registered in main.ts before the session middleware so CSRF protection can read req.signedCookies.
Security checklist before production
Section titled “Security checklist before production”- Change CSRF
getSecretto a real secret from the environment. - Enable
secure: trueon CSRF and session cookies. - Restrict CORS origins to known domains.
- Review Helmet CSP directives for your frontend assets.
- Move rate-limiting thresholds to values that match your traffic.