NestJS
TypeScript server framework with dependency injection, modules and decorators.
The rule
This is the whole text, exactly as your agent receives it. Nothing is held back for the paid tier.
Validation
ValidationPipeis registered globally withwhitelist: trueandforbidNonWhitelisted: true. Withoutwhitelist, unknown properties in the body reach your service — that is how a profile update smuggles inrole.- DTOs are classes with `class-validator` decorators. An interface does not exist at runtime and validates nothing.
Auth
- Guards, applied globally, with public routes opted out explicitly. Per-route guards mean the one you forget is the one that leaks.
- Never take a user id from the request body; derive it from the verified token.
Structure
- Controllers are thin: parse, delegate to a service, return.
- Business logic lives in providers so it can be tested without HTTP.
- One module per feature; export only what other modules genuinely need.
Responses
- Map entities to response DTOs. Returning an ORM entity serialises whatever is on it, including fields no client should see.
- Never return a raw error or stack trace to a client.
Never
- Never put an interface where a DTO class belongs.
- Never disable
whitelistto make a request work — fix the DTO. - Never log secrets, tokens or personal data.
6 formats, one per tool
Each tab is the file that tool actually reads, at the path it actually looks in. Knowing where each one looks is most of the work of supporting it.
---
description: NestJS conventions
globs: ["src/**/*.controller.ts", "src/**/*.service.ts", "src/**/*.module.ts", "src/**/dto/**"]
alwaysApply: false
---
# NestJS
## Validation
- `ValidationPipe` is registered globally with `whitelist: true` and
`forbidNonWhitelisted: true`. Without `whitelist`, unknown properties in the
body reach your service — that is how a profile update smuggles in `role`.
- **DTOs are classes with `class-validator` decorators.** An interface does not
exist at runtime and validates nothing.
## Auth
- Guards, applied globally, with public routes opted out explicitly. Per-route
guards mean the one you forget is the one that leaks.
- Never take a user id from the request body; derive it from the verified token.
## Structure
- Controllers are thin: parse, delegate to a service, return.
- Business logic lives in providers so it can be tested without HTTP.
- One module per feature; export only what other modules genuinely need.
## Responses
- Map entities to response DTOs. Returning an ORM entity serialises whatever is
on it, including fields no client should see.
- Never return a raw error or stack trace to a client.
## Never
- Never put an interface where a DTO class belongs.
- Never disable `whitelist` to make a request work — fix the DTO.
- Never log secrets, tokens or personal data.
Hand-written by the module author, frontmatter and all. It is the source the four derived formats are rendered from, so a correction lands here first.
What else this module writes
The rule is one file of several. Selecting NestJS contributes all of this too — merged with every other module you pick, with conflicts resolved rather than duplicated.
PORToptionalPort the server listens on.DATABASE_URLrequiredConnection string. Full access — never in a client.JWT_SECRETrequiredSigns and verifies access tokens. Rotating it invalidates every session.ALLOWED_ORIGINSrequiredComma-separated CORS origins. Never `*` with credentials.Advisory history
Every time this rule turned out to be wrong, and what we did about it.
This rule has been accurate since it was published. That is a fact about the rule, not a promise about the future — which is the whole reason this section exists.
Pro tells you the day a correction lands that affects a repo you actually have.
See what Pro adds →Rules people add alongside this one
The wizard picks the rest of the stack with you, writes all 6 formats, and leaves a manifest so check can tell you when any of it drifts.