# @payk/nestjs-private-api-guard

> A NestJS API guard to block request to private apis

Latest version **1.1.0** (published 2020-02-24) · ISC license · 0 weekly downloads

## Install

```sh
npm install @payk/nestjs-private-api-guard
pnpm add @payk/nestjs-private-api-guard
yarn add @payk/nestjs-private-api-guard
bun add @payk/nestjs-private-api-guard
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.1.0 |
| Published | 2020-02-24 |
| First published | 2020-02-23 |
| Weekly downloads | 0 |
| License | ISC |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 2 |
| Unpacked size | 18 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Author | Dan Shapir |
| Maintainers | dankopayk, danpayk, one_eye_jackei, oromano |
| Keywords | nest, nestjs, guard, private, api |

## Links

- npm: https://www.npmjs.com/package/@payk/nestjs-private-api-guard
- npm.io page: https://npm.io/package/@payk/nestjs-private-api-guard

## Dependencies (2)

- [tslint](https://npm.io/package/tslint.md) ^5.20.1
- [typescript](https://npm.io/package/typescript.md) ^3.7.2

## Recent versions

- 1.1.0 (latest) — 2020-02-24
- 1.0.4 — 2020-02-23
- 1.0.3 — 2020-02-23
- 1.0.2 — 2020-02-23
- 1.0.1 — 2020-02-23
- 1.0.0 — 2020-02-23

## README

<h1 align="center">
@payk/nestjs-private-api-guard
</h1>
<p align="center">
  <a href="http://nestjs.com"><img src="https://nestjs.com/img/logo_text.svg" width="320" /></a>
</p>

<p align="center">
 API Protection for <a href="https://github.com/nestjs/nest">NestJS</a>
  <br /><br />

  [![Build Status](https://dev.azure.com/payk/PayK%20Public/_apis/build/status/pay-k.nestjs-response-utils?branchName=master)](https://dev.azure.com/payk/PayK%20Public/_build/latest?definitionId=12&branchName=master)

## Installation
```
npm install @payk/nestjs-private-api-guard
```


## What does it do?

## Quick Start
Add a Global Guard
in the `main.ts` after the `app` creation
```ts
  app.useGlobalGuards(new PrivateApiGuard(app.get(Reflector)));
```

### Public End-Point
Each call coming from outside the internal network will carry a header stating it came from the public.
Add a decorator on top of your api end point you wish to expose through the Gateway
```ts
@PublicApi()
@Get()
getAllUsers() {
  return [];
}
```

Any end-point without the `@PublicApi` decorator won't be accessible through the gateway.

The header being used is by default `X-Public-Api` and is `true` when coming from the public domain.

You can choose a different header key name by passing the `PrivateApiGuard` another parameter:
```ts
  app.useGlobalGuards(new PrivateApiGuard(app.get(Reflector), 'X-My-Cool-Public'));
```

### Consumer Group End-Point (ACL)
Each OAuth2 consumer has groups defined on him. We can use those groups in order to define access to specific end-point - for example, only the BackOffice can access that end-point, not the mobile (it's not per user, it's per consumer)
Add a decorator on top of your api end point you wish to expose through the Gateway to a list of groups
```ts
@AllowedConsumerGroups('backoffice', 'admins')
@Get()
getAllUsers() {
  return [];
}
```

---
_Source: https://npm.io/package/@payk/nestjs-private-api-guard · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
