No description
Find a file
valentinbvro 5a1206118a security: enforce TenantGuard and ThrottlerGuard globally, lock down CORS
Both guards were fully implemented but never actually wired in -- Nest
doesn't enforce a guard just because its module is imported, it needs
an explicit APP_GUARD registration. Registered both globally so every
new controller is deny-by-default and rate-limited unless it opts out.

Added a @Public() decorator (checked via Reflector in TenantGuard) for
routes that legitimately have no session, applied it to /health so the
global guard doesn't break it.

CORS was wide open (enableCors() with no origin restriction, effectively
allow-any-origin). Now reads an explicit CORS_ORIGINS allowlist from env,
defaulting to localhost:3000 for local dev.
2026-07-21 19:48:17 +02:00
drizzle feat: scaffold Business/Life/Intelligence/Trust Engine tables 2026-07-21 19:44:45 +02:00
src security: enforce TenantGuard and ThrottlerGuard globally, lock down CORS 2026-07-21 19:48:17 +02:00
.dockerignore fix: correct ceo-api Dockerfile port and dependency install 2026-07-21 02:50:53 +02:00
.env.example security: enforce TenantGuard and ThrottlerGuard globally, lock down CORS 2026-07-21 19:48:17 +02:00
.gitignore feat: scaffold NestJS API skeleton with health check 2026-07-20 22:26:33 +02:00
Dockerfile fix: force devDependencies install in ceo-api Docker build stage 2026-07-21 12:03:42 +02:00
drizzle.config.ts feat: add Drizzle ORM, Supabase admin client, Swagger, Helmet, Pino logging, rate limiting 2026-07-20 22:41:09 +02:00
nest-cli.json feat: scaffold NestJS API skeleton with health check 2026-07-20 22:26:33 +02:00
package-lock.json feat: scaffold Identity Engine (CASL/tenant guard) and Event Fabric (outbox) 2026-07-21 02:46:35 +02:00
package.json feat: scaffold Identity Engine (CASL/tenant guard) and Event Fabric (outbox) 2026-07-21 02:46:35 +02:00
README.md feat: add Drizzle ORM, Supabase admin client, Swagger, Helmet, Pino logging, rate limiting 2026-07-20 22:41:09 +02:00
tsconfig.json fix: scope tsconfig to src/ so nest build emits dist/main.js 2026-07-21 12:07:06 +02:00

ceo-api

NestJS API pentru CEO-OS. Se conecteaza la Supabase (Postgres/Auth) si Redis, deployat prin Coolify pe proiectul CEO-OS.

Dezvoltare

npm install
cp .env.example .env
npm run start:dev

GET /health returneaza statusul serviciului. GET /docs expune Swagger UI.

Stack

NestJS, Drizzle ORM (src/db), Supabase Admin SDK (src/supabase), BullMQ/Redis, class-validator/Zod, Helmet, rate limiting (Throttler), logging Pino.

Migratii

npm run db:generate
npm run db:migrate