{"_id":"@bizyukov/nestjs-role-auth","name":"@bizyukov/nestjs-role-auth","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@bizyukov/nestjs-role-auth","version":"1.0.0","description":"Opinionated role-based access control + JWT authentication for NestJS","main":"dist/index.js","types":"dist/index.d.ts","scripts":{"build":"tsc","prepublishOnly":"npm run build"},"keywords":["nestjs","role","guard","jwt","auth","rbac","authorization","authentication"],"author":{"name":"bizyukov"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/bizyukov/nestjs-role-auth.git"},"peerDependencies":{"@nestjs/common":"^11.0.0","@nestjs/core":"^11.0.0","@nestjs/passport":"^11.0.0","@nestjs/jwt":"^11.0.0","passport":"^0.7.0","passport-jwt":"^4.0.1","reflect-metadata":"^0.2.0"},"devDependencies":{"typescript":"^5.5.0","@types/node":"^22.0.0","@types/passport-jwt":"^4.0.1"},"_id":"@bizyukov/nestjs-role-auth@1.0.0","gitHead":"9b10e9a5a16d2f6ab64d64d9be4c7e74e38c36ab","bugs":{"url":"https://github.com/bizyukov/nestjs-role-auth/issues"},"homepage":"https://github.com/bizyukov/nestjs-role-auth#readme","_nodeVersion":"22.16.0","_npmVersion":"11.5.2","dist":{"integrity":"sha512-ZgVLSGM83lYMlyOeWjMc36fX6VHSOPHy8OBB0eNBezml1pbwsi2xzvpg6gY/ijjTkgH8N77MOFLyKP/qqoO7UQ==","shasum":"a2b9894bb817267328eec64234db12007a17f165","tarball":"https://registry.npmjs.org/@bizyukov/nestjs-role-auth/-/nestjs-role-auth-1.0.0.tgz","fileCount":32,"unpackedSize":24569,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIAbqIdXwVHs8gqqrl8dYafViGeOtqeZMTSybhiQF7jb5AiBWuWLIcJPBWyU/G6W0uOzD/syN/19r5s5wKaIArrC9iA=="}]},"_npmUser":{"name":"bizyukov","email":"bizykov@gmail.com"},"directories":{},"maintainers":[{"name":"bizyukov","email":"bizykov@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/nestjs-role-auth_1.0.0_1776974765079_0.6437900838220811"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-23T20:06:04.916Z","1.0.0":"2026-04-23T20:06:05.231Z","modified":"2026-04-23T20:06:05.523Z"},"maintainers":[{"name":"bizyukov","email":"bizykov@gmail.com"}],"description":"Opinionated role-based access control + JWT authentication for NestJS","homepage":"https://github.com/bizyukov/nestjs-role-auth#readme","keywords":["nestjs","role","guard","jwt","auth","rbac","authorization","authentication"],"repository":{"type":"git","url":"git+https://github.com/bizyukov/nestjs-role-auth.git"},"author":{"name":"bizyukov"},"bugs":{"url":"https://github.com/bizyukov/nestjs-role-auth/issues"},"license":"MIT","readme":"# @bizyukov/nestjs-role-auth\r\n\r\n[![npm version](https://img.shields.io/npm/v/@bizyukov/nestjs-role-auth.svg)](https://www.npmjs.com/package/@bizyukov/nestjs-role-auth)\r\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\r\n[![NestJS](https://img.shields.io/badge/NestJS-%5E11.0.0-red)](https://nestjs.com)\r\n\r\nPlug-and-play **role-based authorization** and **JWT authentication** for NestJS.\r\n\r\nZero-config for common use cases, fully configurable for advanced scenarios.\r\n\r\n## Features\r\n\r\n- 🛡️ **RolesGuard** – restrict endpoints to specific roles\r\n- 🔐 **JwtAuthGuard** – combines JWT authentication with optional role checks\r\n- 🧩 Custom role extraction – supports arrays, custom logic, or multiple roles per user\r\n- 🌍 Global module – import `RoleAuthModule.forRoot()` once\r\n- 🪶 Lightweight – no additional dependencies beyond Passport/JWT\r\n\r\n## Installation\r\n\r\n```bash\r\nnpm install @bizyukov/nestjs-role-auth passport passport-jwt @nestjs/passport @nestjs/jwt\r\n```\r\n\r\nMake sure you have a JWT strategy configured. See NestJS Authentication docs.\r\n\r\n## Quick Start\r\n### 1. Import the module globally\r\n```typescript\r\n// app.module.ts\r\nimport { Module } from '@nestjs/common';\r\nimport { RoleAuthModule } from '@bizyukov/nestjs-role-auth';\r\n\r\n@Module({\r\n  imports: [\r\n    RoleAuthModule.forRoot(),\r\n    // ... other modules\r\n  ],\r\n})\r\nexport class AppModule {}\r\n```\r\n\r\n### 2. Protect routes with @Roles() and JwtAuthGuard\r\n```typescript\r\n// admin.controller.ts\r\nimport { Controller, Get, UseGuards } from '@nestjs/common';\r\nimport { JwtAuthGuard, Roles, UserRole } from '@bizyukov/nestjs-role-auth';\r\n\r\n@Controller('admin')\r\n@UseGuards(JwtAuthGuard)\r\nexport class AdminController {\r\n  @Get()\r\n  @Roles(UserRole.ADMIN)\r\n  findAll() {\r\n    return 'This is only for admins';\r\n  }\r\n\r\n  @Get('dashboard')\r\n  @Roles(UserRole.ADMIN, UserRole.MANAGER)\r\n  dashboard() {\r\n    return 'Admins and managers can see this';\r\n  }\r\n}\r\n```\r\nNow only authenticated users with the required roles can access these endpoints.\r\n\r\n## Advanced Configuration\r\n### Custom role extraction\r\nBy default the guard reads user.role (single string). You can change this globally:\r\n```typescript\r\nRoleAuthModule.forRoot({\r\n  rolesExtractor: (user) => user.roles ?? [user.role], // supports arrays\r\n})\r\n```\r\n\r\n## Using only the RolesGuard (without JWT)\r\nIf you already have authentication handled, you can use RolesGuard directly:\r\n```typescript\r\n@UseGuards(MyAuthGuard, RolesGuard)\r\n@Roles(UserRole.ADMIN)\r\n```\r\n\r\n## API Reference\r\n\r\n| Export | Description |\r\n| :--- | :--- |\r\n| `RoleAuthModule.forRoot(options?)` | Глобальная регистрация модуля |\r\n| `Roles(...roles: UserRole[])` | Декоратор для установки необходимых ролей |\r\n| `RolesGuard` | Guard, который проверяет метаданные `@Roles()` |\r\n| `JwtAuthGuard` | Guard, выполняющий JWT-авторизацию и проверку ролей |\r\n| `UserRole` | Enum стандартных ролей (`USER`, `ADMIN`, `MANAGER`, `CONTENT`) |\r\n| `RoleAuthModuleOptions` | Интерфейс для настройки `rolesExtractor` |\r\n\r\n## Compatibility\r\n\r\n* **NestJS**: 11+\r\n* **Dependencies**: `passport`, `passport-jwt`\r\n\r\n## License\r\n\r\nMIT © 2025 bizyukov\r\n","readmeFilename":"README.md","_rev":"1-d27bf146fd6a4d2b6c8bf65eee06b407"}