docs: add NestJS security cheatsheet #1988
docs: add NestJS security cheatsheet #1988Riya-chandra wants to merge 3 commits intoOWASP:masterfrom
Conversation
jmanico
left a comment
There was a problem hiding this comment.
This is a well organized piece of work and I like it.
|
@jmanico Thankyou sir |
|
Great contribution! This will be helpful for the community. 🔥 |
|
Thanks for the great work! |
|
Please carefully add your new cheatsheet here in this PR. https://github.com/OWASP/CheatSheetSeries/blob/master/Index.md |
|
@jmanico i have added the cheatsheet in the index.md......please have a look |
jmanico
left a comment
There was a problem hiding this comment.
Please give us time for the other reviewers to review this.
|
lint errors in markdown: cheatsheets/NestJs_Security_Cheat_Sheet.md:31 MD031/blanks-around-fences Fenced code blocks should be surrounded by blank lines [Context: " |
Description
This PR introduces a new mini-cheatsheet specifically for NestJS security best practices. While the current Node.js sheet covers Express, this addition provides framework-native patterns for NestJS's unique architecture.
Key Sections:
Request Lifecycle: Strategic placement of security controls across Middleware, Guards, and Pipes.
Input Validation: Strict ValidationPipe setup to mitigate Mass Assignment risks.
Secure Defaults: Hardened Helmet and CORS configurations.
This PR fixes issue #1986.
Verification Results
Technical Accuracy: Snippets verified against NestJS v10+ standards.
Local Build: Verified that the new sheet renders correctly in the navigation under "Languages and Frameworks" using mkdocs serve.
Style: Content is kept concise as requested by the maintainers.
Thank you!