@nestarc/api-keys
Classes
ApiKeyError
Defined in: src/errors.ts:31
Extends
HttpExceptionBase
Constructors
Constructor
new ApiKeyError(code, reason?): ApiKeyError;Defined in: src/errors.ts:38
Parameters
| Parameter | Type |
|---|---|
code | ApiKeyErrorCode |
reason? | string |
Returns
Overrides
HttpExceptionBase.constructorProperties
cause
cause: unknown;Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:28
Exception cause. Indicates the specific original cause of the error. It is used when catching and re-throwing an error with a more-specific or useful error message in order to still have access to the original error.
Inherited from
HttpExceptionBase.causecode
readonly code: ApiKeyErrorCode;Defined in: src/errors.ts:32
httpStatus
readonly httpStatus: number;Defined in: src/errors.ts:36
Backward-compatible status property. Prefer Nest's getStatus() for new code.
message
message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077
Inherited from
HttpExceptionBase.messagename
name: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
HttpExceptionBase.namestack?
optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078
Inherited from
HttpExceptionBase.stackstackTraceLimit
static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:68
The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
HttpExceptionBase.stackTraceLimitMethods
captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:52
Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.
The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();Parameters
| Parameter | Type |
|---|---|
targetObject | object |
constructorOpt? | Function |
Returns
void
Inherited from
HttpExceptionBase.captureStackTracecreateBody()
Call Signature
static createBody(
nil,
message,
statusCode): HttpExceptionBody;Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:74
Parameters
| Parameter | Type |
|---|---|
nil | "" | null |
message | HttpExceptionBodyMessage |
statusCode | number |
Returns
HttpExceptionBody
Inherited from
HttpExceptionBase.createBodyCall Signature
static createBody(
message,
error,
statusCode): HttpExceptionBody;Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:75
Parameters
| Parameter | Type |
|---|---|
message | HttpExceptionBodyMessage |
error | string |
statusCode | number |
Returns
HttpExceptionBody
Inherited from
HttpExceptionBase.createBodyCall Signature
static createBody<Body>(custom): Body;Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:76
Type Parameters
| Type Parameter |
|---|
Body extends Record<string, unknown> |
Parameters
| Parameter | Type |
|---|---|
custom | Body |
Returns
Body
Inherited from
HttpExceptionBase.createBodyextractDescriptionAndOptionsFrom()
static extractDescriptionAndOptionsFrom(descriptionOrOptions): DescriptionAndOptions;Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:84
Utility method used to extract the error description and httpExceptionOptions from the given argument. This is used by inheriting classes to correctly parse both options.
Parameters
| Parameter | Type |
|---|---|
descriptionOrOptions | string | HttpExceptionOptions |
Returns
DescriptionAndOptions
the error description and the httpExceptionOptions as an object.
Inherited from
HttpExceptionBase.extractDescriptionAndOptionsFromgetDescriptionFrom()
static getDescriptionFrom(descriptionOrOptions): string;Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:77
Parameters
| Parameter | Type |
|---|---|
descriptionOrOptions | string | HttpExceptionOptions |
Returns
string
Inherited from
HttpExceptionBase.getDescriptionFromgetHttpExceptionOptionsFrom()
static getHttpExceptionOptionsFrom(descriptionOrOptions): HttpExceptionOptions;Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:78
Parameters
| Parameter | Type |
|---|---|
descriptionOrOptions | string | HttpExceptionOptions |
Returns
HttpExceptionOptions
Inherited from
HttpExceptionBase.getHttpExceptionOptionsFromgetResponse()
getResponse(): string | object;Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:72
Returns
string | object
Inherited from
HttpExceptionBase.getResponsegetStatus()
getStatus(): number;Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:73
Returns
number
Inherited from
HttpExceptionBase.getStatusinitCause()
initCause(): void;Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:69
Configures error chaining support
Returns
void
See
- https://nodejs.org/en/blog/release/v16.9.0/#error-cause
- https://github.com/microsoft/TypeScript/issues/45167
Inherited from
HttpExceptionBase.initCauseinitMessage()
initMessage(): void;Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:70
Returns
void
Inherited from
HttpExceptionBase.initMessageinitName()
initName(): void;Defined in: node_modules/@nestjs/common/exceptions/http.exception.d.ts:71
Returns
void
Inherited from
HttpExceptionBase.initNameprepareStackTrace()
static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:56
Parameters
| Parameter | Type |
|---|---|
err | Error |
stackTraces | CallSite[] |
Returns
any
See
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
HttpExceptionBase.prepareStackTraceApiKeyOperationError
Defined in: src/errors.ts:59
Extends
Error
Constructors
Constructor
new ApiKeyOperationError(
code,
reason?,
options?): ApiKeyOperationError;Defined in: src/errors.ts:62
Parameters
| Parameter | Type |
|---|---|
code | ApiKeyOperationErrorCode |
reason? | string |
options? | ErrorOptions |
Returns
Overrides
Error.constructorProperties
cause?
optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26
Inherited from
Error.causecode
readonly code: ApiKeyOperationErrorCode;Defined in: src/errors.ts:60
message
message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077
Inherited from
Error.messagename
name: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
Error.namestack?
optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078
Inherited from
Error.stackstackTraceLimit
static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:68
The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
Error.stackTraceLimitMethods
captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:52
Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.
The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();Parameters
| Parameter | Type |
|---|---|
targetObject | object |
constructorOpt? | Function |
Returns
void
Inherited from
Error.captureStackTraceprepareStackTrace()
static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:56
Parameters
| Parameter | Type |
|---|---|
err | Error |
stackTraces | CallSite[] |
Returns
any
See
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
Error.prepareStackTraceApiKeysGuard
Defined in: src/api-keys.guard.ts:24
Implements
CanActivate
Constructors
Constructor
new ApiKeysGuard(
service,
reflector,
contextWriter?,
clientIpResolver?): ApiKeysGuard;Defined in: src/api-keys.guard.ts:25
Parameters
| Parameter | Type |
|---|---|
service | ApiKeysService |
reflector | Reflector |
contextWriter? | ApiKeyContextWriter |
clientIpResolver? | ApiKeyClientIpResolver |
Returns
Methods
canActivate()
canActivate(context): Promise<boolean>;Defined in: src/api-keys.guard.ts:37
Parameters
| Parameter | Type | Description |
|---|---|---|
context | ExecutionContext | Current execution context. Provides access to details about the current request pipeline. |
Returns
Promise<boolean>
Value indicating whether or not the current request is allowed to proceed.
Implementation of
CanActivate.canActivateApiKeysModule
Defined in: src/api-keys.module.ts:52
Constructors
Constructor
new ApiKeysModule(): ApiKeysModule;Returns
Methods
forRoot()
static forRoot(options): DynamicModule;Defined in: src/api-keys.module.ts:53
Parameters
| Parameter | Type |
|---|---|
options | ApiKeysModuleOptions |
Returns
DynamicModule
ApiKeysService
Defined in: src/api-keys.service.ts:81
Constructors
Constructor
new ApiKeysService(deps): ApiKeysService;Defined in: src/api-keys.service.ts:112
Parameters
| Parameter | Type |
|---|---|
deps | ApiKeysServiceDeps |
Returns
Methods
authorizeRequest()
authorizeRequest(input): Promise<ApiKeyContext>;Defined in: src/api-keys.service.ts:224
Parameters
| Parameter | Type |
|---|---|
input | ApiKeyRequestAuthorizationInput |
Returns
Promise<ApiKeyContext>
create()
create(input): Promise<CreateApiKeyResult>;Defined in: src/api-keys.service.ts:153
Parameters
| Parameter | Type |
|---|---|
input | CreateApiKeyInput |
Returns
Promise<CreateApiKeyResult>
list()
list(tenantId, opts?): Promise<ApiKeySummary[]>;Defined in: src/api-keys.service.ts:601
Parameters
| Parameter | Type |
|---|---|
tenantId | string |
opts | ListApiKeysOptions |
Returns
Promise<ApiKeySummary[]>
revoke()
revoke(id): Promise<void>;Defined in: src/api-keys.service.ts:382
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Promise<void>
revokeForTenant()
revokeForTenant(tenantId, id): Promise<void>;Defined in: src/api-keys.service.ts:400
Parameters
| Parameter | Type |
|---|---|
tenantId | string |
id | string |
Returns
Promise<void>
rotate()
rotate(id, input?): Promise<RotateApiKeyResult>;Defined in: src/api-keys.service.ts:439
Parameters
| Parameter | Type |
|---|---|
id | string |
input | RotateApiKeyInput |
Returns
Promise<RotateApiKeyResult>
rotateForTenant()
rotateForTenant(
tenantId,
id,
input?): Promise<RotateApiKeyResult>;Defined in: src/api-keys.service.ts:446
Parameters
| Parameter | Type |
|---|---|
tenantId | string |
id | string |
input | RotateApiKeyInput |
Returns
Promise<RotateApiKeyResult>
verify()
verify(rawKey): Promise<ApiKeyContext>;Defined in: src/api-keys.service.ts:218
Parameters
| Parameter | Type |
|---|---|
rawKey | string |
Returns
Promise<ApiKeyContext>
ApiKeyStorageContractError
Defined in: src/storage/storage-contract.ts:22
Extends
Error
Constructors
Constructor
new ApiKeyStorageContractError(
adapterName,
check,
cause): ApiKeyStorageContractError;Defined in: src/storage/storage-contract.ts:26
Parameters
| Parameter | Type |
|---|---|
adapterName | string |
check | string |
cause | unknown |
Returns
Overrides
Error.constructorProperties
adapterName
readonly adapterName: string;Defined in: src/storage/storage-contract.ts:23
cause?
optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:26
Inherited from
Error.causecheck
readonly check: string;Defined in: src/storage/storage-contract.ts:24
message
message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1077
Inherited from
Error.messagename
name: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
Error.namestack?
optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1078
Inherited from
Error.stackstackTraceLimit
static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:68
The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
Error.stackTraceLimitMethods
captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:52
Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.
const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.
The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:
function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();Parameters
| Parameter | Type |
|---|---|
targetObject | object |
constructorOpt? | Function |
Returns
void
Inherited from
Error.captureStackTraceprepareStackTrace()
static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:56
Parameters
| Parameter | Type |
|---|---|
err | Error |
stackTraces | CallSite[] |
Returns
any
See
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
Error.prepareStackTraceInMemoryApiKeyStorage
Defined in: src/storage/in-memory-storage.ts:12
Implements
Constructors
Constructor
new InMemoryApiKeyStorage(): InMemoryApiKeyStorage;Returns
Methods
findById()
findById(id): Promise<ApiKeyRecord | null>;Defined in: src/storage/in-memory-storage.ts:29
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Promise<ApiKeyRecord | null>
Implementation of
findByPrefix()
findByPrefix(prefix): Promise<ApiKeyRecord | null>;Defined in: src/storage/in-memory-storage.ts:34
Parameters
| Parameter | Type |
|---|---|
prefix | string |
Returns
Promise<ApiKeyRecord | null>
Implementation of
insert()
insert(record): Promise<void>;Defined in: src/storage/in-memory-storage.ts:15
Parameters
| Parameter | Type |
|---|---|
record | ApiKeyRecord |
Returns
Promise<void>
Implementation of
listByTenant()
listByTenant(tenantId, opts?): Promise<ApiKeyRecord[]>;Defined in: src/storage/in-memory-storage.ts:44
Return tenant records ordered by createdAt descending, then id ascending.
Parameters
| Parameter | Type |
|---|---|
tenantId | string |
opts | ListApiKeysOptions |
Returns
Promise<ApiKeyRecord[]>
Implementation of
markRevoked()
markRevoked(id, at): Promise<void>;Defined in: src/storage/in-memory-storage.ts:53
Parameters
| Parameter | Type |
|---|---|
id | string |
at | Date |
Returns
Promise<void>
Implementation of
revokeForTenant()
revokeForTenant(input): Promise<TenantBoundRevokeApiKeyStorageResult>;Defined in: src/storage/in-memory-storage.ts:62
Parameters
| Parameter | Type |
|---|---|
input | TenantBoundRevokeApiKeyStorageInput |
Returns
Promise<TenantBoundRevokeApiKeyStorageResult>
Implementation of
rotate()
rotate(input): Promise<RotateApiKeyStorageResult>;Defined in: src/storage/in-memory-storage.ts:83
Parameters
| Parameter | Type |
|---|---|
input | RotateApiKeyStorageInput |
Returns
Promise<RotateApiKeyStorageResult>
Implementation of
rotateForTenant()
rotateForTenant(input): Promise<RotateApiKeyStorageResult>;Defined in: src/storage/in-memory-storage.ts:87
Parameters
| Parameter | Type |
|---|---|
input | TenantBoundRotateApiKeyStorageInput |
Returns
Promise<RotateApiKeyStorageResult>
Implementation of
touchLastUsed()
touchLastUsed(id, at): Promise<void>;Defined in: src/storage/in-memory-storage.ts:74
Parameters
| Parameter | Type |
|---|---|
id | string |
at | Date |
Returns
Promise<void>
Implementation of
PrismaApiKeyStorage
Defined in: src/storage/prisma-storage.ts:28
Implements
Constructors
Constructor
new PrismaApiKeyStorage(prisma): PrismaApiKeyStorage;Defined in: src/storage/prisma-storage.ts:29
Parameters
| Parameter | Type |
|---|---|
prisma | PrismaLike |
Returns
Methods
findById()
findById(id): Promise<ApiKeyRecord | null>;Defined in: src/storage/prisma-storage.ts:35
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Promise<ApiKeyRecord | null>
Implementation of
findByPrefix()
findByPrefix(prefix): Promise<ApiKeyRecord | null>;Defined in: src/storage/prisma-storage.ts:45
Parameters
| Parameter | Type |
|---|---|
prefix | string |
Returns
Promise<ApiKeyRecord | null>
Implementation of
insert()
insert(record): Promise<void>;Defined in: src/storage/prisma-storage.ts:31
Parameters
| Parameter | Type |
|---|---|
record | ApiKeyRecord |
Returns
Promise<void>
Implementation of
listByTenant()
listByTenant(tenantId, opts?): Promise<ApiKeyRecord[]>;Defined in: src/storage/prisma-storage.ts:55
Return tenant records ordered by createdAt descending, then id ascending.
Parameters
| Parameter | Type |
|---|---|
tenantId | string |
opts | ListApiKeysOptions |
Returns
Promise<ApiKeyRecord[]>
Implementation of
markRevoked()
markRevoked(id, at): Promise<void>;Defined in: src/storage/prisma-storage.ts:72
Parameters
| Parameter | Type |
|---|---|
id | string |
at | Date |
Returns
Promise<void>
Implementation of
revokeForTenant()
revokeForTenant(input): Promise<TenantBoundRevokeApiKeyStorageResult>;Defined in: src/storage/prisma-storage.ts:76
Parameters
| Parameter | Type |
|---|---|
input | TenantBoundRevokeApiKeyStorageInput |
Returns
Promise<TenantBoundRevokeApiKeyStorageResult>
Implementation of
rotate()
rotate(input): Promise<RotateApiKeyStorageResult>;Defined in: src/storage/prisma-storage.ts:90
Parameters
| Parameter | Type |
|---|---|
input | RotateApiKeyStorageInput |
Returns
Promise<RotateApiKeyStorageResult>
Implementation of
rotateForTenant()
rotateForTenant(input): Promise<RotateApiKeyStorageResult>;Defined in: src/storage/prisma-storage.ts:94
Parameters
| Parameter | Type |
|---|---|
input | TenantBoundRotateApiKeyStorageInput |
Returns
Promise<RotateApiKeyStorageResult>
Implementation of
touchLastUsed()
touchLastUsed(id, at): Promise<void>;Defined in: src/storage/prisma-storage.ts:86
Parameters
| Parameter | Type |
|---|---|
id | string |
at | Date |
Returns
Promise<void>
Implementation of
Sha256Hasher
Defined in: src/hasher.ts:15
Constructors
Constructor
new Sha256Hasher(options): Sha256Hasher;Defined in: src/hasher.ts:16
Parameters
| Parameter | Type |
|---|---|
options | HasherOptions |
Returns
Methods
dummyVerify()
dummyVerify(secret): boolean;Defined in: src/hasher.ts:42
Parameters
| Parameter | Type |
|---|---|
secret | string |
Returns
boolean
hash()
hash(secret): HashedSecret;Defined in: src/hasher.ts:22
Parameters
| Parameter | Type |
|---|---|
secret | string |
Returns
verify()
verify(
secret,
expectedHash,
pepperVersion): boolean;Defined in: src/hasher.ts:32
Parameters
| Parameter | Type |
|---|---|
secret | string |
expectedHash | string |
pepperVersion | number |
Returns
boolean
Interfaces
ApiKeyAuthFailedEvent
Defined in: src/types.ts:127
Extends
Properties
at
at: Date;Defined in: src/types.ts:93
Inherited from
code
code: ApiKeyErrorCode;Defined in: src/types.ts:130
environment?
optional environment?: Environment;Defined in: src/types.ts:133
keyId?
optional keyId?: string;Defined in: src/types.ts:132
prefix
prefix: string | null;Defined in: src/types.ts:129
tenantId?
optional tenantId?: string;Defined in: src/types.ts:131
type
type: "api_key.auth_failed";Defined in: src/types.ts:128
ApiKeyAuthorizationDeniedEvent
Defined in: src/types.ts:136
Extends
Properties
at
at: Date;Defined in: src/types.ts:93
Inherited from
code
code: ApiKeyErrorCode;Defined in: src/types.ts:138
type
type: "api_key.authorization_denied";Defined in: src/types.ts:137
ApiKeyAuthorizationMetric
Defined in: src/types.ts:186
Properties
durationMs
durationMs: number;Defined in: src/types.ts:189
environment?
optional environment?: Environment;Defined in: src/types.ts:190
outcome
outcome: ApiKeyAuthorizationOutcome;Defined in: src/types.ts:188
type
type: "api_key.authorization";Defined in: src/types.ts:187
ApiKeyContext
Defined in: src/types.ts:53
Properties
allowedIpCidrs?
optional allowedIpCidrs?: string[];Defined in: src/types.ts:59
environment
environment: Environment;Defined in: src/types.ts:56
keyId
keyId: string;Defined in: src/types.ts:54
prefix
prefix: string;Defined in: src/types.ts:58
scopes
scopes: string[];Defined in: src/types.ts:57
tenantId
tenantId: string;Defined in: src/types.ts:55
ApiKeyCreatedEvent
Defined in: src/types.ts:96
Extends
Properties
at
at: Date;Defined in: src/types.ts:93
Inherited from
createdBy
createdBy: string | null;Defined in: src/types.ts:103
environment
environment: Environment;Defined in: src/types.ts:101
keyId
keyId: string;Defined in: src/types.ts:98
prefix
prefix: string;Defined in: src/types.ts:100
scopes
scopes: string[];Defined in: src/types.ts:102
tenantId
tenantId: string;Defined in: src/types.ts:99
type
type: "api_key.created";Defined in: src/types.ts:97
ApiKeyEventBase
Defined in: src/types.ts:92
Extended by
ApiKeyCreatedEventApiKeyRevokedEventApiKeyRotatedEventApiKeyAuthFailedEventApiKeyAuthorizationDeniedEventApiKeyUsedEvent
Properties
at
at: Date;Defined in: src/types.ts:93
ApiKeyOperationMetric
Defined in: src/types.ts:199
Properties
attempts
attempts: number;Defined in: src/types.ts:203
operation
operation: ApiKeyOperationMetricOperation;Defined in: src/types.ts:201
outcome
outcome: "prefix_collision_exhausted";Defined in: src/types.ts:202
type
type: "api_key.operation";Defined in: src/types.ts:200
ApiKeyRecord
Defined in: src/types.ts:12
Properties
allowedIpCidrs?
optional allowedIpCidrs?: string[];Defined in: src/types.ts:21
createdAt
createdAt: Date;Defined in: src/types.ts:28
createdBy
createdBy: string | null;Defined in: src/types.ts:27
environment
environment: Environment;Defined in: src/types.ts:16
expiresAt
expiresAt: Date | null;Defined in: src/types.ts:23
hash
hash: string;Defined in: src/types.ts:18
id
id: string;Defined in: src/types.ts:13
lastUsedAt
lastUsedAt: Date | null;Defined in: src/types.ts:22
name
name: string;Defined in: src/types.ts:15
pepperVersion
pepperVersion: number;Defined in: src/types.ts:19
prefix
prefix: string;Defined in: src/types.ts:17
replacedByKeyId
replacedByKeyId: string | null;Defined in: src/types.ts:26
revokedAt
revokedAt: Date | null;Defined in: src/types.ts:24
rotatedAt
rotatedAt: Date | null;Defined in: src/types.ts:25
scopes
scopes: string[];Defined in: src/types.ts:20
tenantId
tenantId: string;Defined in: src/types.ts:14
ApiKeyRequestAuthorizationInput
Defined in: src/types.ts:210
Properties
clientIp?
optional clientIp?: string;Defined in: src/types.ts:214
clientIpResolver?
optional clientIpResolver?: (request) => string | Promise<string | undefined> | undefined;Defined in: src/types.ts:216
Parameters
| Parameter | Type |
|---|---|
request | unknown |
Returns
string | Promise<string | undefined> | undefined
rawKey?
optional rawKey?: string | null;Defined in: src/types.ts:211
request?
optional request?: unknown;Defined in: src/types.ts:215
requiredEnvironment?
optional requiredEnvironment?: Environment;Defined in: src/types.ts:212
requiredScope?
optional requiredScope?: Scope;Defined in: src/types.ts:213
ApiKeyRevokedEvent
Defined in: src/types.ts:106
Extends
Properties
at
at: Date;Defined in: src/types.ts:93
Inherited from
environment
environment: Environment;Defined in: src/types.ts:111
keyId
keyId: string;Defined in: src/types.ts:108
prefix
prefix: string;Defined in: src/types.ts:110
tenantId
tenantId: string;Defined in: src/types.ts:109
type
type: "api_key.revoked";Defined in: src/types.ts:107
ApiKeyRotatedEvent
Defined in: src/types.ts:114
Extends
Properties
at
at: Date;Defined in: src/types.ts:93
Inherited from
createdBy
createdBy: string | null;Defined in: src/types.ts:124
environment
environment: Environment;Defined in: src/types.ts:121
graceExpiresAt
graceExpiresAt: Date;Defined in: src/types.ts:123
newKeyId
newKeyId: string;Defined in: src/types.ts:119
newPrefix
newPrefix: string;Defined in: src/types.ts:120
oldKeyId
oldKeyId: string;Defined in: src/types.ts:117
oldPrefix
oldPrefix: string;Defined in: src/types.ts:118
scopes
scopes: string[];Defined in: src/types.ts:122
tenantId
tenantId: string;Defined in: src/types.ts:116
type
type: "api_key.rotated";Defined in: src/types.ts:115
ApiKeysModuleOptions
Defined in: src/api-keys.module.ts:27
Properties
clientIpResolver?
optional clientIpResolver?: ApiKeyClientIpResolver;Defined in: src/api-keys.module.ts:48
contextWriter?
optional contextWriter?: ApiKeyContextWriter;Defined in: src/api-keys.module.ts:47
currentPepperVersion?
optional currentPepperVersion?: number;Defined in: src/api-keys.module.ts:30
debounceMs?
optional debounceMs?: number;Defined in: src/api-keys.module.ts:31
emitUsageEvents?
optional emitUsageEvents?: boolean;Defined in: src/api-keys.module.ts:45
namespace?
optional namespace?: string;Defined in: src/api-keys.module.ts:28
onAuthFailed?
optional onAuthFailed?: (prefix, code) => void | PromiseLike<void>;Defined in: src/api-keys.module.ts:36
Parameters
| Parameter | Type |
|---|---|
prefix | string | null |
code | string |
Returns
void | PromiseLike<void>
Deprecated
Use onEvent and handle api_key.auth_failed events instead.
onAuthorizationMetric?
optional onAuthorizationMetric?: ApiKeyAuthorizationMetricSink;Defined in: src/api-keys.module.ts:41
onAuthorizationMetricError?
optional onAuthorizationMetricError?: (error, metric) => void;Defined in: src/api-keys.module.ts:42
Parameters
| Parameter | Type |
|---|---|
error | unknown |
metric | ApiKeyAuthorizationMetric |
Returns
void
onEvent?
optional onEvent?: ApiKeyEventSink;Defined in: src/api-keys.module.ts:37
onEventError?
optional onEventError?: (error, event) => void;Defined in: src/api-keys.module.ts:38
Parameters
| Parameter | Type |
|---|---|
error | unknown |
event | ApiKeyEvent |
Returns
void
onMetric?
optional onMetric?: ApiKeyMetricSink;Defined in: src/api-keys.module.ts:39
onMetricError?
optional onMetricError?: (error, metric) => void;Defined in: src/api-keys.module.ts:40
Parameters
| Parameter | Type |
|---|---|
error | unknown |
metric | ApiKeyVerificationMetric |
Returns
void
onOperationMetric?
optional onOperationMetric?: ApiKeyOperationMetricSink;Defined in: src/api-keys.module.ts:43
onOperationMetricError?
optional onOperationMetricError?: (error, metric) => void;Defined in: src/api-keys.module.ts:44
Parameters
| Parameter | Type |
|---|---|
error | unknown |
metric | ApiKeyOperationMetric |
Returns
void
peppers
peppers: Record<number, string>;Defined in: src/api-keys.module.ts:29
storage
storage: ApiKeyStorage;Defined in: src/api-keys.module.ts:32
ttlPolicy?
optional ttlPolicy?: ApiKeyTtlPolicy;Defined in: src/api-keys.module.ts:46
ApiKeysServiceDeps
Defined in: src/api-keys.service.ts:54
Properties
clock?
optional clock?: () => Date;Defined in: src/api-keys.service.ts:59
Returns
Date
debounceMs?
optional debounceMs?: number;Defined in: src/api-keys.service.ts:60
emitUsageEvents?
optional emitUsageEvents?: boolean;Defined in: src/api-keys.service.ts:76
hasher
hasher: Sha256Hasher;Defined in: src/api-keys.service.ts:56
idFactory?
optional idFactory?: () => string;Defined in: src/api-keys.service.ts:58
Returns
string
monotonicClock?
optional monotonicClock?: () => number;Defined in: src/api-keys.service.ts:78
Returns
number
namespace
namespace: string;Defined in: src/api-keys.service.ts:57
onAuthFailed?
optional onAuthFailed?: (prefix, code) => void | PromiseLike<void>;Defined in: src/api-keys.service.ts:64
Parameters
| Parameter | Type |
|---|---|
prefix | string | null |
code | string |
Returns
void | PromiseLike<void>
Deprecated
Use onEvent and handle api_key.auth_failed events instead.
onAuthorizationMetric?
optional onAuthorizationMetric?: ApiKeyAuthorizationMetricSink;Defined in: src/api-keys.service.ts:72
onAuthorizationMetricError?
optional onAuthorizationMetricError?: (error, metric) => void;Defined in: src/api-keys.service.ts:73
Parameters
| Parameter | Type |
|---|---|
error | unknown |
metric | ApiKeyAuthorizationMetric |
Returns
void
onEvent?
optional onEvent?: ApiKeyEventSink;Defined in: src/api-keys.service.ts:68
onEventError?
optional onEventError?: (error, event) => void;Defined in: src/api-keys.service.ts:69
Parameters
| Parameter | Type |
|---|---|
error | unknown |
event | ApiKeyEvent |
Returns
void
onMetric?
optional onMetric?: ApiKeyMetricSink;Defined in: src/api-keys.service.ts:70
onMetricError?
optional onMetricError?: (error, metric) => void;Defined in: src/api-keys.service.ts:71
Parameters
| Parameter | Type |
|---|---|
error | unknown |
metric | ApiKeyVerificationMetric |
Returns
void
onOperationMetric?
optional onOperationMetric?: ApiKeyOperationMetricSink;Defined in: src/api-keys.service.ts:74
onOperationMetricError?
optional onOperationMetricError?: (error, metric) => void;Defined in: src/api-keys.service.ts:75
Parameters
| Parameter | Type |
|---|---|
error | unknown |
metric | ApiKeyOperationMetric |
Returns
void
storage
storage: ApiKeyStorage;Defined in: src/api-keys.service.ts:55
ttlPolicy?
optional ttlPolicy?: ApiKeyTtlPolicy;Defined in: src/api-keys.service.ts:77
ApiKeyStorage
Defined in: src/storage/api-key-storage.interface.ts:29
Methods
findById()
findById(id): Promise<ApiKeyRecord | null>;Defined in: src/storage/api-key-storage.interface.ts:31
Parameters
| Parameter | Type |
|---|---|
id | string |
Returns
Promise<ApiKeyRecord | null>
findByPrefix()
findByPrefix(prefix): Promise<ApiKeyRecord | null>;Defined in: src/storage/api-key-storage.interface.ts:32
Parameters
| Parameter | Type |
|---|---|
prefix | string |
Returns
Promise<ApiKeyRecord | null>
insert()
insert(record): Promise<void>;Defined in: src/storage/api-key-storage.interface.ts:30
Parameters
| Parameter | Type |
|---|---|
record | ApiKeyRecord |
Returns
Promise<void>
listByTenant()
listByTenant(tenantId, opts?): Promise<ApiKeyRecord[]>;Defined in: src/storage/api-key-storage.interface.ts:34
Return tenant records ordered by createdAt descending, then id ascending.
Parameters
| Parameter | Type |
|---|---|
tenantId | string |
opts? | ListApiKeysOptions |
Returns
Promise<ApiKeyRecord[]>
markRevoked()
markRevoked(id, at): Promise<void>;Defined in: src/storage/api-key-storage.interface.ts:35
Parameters
| Parameter | Type |
|---|---|
id | string |
at | Date |
Returns
Promise<void>
revokeForTenant()?
optional revokeForTenant(input): Promise<TenantBoundRevokeApiKeyStorageResult>;Defined in: src/storage/api-key-storage.interface.ts:36
Parameters
| Parameter | Type |
|---|---|
input | TenantBoundRevokeApiKeyStorageInput |
Returns
Promise<TenantBoundRevokeApiKeyStorageResult>
rotate()
rotate(input): Promise<RotateApiKeyStorageResult>;Defined in: src/storage/api-key-storage.interface.ts:40
Parameters
| Parameter | Type |
|---|---|
input | RotateApiKeyStorageInput |
Returns
Promise<RotateApiKeyStorageResult>
rotateForTenant()?
optional rotateForTenant(input): Promise<RotateApiKeyStorageResult>;Defined in: src/storage/api-key-storage.interface.ts:41
Parameters
| Parameter | Type |
|---|---|
input | TenantBoundRotateApiKeyStorageInput |
Returns
Promise<RotateApiKeyStorageResult>
touchLastUsed()
touchLastUsed(id, at): Promise<void>;Defined in: src/storage/api-key-storage.interface.ts:39
Parameters
| Parameter | Type |
|---|---|
id | string |
at | Date |
Returns
Promise<void>
ApiKeyStorageContractOptions
Defined in: src/storage/storage-contract.ts:6
Properties
createStorage
createStorage: () =>
| ApiKeyStorage
| Promise<ApiKeyStorage>;Defined in: src/storage/storage-contract.ts:10
Create an isolated adapter backed by disposable test data.
Returns
| ApiKeyStorage | Promise<ApiKeyStorage>
disposeStorage?
optional disposeStorage?: (storage) => void | Promise<void>;Defined in: src/storage/storage-contract.ts:12
Release adapter resources and remove contract fixture data.
Parameters
| Parameter | Type |
|---|---|
storage | ApiKeyStorage |
Returns
void | Promise<void>
name
name: string;Defined in: src/storage/storage-contract.ts:8
Human-readable adapter name used in failures and the result.
rotationConcurrency?
optional rotationConcurrency?: number;Defined in: src/storage/storage-contract.ts:14
Number of simultaneous rotation attempts. Defaults to 8 and must be at least 2.
ApiKeyStorageContractResult
Defined in: src/storage/storage-contract.ts:17
Properties
checks
checks: string[];Defined in: src/storage/storage-contract.ts:19
name
name: string;Defined in: src/storage/storage-contract.ts:18
ApiKeySummary
Defined in: src/types.ts:36
Serialization-safe API key metadata returned by ApiKeysService.list.
Verifier material is intentionally available only on internal storage records.
Properties
allowedIpCidrs?
optional allowedIpCidrs?: string[];Defined in: src/types.ts:43
createdAt
createdAt: Date;Defined in: src/types.ts:50
createdBy
createdBy: string | null;Defined in: src/types.ts:49
environment
environment: Environment;Defined in: src/types.ts:40
expiresAt
expiresAt: Date | null;Defined in: src/types.ts:45
id
id: string;Defined in: src/types.ts:37
lastUsedAt
lastUsedAt: Date | null;Defined in: src/types.ts:44
name
name: string;Defined in: src/types.ts:39
prefix
prefix: string;Defined in: src/types.ts:41
replacedByKeyId
replacedByKeyId: string | null;Defined in: src/types.ts:48
revokedAt
revokedAt: Date | null;Defined in: src/types.ts:46
rotatedAt
rotatedAt: Date | null;Defined in: src/types.ts:47
scopes
scopes: string[];Defined in: src/types.ts:42
tenantId
tenantId: string;Defined in: src/types.ts:38
ApiKeyTtlPolicy
Defined in: src/types.ts:221
Properties
allowNeverExpires?
optional allowNeverExpires?: boolean;Defined in: src/types.ts:224
defaultExpiresInMs?
optional defaultExpiresInMs?: number;Defined in: src/types.ts:222
maxExpiresInMs?
optional maxExpiresInMs?: number;Defined in: src/types.ts:223
ApiKeyUsedEvent
Defined in: src/types.ts:141
Extends
Properties
at
at: Date;Defined in: src/types.ts:93
Inherited from
environment
environment: Environment;Defined in: src/types.ts:146
keyId
keyId: string;Defined in: src/types.ts:143
prefix
prefix: string;Defined in: src/types.ts:145
scopes
scopes: string[];Defined in: src/types.ts:147
tenantId
tenantId: string;Defined in: src/types.ts:144
type
type: "api_key.used";Defined in: src/types.ts:142
ApiKeyVerificationMetric
Defined in: src/types.ts:168
Properties
durationMs
durationMs: number;Defined in: src/types.ts:171
environment?
optional environment?: Environment;Defined in: src/types.ts:172
outcome
outcome: ApiKeyVerificationOutcome;Defined in: src/types.ts:170
type
type: "api_key.verification";Defined in: src/types.ts:169
CreateApiKeyInput
Defined in: src/types.ts:62
Properties
allowedIpCidrs?
optional allowedIpCidrs?: string[];Defined in: src/types.ts:69
createdBy?
optional createdBy?: string;Defined in: src/types.ts:68
environment?
optional environment?: Environment;Defined in: src/types.ts:65
expiresAt?
optional expiresAt?: Date;Defined in: src/types.ts:67
name
name: string;Defined in: src/types.ts:64
scopes
scopes: Scope[];Defined in: src/types.ts:66
tenantId
tenantId: string;Defined in: src/types.ts:63
CreateApiKeyResult
Defined in: src/types.ts:72
Properties
id
id: string;Defined in: src/types.ts:73
key
key: string;Defined in: src/types.ts:74
CreateTestKeyOptions
Defined in: src/testing.ts:4
Properties
allowedIpCidrs?
optional allowedIpCidrs?: string[];Defined in: src/testing.ts:11
createdBy?
optional createdBy?: string;Defined in: src/testing.ts:10
environment?
optional environment?: Environment;Defined in: src/testing.ts:7
expiresAt?
optional expiresAt?: Date;Defined in: src/testing.ts:9
name?
optional name?: string;Defined in: src/testing.ts:6
scopes?
optional scopes?: Scope[];Defined in: src/testing.ts:8
tenantId?
optional tenantId?: string;Defined in: src/testing.ts:5
HashedSecret
Defined in: src/hasher.ts:5
Properties
hash
hash: string;Defined in: src/hasher.ts:6
pepperVersion
pepperVersion: number;Defined in: src/hasher.ts:7
HasherOptions
Defined in: src/hasher.ts:10
Properties
currentVersion
currentVersion: number;Defined in: src/hasher.ts:12
peppers
peppers: Record<number, string>;Defined in: src/hasher.ts:11
ListApiKeysOptions
Defined in: src/storage/api-key-storage.interface.ts:3
Properties
includeRevoked?
optional includeRevoked?: boolean;Defined in: src/storage/api-key-storage.interface.ts:5
Include records with a non-null revokedAt. Expired and rotated records are always included.
PrismaLike
Defined in: src/storage/prisma-storage.ts:24
Extends
PrismaTransactionLike
Properties
apiKey
apiKey: PrismaApiKeyDelegate;Defined in: src/storage/prisma-storage.ts:21
Inherited from
PrismaTransactionLike.apiKeyMethods
$transaction()
$transaction<T>(callback): Promise<T>;Defined in: src/storage/prisma-storage.ts:25
Type Parameters
| Type Parameter |
|---|
T |
Parameters
| Parameter | Type |
|---|---|
callback | (transaction) => Promise<T> |
Returns
Promise<T>
RequiredScope
Defined in: src/decorators/require-scope.decorator.ts:9
Properties
level
level: ScopeLevel;Defined in: src/decorators/require-scope.decorator.ts:11
resource
resource: string;Defined in: src/decorators/require-scope.decorator.ts:10
RotateApiKeyInput
Defined in: src/types.ts:77
Properties
allowedIpCidrs?
optional allowedIpCidrs?: string[];Defined in: src/types.ts:82
createdBy?
optional createdBy?: string;Defined in: src/types.ts:80
expiresAt?
optional expiresAt?: Date | null;Defined in: src/types.ts:81
gracePeriodMs?
optional gracePeriodMs?: number;Defined in: src/types.ts:78
name?
optional name?: string;Defined in: src/types.ts:79
RotateApiKeyResult
Defined in: src/types.ts:85
Properties
graceExpiresAt
graceExpiresAt: Date;Defined in: src/types.ts:89
id
id: string;Defined in: src/types.ts:86
key
key: string;Defined in: src/types.ts:87
replacedKeyId
replacedKeyId: string;Defined in: src/types.ts:88
RotateApiKeyStorageInput
Defined in: src/storage/api-key-storage.interface.ts:8
Extended by
Properties
newRecord
newRecord: ApiKeyRecord;Defined in: src/storage/api-key-storage.interface.ts:10
oldExpiresAt
oldExpiresAt: Date;Defined in: src/storage/api-key-storage.interface.ts:11
oldKeyId
oldKeyId: string;Defined in: src/storage/api-key-storage.interface.ts:9
rotatedAt
rotatedAt: Date;Defined in: src/storage/api-key-storage.interface.ts:12
Scope
Defined in: src/types.ts:7
Properties
level
level: ScopeLevel;Defined in: src/types.ts:9
resource
resource: string;Defined in: src/types.ts:8
TenantBoundRevokeApiKeyStorageInput
Defined in: src/storage/api-key-storage.interface.ts:15
Properties
expectedTenantId
expectedTenantId: string;Defined in: src/storage/api-key-storage.interface.ts:17
keyId
keyId: string;Defined in: src/storage/api-key-storage.interface.ts:16
revokedAt
revokedAt: Date;Defined in: src/storage/api-key-storage.interface.ts:18
TenantBoundRotateApiKeyStorageInput
Defined in: src/storage/api-key-storage.interface.ts:23
Extends
Properties
expectedTenantId
expectedTenantId: string;Defined in: src/storage/api-key-storage.interface.ts:24
newRecord
newRecord: ApiKeyRecord;Defined in: src/storage/api-key-storage.interface.ts:10
Inherited from
RotateApiKeyStorageInput.newRecord
oldExpiresAt
oldExpiresAt: Date;Defined in: src/storage/api-key-storage.interface.ts:11
Inherited from
RotateApiKeyStorageInput.oldExpiresAt
oldKeyId
oldKeyId: string;Defined in: src/storage/api-key-storage.interface.ts:9
Inherited from
RotateApiKeyStorageInput.oldKeyId
rotatedAt
rotatedAt: Date;Defined in: src/storage/api-key-storage.interface.ts:12
Inherited from
RotateApiKeyStorageInput.rotatedAt
Type Aliases
ApiKeyAuthorizationMetricSink
type ApiKeyAuthorizationMetricSink = (metric) => void | Promise<void>;Defined in: src/types.ts:193
Parameters
| Parameter | Type |
|---|---|
metric | ApiKeyAuthorizationMetric |
Returns
void | Promise<void>
ApiKeyAuthorizationOutcome
type ApiKeyAuthorizationOutcome =
| "success"
| "missing"
| "credential_rejected"
| "environment_denied"
| "ip_denied"
| "scope_denied"
| "error";Defined in: src/types.ts:177
ApiKeyClientIpResolver
type ApiKeyClientIpResolver = (request) => string | undefined | Promise<string | undefined>;Defined in: src/ip-allowlist.ts:5
Parameters
| Parameter | Type |
|---|---|
request | unknown |
Returns
string | undefined | Promise<string | undefined>
ApiKeyContextWriter
type ApiKeyContextWriter = (apiKey, request) => void | Promise<void>;Defined in: src/context.ts:6
Parameters
| Parameter | Type |
|---|---|
apiKey | ApiKeyContext |
request | unknown |
Returns
void | Promise<void>
ApiKeyErrorCode
type ApiKeyErrorCode = typeof ApiKeyErrorCode[keyof typeof ApiKeyErrorCode];Defined in: src/errors.ts:7
ApiKeyEvent
type ApiKeyEvent =
| ApiKeyCreatedEvent
| ApiKeyRevokedEvent
| ApiKeyRotatedEvent
| ApiKeyAuthFailedEvent
| ApiKeyAuthorizationDeniedEvent
| ApiKeyUsedEvent;Defined in: src/types.ts:150
ApiKeyEventSink
type ApiKeyEventSink = (event) => void | Promise<void>;Defined in: src/types.ts:158
Parameters
| Parameter | Type |
|---|---|
event | ApiKeyEvent |
Returns
void | Promise<void>
ApiKeyMetricSink
type ApiKeyMetricSink = (metric) => void | Promise<void>;Defined in: src/types.ts:175
Parameters
| Parameter | Type |
|---|---|
metric | ApiKeyVerificationMetric |
Returns
void | Promise<void>
ApiKeyOperationErrorCode
type ApiKeyOperationErrorCode = typeof ApiKeyOperationErrorCode[keyof typeof ApiKeyOperationErrorCode];Defined in: src/errors.ts:48
ApiKeyOperationMetricOperation
type ApiKeyOperationMetricOperation = "create" | "rotate";Defined in: src/types.ts:197
ApiKeyOperationMetricSink
type ApiKeyOperationMetricSink = (metric) => void | Promise<void>;Defined in: src/types.ts:206
Parameters
| Parameter | Type |
|---|---|
metric | ApiKeyOperationMetric |
Returns
void | Promise<void>
ApiKeyVerificationOutcome
type ApiKeyVerificationOutcome = "success" | "malformed" | "invalid" | "revoked" | "expired" | "error";Defined in: src/types.ts:160
Environment
type Environment = "live" | "test";Defined in: src/types.ts:3
RotateApiKeyStorageResult
type RotateApiKeyStorageResult = "rotated" | "not_rotatable";Defined in: src/storage/api-key-storage.interface.ts:27
ScopeLevel
type ScopeLevel = "read" | "write";Defined in: src/types.ts:5
TenantBoundRevokeApiKeyStorageResult
type TenantBoundRevokeApiKeyStorageResult = "revoked" | "not_found";Defined in: src/storage/api-key-storage.interface.ts:21
Variables
API_KEY_CLIENT_IP_RESOLVER
const API_KEY_CLIENT_IP_RESOLVER: typeof API_KEY_CLIENT_IP_RESOLVER;Defined in: src/ip-allowlist.ts:3
API_KEY_CONTEXT_PROPERTY
const API_KEY_CONTEXT_PROPERTY: "apiKey" = 'apiKey';Defined in: src/context.ts:3
API_KEY_CONTEXT_WRITER
const API_KEY_CONTEXT_WRITER: typeof API_KEY_CONTEXT_WRITER;Defined in: src/context.ts:4
API_KEY_NAMESPACE_MAX_LENGTH
const API_KEY_NAMESPACE_MAX_LENGTH: 32 = 32;Defined in: src/input-validation.ts:4
API_KEY_REDACT_REGEX
const API_KEY_REDACT_REGEX: RegExp;Defined in: src/key-format.ts:99
API_KEY_SCOPE_RESOURCE_MAX_LENGTH
const API_KEY_SCOPE_RESOURCE_MAX_LENGTH: 128 = 128;Defined in: src/input-validation.ts:5
API_KEY_TENANT_ID_MAX_LENGTH
const API_KEY_TENANT_ID_MAX_LENGTH: 255 = 255;Defined in: src/input-validation.ts:6
API_KEYS_OPTIONS
const API_KEYS_OPTIONS: typeof API_KEYS_OPTIONS;Defined in: src/api-keys.module.ts:24
API_KEYS_STORAGE
const API_KEYS_STORAGE: typeof API_KEYS_STORAGE;Defined in: src/api-keys.module.ts:25
ApiKeyErrorCode
const ApiKeyErrorCode: {
EnvironmentMismatch: "api_key_environment_mismatch";
Expired: "api_key_expired";
Invalid: "api_key_invalid";
IpNotAllowed: "api_key_ip_not_allowed";
Malformed: "api_key_malformed";
Missing: "api_key_missing";
Revoked: "api_key_revoked";
ScopeInsufficient: "api_key_scope_insufficient";
};Defined in: src/errors.ts:7
Type Declaration
| Name | Type | Default value | Defined in |
|---|---|---|---|
EnvironmentMismatch | "api_key_environment_mismatch" | 'api_key_environment_mismatch' | src/errors.ts:13 |
Expired | "api_key_expired" | 'api_key_expired' | src/errors.ts:12 |
Invalid | "api_key_invalid" | 'api_key_invalid' | src/errors.ts:10 |
IpNotAllowed | "api_key_ip_not_allowed" | 'api_key_ip_not_allowed' | src/errors.ts:15 |
Malformed | "api_key_malformed" | 'api_key_malformed' | src/errors.ts:9 |
Missing | "api_key_missing" | 'api_key_missing' | src/errors.ts:8 |
Revoked | "api_key_revoked" | 'api_key_revoked' | src/errors.ts:11 |
ScopeInsufficient | "api_key_scope_insufficient" | 'api_key_scope_insufficient' | src/errors.ts:14 |
ApiKeyOperationErrorCode
const ApiKeyOperationErrorCode: {
InvalidInput: "api_key_invalid_input";
InvalidTime: "api_key_invalid_time";
NotFound: "api_key_record_not_found";
NotRotatable: "api_key_not_rotatable";
PrefixCollision: "api_key_prefix_collision";
};Defined in: src/errors.ts:48
Type Declaration
| Name | Type | Default value | Defined in |
|---|---|---|---|
InvalidInput | "api_key_invalid_input" | 'api_key_invalid_input' | src/errors.ts:53 |
InvalidTime | "api_key_invalid_time" | 'api_key_invalid_time' | src/errors.ts:52 |
NotFound | "api_key_record_not_found" | 'api_key_record_not_found' | src/errors.ts:49 |
NotRotatable | "api_key_not_rotatable" | 'api_key_not_rotatable' | src/errors.ts:50 |
PrefixCollision | "api_key_prefix_collision" | 'api_key_prefix_collision' | src/errors.ts:51 |
CurrentApiKey
const CurrentApiKey: (...dataOrPipes) => ParameterDecorator;Defined in: src/decorators/current-api-key.decorator.ts:4
Parameters
| Parameter | Type |
|---|---|
...dataOrPipes | unknown[] |
Returns
ParameterDecorator
defaultApiKeyClientIpResolver
const defaultApiKeyClientIpResolver: ApiKeyClientIpResolver;Defined in: src/ip-allowlist.ts:9
ENVIRONMENT_METADATA
const ENVIRONMENT_METADATA: "nestarc:api-keys:environment" = 'nestarc:api-keys:environment';Defined in: src/decorators/require-environment.decorator.ts:7
SCOPE_METADATA
const SCOPE_METADATA: "nestarc:api-keys:scope" = 'nestarc:api-keys:scope';Defined in: src/decorators/require-scope.decorator.ts:7
Functions
createTestKey()
function createTestKey(service, options?): Promise<CreateApiKeyResult & {
context: ApiKeyContext;
}>;Defined in: src/testing.ts:14
Parameters
| Parameter | Type |
|---|---|
service | ApiKeysService |
options | CreateTestKeyOptions |
Returns
Promise<CreateApiKeyResult & { context: ApiKeyContext; }>
flattenScopes()
function flattenScopes(scopes): string[];Defined in: src/scope-matcher.ts:4
Parameters
| Parameter | Type |
|---|---|
scopes | Scope[] |
Returns
string[]
generateKey()
function generateKey(options): GeneratedKey;Defined in: src/key-format.ts:36
Parameters
| Parameter | Type |
|---|---|
options | { environment: Environment; namespace: string; } |
options.environment | Environment |
options.namespace | string |
Returns
GeneratedKey
getApiKeyContext()
function getApiKeyContext(request): ApiKeyContext | undefined;Defined in: src/context.ts:11
Parameters
| Parameter | Type |
|---|---|
request | unknown |
Returns
ApiKeyContext | undefined
isIpAllowed()
function isIpAllowed(clientIp, allowedIpCidrs): boolean;Defined in: src/ip-allowlist.ts:22
Parameters
| Parameter | Type |
|---|---|
clientIp | string | undefined |
allowedIpCidrs | readonly string[] |
Returns
boolean
isValidTenantId()
function isValidTenantId(value): value is string;Defined in: src/input-validation.ts:42
Parameters
| Parameter | Type |
|---|---|
value | unknown |
Returns
value is string
normalizeAllowedIpCidrs()
function normalizeAllowedIpCidrs(entries?): string[];Defined in: src/ip-allowlist.ts:18
Parameters
| Parameter | Type | Default value |
|---|---|---|
entries | readonly string[] | [] |
Returns
string[]
parseKey()
function parseKey(raw): ParsedKey;Defined in: src/key-format.ts:62
Parameters
| Parameter | Type |
|---|---|
raw | string |
Returns
ParsedKey
RequireEnvironment()
function RequireEnvironment(environment): CustomDecorator<string>;Defined in: src/decorators/require-environment.decorator.ts:9
Parameters
| Parameter | Type |
|---|---|
environment | Environment |
Returns
CustomDecorator<string>
RequireScope()
function RequireScope(resource, level): CustomDecorator<string>;Defined in: src/decorators/require-scope.decorator.ts:14
Parameters
| Parameter | Type |
|---|---|
resource | string |
level | ScopeLevel |
Returns
CustomDecorator<string>
runApiKeyStorageContract()
function runApiKeyStorageContract(options): Promise<ApiKeyStorageContractResult>;Defined in: src/storage/storage-contract.ts:42
Run the public, framework-independent contract for a custom ApiKeyStorage adapter.
The runner uses Node assertions and throws ApiKeyStorageContractError on the first failure. It does not depend on Jest, Vitest, Mocha, or their globals.
Parameters
| Parameter | Type |
|---|---|
options | ApiKeyStorageContractOptions |
Returns
Promise<ApiKeyStorageContractResult>
scopeSatisfies()
function scopeSatisfies(
granted,
resource,
required): boolean;Defined in: src/scope-matcher.ts:10
Parameters
| Parameter | Type |
|---|---|
granted | string[] |
resource | string |
required | ScopeLevel |
Returns
boolean
validateTenantId()
function validateTenantId(value): string;Defined in: src/input-validation.ts:51
Parameters
| Parameter | Type |
|---|---|
value | unknown |
Returns
string