Agent-skills-standard nestjs-security-isolation
Enforce multi-tenant isolation and PostgreSQL Row Level Security in NestJS. Use when enforcing tenant isolation or PostgreSQL RLS in NestJS multi-tenant apps. (triggers: src/modules/**, SECURITY.md, src/migrations/**, RLS, Row Level Security, childId, isolation, access policy)
install
source · Clone the upstream repo
git clone https://github.com/HoangNguyen0403/agent-skills-standard
Claude Code · Install into ~/.claude/skills/
T=$(mktemp -d) && git clone --depth=1 https://github.com/HoangNguyen0403/agent-skills-standard "$T" && mkdir -p ~/.claude/skills && cp -r "$T/skills/nestjs/nestjs-security-isolation" ~/.claude/skills/hoangnguyen0403-agent-skills-standard-nestjs-security-isolation && rm -rf "$T"
manifest:
skills/nestjs/nestjs-security-isolation/SKILL.mdsource content
Priority: P0 (CRITICAL)
Strict multi-tenant isolation. All child-centric data must secured via PostgreSQL RLS and service-level validation.
RLS Enforcement Workflow
- Migration: Create tables with
. Define policies usingENABLE ROW LEVEL SECURITY
.current_setting('app.current_user_id') - Entity Logic: Add
JSDoc to entity class.@Security - Security Doc: Update
with new table and its access logic.SECURITY.md - Service Validation: Call
before any persistence operation.childrenService.validateChildAccess(childId, userId)
Core Guidelines
- Mandatory RLS: Every new table linking to
orchild
MUST RLS enabled in its creation migration.family - Centralized Validation: Never reimplement access logic. Use
for child/family membership checks.ChildrenService - Traceable Security:
source of truth. Any change to RLS policies must reflected there immediately.SECURITY.md - Nested Route Constraint: Data isolation enforced at controller level via nested routes:
./children/:childId/... - No Direct Entity exposure: Use Response DTOs to prevent leaking internal database IDs or metadata that could bypass security filters.
Anti-Patterns
- No Public Tables: Don't create child-linked tables without RLS.
- No Manual Policy Checks: Don't write raw SQL access checks in services. Use centralized validator.
- No Stale Docs: Don't merge RLS changes without updating
and entity JSDoc.SECURITY.md - No Root IDs: Don't use
for child data. Always scope by/domain/:id
.:childId