55 lines
1.9 KiB
TypeScript
55 lines
1.9 KiB
TypeScript
import { Logger } from '@nestjs/common';
|
|
import { NestFactory } from '@nestjs/core';
|
|
import { NestExpressApplication } from '@nestjs/platform-express';
|
|
import { DocumentBuilder, SwaggerModule } from '@nestjs/swagger';
|
|
import cookieParser from 'cookie-parser';
|
|
import helmet from 'helmet';
|
|
import type { NextFunction, Request, Response } from 'express';
|
|
import { AppModule } from './app.module';
|
|
import { AllExceptionsFilter } from './common/filters/all-exceptions.filter';
|
|
import { loadConfiguration } from './config/config.tokens';
|
|
|
|
/**
|
|
* Bootstrap der Management-API:
|
|
* - Security-Header (Helmet), Trust-Proxy für korrekte IPs
|
|
* - OpenAPI/Swagger unter /api/docs
|
|
* - Strukturierte Fehlerbehandlung
|
|
* Hinweis: Validierung erfolgt über Zod (ZodValidationPipe),
|
|
* nicht über den NestJS-ValidationPipe (class-validator).
|
|
*/
|
|
async function bootstrap(): Promise<void> {
|
|
const config = loadConfiguration();
|
|
const logger = new Logger('Bootstrap');
|
|
|
|
const app = await NestFactory.create<NestExpressApplication>(AppModule, {
|
|
logger: config.nodeEnv === 'production' ? ['log', 'warn', 'error'] : ['log', 'warn', 'error', 'debug'],
|
|
});
|
|
|
|
app.use(helmet());
|
|
app.use(cookieParser());
|
|
app.use('/api', (_request: Request, response: Response, next: NextFunction) => {
|
|
response.setHeader('Cache-Control', 'no-store');
|
|
next();
|
|
});
|
|
|
|
if (config.security.behindProxy) {
|
|
app.set('trust proxy', 1);
|
|
}
|
|
|
|
app.useGlobalFilters(new AllExceptionsFilter());
|
|
|
|
const swaggerConfig = new DocumentBuilder()
|
|
.setTitle('MPM Management API')
|
|
.setDescription('Zentrale Management-API der MPM-Plattform (Auth, RBAC, Health)')
|
|
.setVersion('0.1.0')
|
|
.addCookieAuth('mpm_session')
|
|
.build();
|
|
const document = SwaggerModule.createDocument(app, swaggerConfig);
|
|
SwaggerModule.setup('api/docs', app, document);
|
|
|
|
await app.listen(config.port, '0.0.0.0');
|
|
logger.log(`Management-Backend läuft auf Port ${config.port}`);
|
|
}
|
|
|
|
void bootstrap();
|