> nestjs-security-isolation
Standards for multi-tenant isolation and PostgreSQL Row Level Security. Use when enforcing tenant isolation or PostgreSQL RLS in NestJS multi-tenant apps. (triggers: src/modules/**, SECURITY.md, src/migrations/**, RLS, Row Level Security, childId, isolation, access policy)
curl "https://skillshub.wtf/HoangNguyen0403/agent-skills-standard/nestjs-security-isolation?format=md"Priority: P0 (CRITICAL)
Strict multi-tenant isolation. All child-centric data must be secured via PostgreSQL RLS and service-level validation.
RLS Enforcement Workflow
- Migration: Create tables with
ENABLE ROW LEVEL SECURITY. Define policies usingcurrent_setting('app.current_user_id'). - Entity Logic: Add
@SecurityJSDoc to the entity class. - Security Doc: Update
SECURITY.mdwith the new table and its access logic. - Service Validation: Call
childrenService.validateChildAccess(childId, userId)before any persistence operation.
Core Guidelines
- Mandatory RLS: Every new table linking to a
childorfamilyMUST have RLS enabled in its creation migration. - Centralized Validation: Never reimplement access logic. Use
ChildrenServicefor child/family membership checks. - Traceable Security:
SECURITY.mdis the source of truth. Any change to RLS policies must be reflected there immediately. - Nested Route Constraint: Data isolation is enforced at the controller level via nested routes:
/children/:childId/.... - No Direct Entity exposure: Use Response DTOs to prevent leaking internal database IDs or metadata that could bypass security filters.
Anti-Patterns
- No Public Tables: Don't create child-linked tables without RLS.
- No Manual Policy Checks: Don't write raw SQL access checks in services. Use the centralized validator.
- No Stale Docs: Don't merge RLS changes without updating
SECURITY.mdand entity JSDoc. - No Root IDs: Don't use
/domain/:idfor child data. Always scope by:childId.
Reference & Examples
> related_skills --same-repo
> typescript-tooling
Development tools, linting, and build config for TypeScript. Use when configuring ESLint, Prettier, Jest, Vitest, tsconfig, or any TS build tooling. (triggers: tsconfig.json, .eslintrc.*, jest.config.*, package.json, eslint, prettier, jest, vitest, build, compile, lint)
> typescript-security
Secure coding practices for TypeScript. Use when validating input, handling auth tokens, sanitizing data, or managing secrets and sensitive configuration. (triggers: **/*.ts, **/*.tsx, validate, sanitize, xss, injection, auth, password, secret, token)
> typescript-language
Modern TypeScript standards for type safety and maintainability. Use when working with types, interfaces, generics, enums, unions, or tsconfig settings. (triggers: **/*.ts, **/*.tsx, tsconfig.json, type, interface, generic, enum, union, intersection, readonly, const, namespace)
> typescript-best-practices
Idiomatic TypeScript patterns for clean, maintainable code. Use when writing or refactoring TypeScript classes, functions, modules, or async logic. (triggers: **/*.ts, **/*.tsx, class, function, module, import, export, async, promise)