Guards Module (node-yalc/guards)
The Guards module provides reusable security interceptors for the Ferrox-Node Framework. Guards are executed before route handlers to ensure the incoming request meets specific authentication, authorization, or compliance criteria. If a guard fails, the request is immediately rejected with the appropriate HTTP status code (e.g., 401 or 403), completely bypassing business logic.
Overview
Ferrox promotes defense-in-depth. Instead of writing authentication logic inside every controller, you attach Guards to your routes.
RbacGuard
The Role-Based Access Control (RBAC) Guard integrates directly with the @node-yalc/auth module. It verifies v4.local PASETO tokens and enforces role requirements.
import { RbacGuard } from '@node-yalc/guards';
import { PasetoAuthService } from '@node-yalc/auth';
const authService = new PasetoAuthService('your-secret-key-string-min-32-chars-long!');
// 1. Guard that only requires a valid login (No specific role)
const authenticationGuard = new RbacGuard(authService);
// 2. Guard that requires the user to be an Admin OR a SuperAdmin
const adminGuard = new RbacGuard(authService, ['Admin', 'SuperAdmin']);
Attach these instances to your router middleware.
MandatoryComplianceGuard
Enterprise applications must adhere to strict security headers (OWASP best practices). This guard automatically injects essential headers into every response and drops requests containing known malicious User-Agents.
import { MandatoryComplianceGuard } from '@node-yalc/guards';
const complianceGuard = new MandatoryComplianceGuard();
// Usage in Fastify or Express middleware:
app.use((req, res, next) => {
const isAllowed = complianceGuard.canActivate(req, res);
if (isAllowed) {
next();
}
});
Headers injected automatically:
X-Content-Type-Options: nosniffX-Frame-Options: DENYStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadContent-Security-Policy: default-src 'self'X-XSS-Protection: 1; mode=block