Public
@Public() marks a NestJS controller class or route handler method as publicly accessible, signalling to OPRA's authentication guards that the endpoint requires no authentication.
import { Public } from '@opra/nestjs';
Usage
import { Controller, Get } from '@nestjs/common';
import { Public } from '@opra/nestjs';
@Controller('health')
export class HealthController {
@Public()
@Get()
check() {
return { status: 'ok' };
}
}
Apply it at the controller level to make all routes public:
@Public()
@Controller('public')
export class PublicController { ... }
How it works
@Public() calls SetMetadata(IS_PUBLIC_KEY, true) on the decorated target. Guards that implement authentication should check for this metadata and skip authentication when it is present:
import { IS_PUBLIC_KEY } from '@opra/nestjs';
import { CanActivate, ExecutionContext, Injectable } from '@nestjs/common';
import { Reflector } from '@nestjs/core';
@Injectable()
export class AuthGuard implements CanActivate {
constructor(private reflector: Reflector) {}
canActivate(context: ExecutionContext): boolean {
const isPublic = this.reflector.getAllAndOverride<boolean>(IS_PUBLIC_KEY, [
context.getHandler(),
context.getClass(),
]);
if (isPublic) return true;
// ... authentication logic
}
}
See also
IS_PUBLIC_KEY— the metadata key set by this decoratorOpraNestUtils