Skip to main content

Public

@Public() marks a NestJS controller class or route handler method as publicly accessible, signalling to OPRA's authentication guards that the endpoint requires no authentication.

import { Public } from '@opra/nestjs';

Usage​

import { Controller, Get } from '@nestjs/common';
import { Public } from '@opra/nestjs';

@Controller('health')
export class HealthController {
@Public()
@Get()
check() {
return { status: 'ok' };
}
}

Apply it at the controller level to make all routes public:

@Public()
@Controller('public')
export class PublicController { ... }

How it works​

@Public() calls SetMetadata(IS_PUBLIC_KEY, true) on the decorated target. Guards that implement authentication should check for this metadata and skip authentication when it is present:

import { IS_PUBLIC_KEY } from '@opra/nestjs';
import { CanActivate, ExecutionContext, Injectable } from '@nestjs/common';
import { Reflector } from '@nestjs/core';

@Injectable()
export class AuthGuard implements CanActivate {
constructor(private reflector: Reflector) {}

canActivate(context: ExecutionContext): boolean {
const isPublic = this.reflector.getAllAndOverride<boolean>(IS_PUBLIC_KEY, [
context.getHandler(),
context.getClass(),
]);
if (isPublic) return true;
// ... authentication logic
}
}

See also​