2026-02-08 22:44:16 +05:30
|
|
|
import { Module } from '@nestjs/common';
|
|
|
|
|
import { JwtModule } from '@nestjs/jwt';
|
|
|
|
|
import { ConfigModule, ConfigService } from '@nestjs/config';
|
|
|
|
|
import { MessagesController } from './messages.controller';
|
|
|
|
|
import { MessagesService } from './messages.service';
|
|
|
|
|
import { MessagesGateway } from './messages.gateway';
|
|
|
|
|
import { PrismaModule } from '../prisma/prisma.module';
|
2026-03-05 06:37:07 +05:30
|
|
|
import { SupportChatModule } from '../support-chat/support-chat.module';
|
2026-03-28 18:46:49 +05:30
|
|
|
import { ConnectionRequestsModule } from '../connection-requests/connection-requests.module';
|
2026-04-02 19:30:08 +05:30
|
|
|
import { RedisPresenceService } from '../common/services/redis-presence.service';
|
2026-02-08 22:44:16 +05:30
|
|
|
|
|
|
|
|
@Module({
|
|
|
|
|
imports: [
|
|
|
|
|
PrismaModule,
|
2026-03-05 06:37:07 +05:30
|
|
|
SupportChatModule,
|
2026-03-28 18:46:49 +05:30
|
|
|
ConnectionRequestsModule,
|
2026-02-08 22:44:16 +05:30
|
|
|
ConfigModule,
|
|
|
|
|
JwtModule.registerAsync({
|
|
|
|
|
imports: [ConfigModule],
|
|
|
|
|
inject: [ConfigService],
|
|
|
|
|
useFactory: (configService: ConfigService) => ({
|
fix(security): resolve audit findings — secrets, env contract, migrations
Removes hardcoded fallback secrets and makes a misconfigured deploy fail
loudly instead of silently falling back to development defaults.
- Remove insecure JWT fallback secrets (messages.module, configuration)
- Remove the 'default-secret' fallback for the 2FA TOTP encryption key and
allow a dedicated TWO_FACTOR_ENCRYPTION_KEY so rotating JWT_SECRET no
longer locks out every 2FA user (see docs/2fa-key-rotation.md)
- Require EMAIL_API_URL; drop the hardcoded vendor email endpoint
- Drive WebSocket CORS from CORS_ORIGINS instead of origin:'*'
- Load .env before any Nest module is imported (src/load-env.ts). Decorator
arguments evaluate at import time, so the gateway previously froze its CORS
config to the localhost fallback even when CORS_ORIGINS was set
- Add boot-time env validation: missing required vars, weak JWT_SECRET, and
inverted access/refresh token lifetimes now abort startup
- Enable Redis TLS certificate verification
- Require ADMIN_EMAIL/ADMIN_PASSWORD for the seed; remove the published
default super-admin credentials and stop printing them
- Add the initial Prisma migration and stop gitignoring prisma/migrations
- Make .env.example an accurate configuration contract (admin bootstrap,
REDIS_TLS, S3_ENDPOINT, 2FA key, Firebase path; drop the dead SMTP block)
- Add handover documentation: architecture, ER model, sequence and data-flow
diagrams, 2FA key rotation runbook
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-04 11:30:36 +05:30
|
|
|
secret: configService.get<string>('JWT_SECRET'),
|
2026-02-08 22:44:16 +05:30
|
|
|
signOptions: {
|
|
|
|
|
expiresIn: '15m',
|
|
|
|
|
},
|
|
|
|
|
}),
|
|
|
|
|
}),
|
|
|
|
|
],
|
|
|
|
|
controllers: [MessagesController],
|
2026-04-02 19:30:08 +05:30
|
|
|
providers: [MessagesService, MessagesGateway, RedisPresenceService],
|
|
|
|
|
exports: [MessagesService, MessagesGateway, RedisPresenceService],
|
2026-02-08 22:44:16 +05:30
|
|
|
})
|
|
|
|
|
export class MessagesModule {}
|