@ahmedhegazee/nestjs-telescope
Version:
Advanced observability and monitoring solution for NestJS applications with ML-powered analytics, enterprise features, and production-ready scaling
234 lines (233 loc) • 6.81 kB
TypeScript
import { OnModuleInit } from '@nestjs/common';
import { Observable } from 'rxjs';
import { TelescopeConfig } from '../interfaces/telescope-config.interface';
export interface EnterpriseSecurityConfig {
enabled: boolean;
authentication: {
enabled: boolean;
methods: ('jwt' | 'oauth2' | 'saml' | 'ldap' | 'active-directory')[];
jwt: {
secret: string;
expiresIn: string;
refreshExpiresIn: string;
};
oauth2: {
providers: {
google?: OAuth2Provider;
github?: OAuth2Provider;
azure?: OAuth2Provider;
okta?: OAuth2Provider;
};
};
saml: {
enabled: boolean;
entryPoint: string;
issuer: string;
cert: string;
};
ldap: {
enabled: boolean;
url: string;
bindDN: string;
bindCredentials: string;
searchBase: string;
searchFilter: string;
};
};
authorization: {
enabled: boolean;
rbac: boolean;
abac: boolean;
policies: SecurityPolicy[];
};
encryption: {
enabled: boolean;
algorithm: 'aes-256-gcm' | 'aes-256-cbc' | 'chacha20-poly1305';
keyRotation: boolean;
keyRotationInterval: number;
};
audit: {
enabled: boolean;
logLevel: 'basic' | 'detailed' | 'comprehensive';
retention: number;
compliance: ('gdpr' | 'sox' | 'hipaa' | 'pci')[];
};
compliance: {
gdpr: {
enabled: boolean;
dataRetention: number;
rightToBeForgotten: boolean;
dataPortability: boolean;
};
sox: {
enabled: boolean;
auditTrail: boolean;
accessControls: boolean;
};
hipaa: {
enabled: boolean;
phiProtection: boolean;
accessLogging: boolean;
};
pci: {
enabled: boolean;
cardDataEncryption: boolean;
tokenization: boolean;
};
};
}
export interface OAuth2Provider {
clientId: string;
clientSecret: string;
authorizationUrl: string;
tokenUrl: string;
userInfoUrl: string;
scope: string[];
}
export interface SecurityPolicy {
id: string;
name: string;
description: string;
type: 'allow' | 'deny';
resources: string[];
actions: string[];
conditions: PolicyCondition[];
priority: number;
}
export interface PolicyCondition {
field: string;
operator: 'equals' | 'not_equals' | 'contains' | 'regex' | 'in' | 'not_in';
value: any;
}
export interface User {
id: string;
username: string;
email: string;
firstName: string;
lastName: string;
roles: string[];
permissions: string[];
groups: string[];
tenantId?: string;
lastLogin: Date;
isActive: boolean;
metadata: Record<string, any>;
}
export interface AuthenticationResult {
success: boolean;
user?: User;
token?: string;
refreshToken?: string;
expiresAt?: Date;
error?: string;
method: string;
}
export interface AuthorizationResult {
allowed: boolean;
reason?: string;
policies: string[];
conditions: PolicyCondition[];
}
export interface SecurityAuditEvent {
id: string;
timestamp: Date;
userId: string;
action: string;
resource: string;
result: 'success' | 'failure' | 'denied';
ipAddress: string;
userAgent: string;
metadata: Record<string, any>;
compliance: {
gdpr: boolean;
sox: boolean;
hipaa: boolean;
pci: boolean;
};
}
export interface ComplianceReport {
gdpr: {
compliant: boolean;
issues: string[];
dataRetention: number;
dataSubjects: number;
};
sox: {
compliant: boolean;
issues: string[];
auditTrail: boolean;
accessControls: boolean;
};
hipaa: {
compliant: boolean;
issues: string[];
phiProtected: boolean;
accessLogged: boolean;
};
pci: {
compliant: boolean;
issues: string[];
cardDataEncrypted: boolean;
tokenized: boolean;
};
}
export declare class EnterpriseSecurityService implements OnModuleInit {
private readonly telescopeConfig;
private readonly logger;
private readonly users;
private readonly policies;
private readonly auditEvents;
private readonly encryptionKeys;
private readonly config;
private readonly auditSubject;
private readonly authSubject;
private readonly complianceSubject;
private keyRotationInterval;
constructor(telescopeConfig: TelescopeConfig);
onModuleInit(): Promise<void>;
private getDefaultSecurityConfig;
private initializeSecurity;
private initializeEncryptionKeys;
private initializeDefaultPolicies;
private initializeDefaultUsers;
private initializeComplianceMonitoring;
private startKeyRotation;
authenticate(credentials: {
method: string;
username?: string;
password?: string;
token?: string;
code?: string;
}): Promise<AuthenticationResult>;
private authenticateJwt;
private authenticateOAuth2;
private authenticateSaml;
private authenticateLdap;
authorize(userId: string, action: string, resource: string, context?: Record<string, any>): Promise<AuthorizationResult>;
private getApplicablePolicies;
private evaluatePolicy;
private evaluateCondition;
encrypt(data: string, keyId?: string): Promise<string>;
decrypt(encryptedData: string): Promise<string>;
private rotateEncryptionKeys;
private logAuditEvent;
generateComplianceReport(): Promise<ComplianceReport>;
private checkGDPRCompliance;
private checkSOXCompliance;
private checkHIPAACompliance;
private checkPCICompliance;
getUsers(): User[];
getUserById(userId: string): User | undefined;
createUser(userData: Omit<User, 'id' | 'lastLogin'>): Promise<User>;
updateUser(userId: string, updates: Partial<User>): Promise<User | null>;
deleteUser(userId: string): Promise<boolean>;
getPolicies(): SecurityPolicy[];
createPolicy(policy: Omit<SecurityPolicy, 'id'>): Promise<SecurityPolicy>;
updatePolicy(policyId: string, updates: Partial<SecurityPolicy>): Promise<SecurityPolicy | null>;
deletePolicy(policyId: string): Promise<boolean>;
getAuditEvents(): SecurityAuditEvent[];
getAuthenticationUpdates(): Observable<AuthenticationResult>;
getAuditUpdates(): Observable<SecurityAuditEvent>;
getComplianceUpdates(): Observable<ComplianceReport>;
shutdown(): Promise<void>;
}