Skip to content
Back to skills

Backend Controller Pattern Backdoor

ASecurity

Provides NestJS Controller patterns for Backdoor (Service-to-Service) endpoints. This skill should be used when building endpoints that require API Key authentication for internal communication.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
developmenttypescriptapibackend

Works with

  • api

Security analysis

A100/100

Scanned September 27, 2026

npx -y skills add David-Li0406/meta-skill-evloving --skill backend-controller-pattern-backdoor --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Backend Controller Pattern Backdoor?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Backend Controller Pattern Backdoor
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-backend-controller-pattern-backdoor/badge)](https://www.skillsdirectory.com/skills/david-li0406-backend-controller-pattern-backdoor)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: backend-controller-pattern-backdoor
description: Provides NestJS Controller patterns for Backdoor (Service-to-Service) endpoints. This skill should be used when building endpoints that require API Key authentication for internal communication.
---

# Backdoor Controller Pattern (NestJS)

This skill outlines the patterns for **Backdoor** controllers in `erify_api`. These endpoints are designed for service-to-service communication or internal tools that bypass standard JWT authentication in favor of API Key authentication.

## Core Principles

1.  **Inheritance**: All backdoor controllers MUST extend `BaseBackdoorController`.
2.  **Authentication**: Automatically authenticated via API Key using the `@Backdoor()` decorator (from base class).
3.  **Path Structure**: All routes must start with `backdoor/`.

## Base Controller

`BaseBackdoorController` provides:
*   `@Backdoor()` decorator application (skips JWT guard, applies API Key guard).

## Implementation Pattern

```typescript
import { Controller, Get, Param, UseGuards } from '@nestjs/common';
import { BaseBackdoorController } from '@/backdoor/base-backdoor.controller';
import { ZodResponse } from '@/lib/decorators/zod-response.decorator';

@Controller('backdoor/users')
export class BackdoorUserController extends BaseBackdoorController {
  constructor(private readonly userService: UserService) {
    super();
  }

  @Get(':ext_id')
  @ZodResponse(UserDto)
  async getUserByExtId(@Param('ext_id') extId: string) {
    return this.userService.getUserByExtId(extId);
  }
}
```

## Checklist

- [ ] Controller extends `BaseBackdoorController`.
- [ ] Route prefix is `backdoor/<resource>`.
- [ ] Uses `@ZodResponse` for serialization.
- [ ] NO `@CurrentUser` decorator (concept doesn't exist for API keys).

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…