CodeZettaInterview Hub

NestJS · Pipes · Junior · Best Practice

ValidationPipe with whitelist/forbidNonWhitelisted — why?

Short Interview Answer

Strips or rejects unknown properties to prevent mass assignment and unexpected fields.

Detailed Explanation

Always enable in APIs accepting bodies. Pair with DTO classes. This is a security best practice interview staple.

Example

new ValidationPipe({ whitelist: true, forbidNonWhitelisted: true, transform: true })

Did you know this answer?