NestJS Enterprise Backend APIs · Lezione

DTO e pipe di validazione

Implementi i Data Transfer Object (DTO) e utilizzi pipe di validazione per garantire che i dati delle richieste in ingresso rispettino i criteri definiti.

Lezione 2 di 311 passaggi

DTO e pipe di validazione è una lezione NestJS Enterprise Backend APIs gratuita su CoddyKit. Questa è la lezione 2 di 3. Puoi leggere la lezione completa qui gratuitamente — poi esercitati direttamente nel browser con un editor di codice integrato e un tutor IA disponibile 24/7. Fa parte del percorso di apprendimento NestJS Enterprise Backend APIs, e i tuoi progressi si sincronizzano tra il web e l'app CoddyKit. Il corso NestJS Enterprise Backend APIs include 3 lezioni in totale.

Parti di questa lezione non sono ancora state tradotte e vengono mostrate in inglese.

Why Data Transfer Objects?

When building APIs, your application receives data from users. This data needs to be structured and safe.

Data Transfer Objects (DTOs) are plain classes that define the expected shape of the data coming into your application (e.g., from a request body) or going out (e.g., as a response).

Using DTOs helps with:

  • Clarity: Clearly shows what data is expected.
  • Consistency: Ensures data adheres to a specific format.
  • Security: Prevents unexpected or malicious data from being processed.

Defining a Simple DTO

A DTO is essentially a TypeScript class with properties that match the data you expect. It's a blueprint for your data.

Here's a basic example for creating a new product:

export class CreateProductDto {
  name: string;
  description: string;
  price: number;
}

DTOs in NestJS Context

In a NestJS application, you'll typically create DTO files in a dto folder within your module (e.g., src/products/dto/create-product.dto.ts).

These classes are then used in your controllers to type the incoming request body.

import { Body, Controller, Post } from '@nestjs/common';
import { CreateProductDto } from './dto/create-product.dto';

@Controller('products')
export class ProductsController {
  @Post()
  create(@Body() createProductDto: CreateProductDto) {
    // createProductDto will have 'name', 'description', 'price'
    console.log(createProductDto);
    return 'Product created!';
  }
}

Why Validate Input?

Just defining a DTO isn't enough. What if a user sends invalid data?

  • A name that's too short?
  • A price that's negative or not a number?
  • Missing required fields?

Without validation, your application could:

  • Store bad data.
  • Crash unexpectedly.
  • Be vulnerable to security exploits.

This is where NestJS Validation Pipes come in!

Introducing Validation Pipes

A Validation Pipe is a special type of middleware in NestJS that automatically validates incoming request data against your DTO definitions.

If the data doesn't match the rules you've set, the pipe will automatically throw an error, preventing invalid data from reaching your controller logic.

The Validation Duo: `class-validator` & `class-transformer`

NestJS leverages two powerful libraries for DTO validation:

  • class-validator: Provides decorators (like @IsString(), @IsInt()) to define validation rules directly on your DTO properties.
  • class-transformer: Helps convert plain JavaScript objects (from the request body) into instances of your DTO classes, which is crucial for class-validator to work correctly.

You'll need to install them:

npm i class-validator class-transformer

Decorating Your DTOs for Validation

Let's add some validation rules to our CreateProductDto using decorators from class-validator.

These decorators ensure that the incoming data meets specific criteria, like being a string, a number, or not empty.

import { IsString, IsNumber, IsNotEmpty, IsPositive } from 'class-validator';

export class CreateProductDto {
  @IsString()
  @IsNotEmpty()
  name: string;

  @IsString()
  @IsNotEmpty()
  description: string;

  @IsNumber()
  @IsPositive()
  price: number;
}

Applying `ValidationPipe` to a Route

Now that our DTO has validation decorators, we need to tell NestJS to use the ValidationPipe for a specific route.

You can apply it using the @UsePipes() decorator on your controller method. This makes the pipe active only for that particular route.

import { Controller, Post, Body, UsePipes, ValidationPipe } from '@nestjs/common';
import { CreateProductDto } from './dto/create-product.dto';

@Controller('products')
export class ProductsController {
  @Post()
  @UsePipes(new ValidationPipe()) // Apply pipe here
  create(@Body() createProductDto: CreateProductDto) {
    // If validation fails, this code won't run
    return `Product '${createProductDto.name}' created!`;
  }
}

Global Validation Pipe

Applying @UsePipes(new ValidationPipe()) to every method can be repetitive. For consistency, you can register the ValidationPipe globally in your main.ts file.

This will apply the validation pipe to all incoming requests across your entire application, simplifying your code and ensuring consistent validation.

import { NestFactory } from '@nestjs/core';
import { AppModule } from './app.module';
import { ValidationPipe } from '@nestjs/common';

async function bootstrap() {
  const app = await NestFactory.create(AppModule);
  app.useGlobalPipes(new ValidationPipe()); // Apply pipe globally
  await app.listen(3000);
}
bootstrap();

Check Your Knowledge

Time to test what you've learned about DTOs and Validation Pipes!

Recap: DTOs & Validation Pipes

You've mastered DTOs and Validation Pipes!

  • DTOs are TypeScript classes that define the structure of data for your API.
  • They bring clarity, consistency, and security to your data handling.
  • Validation Pipes automatically enforce rules defined by class-validator decorators.
  • class-transformer ensures incoming data is converted to DTO instances for validation.
  • Pipes can be applied per-route with @UsePipes() or globally in main.ts.

This ensures your NestJS API always receives and processes clean, valid data.

Gratis per iniziare

Impara TypeScript con un tutor IA — gratis

Scrivi ed esegui vero codice nel tuo browser, ricevi aiuto istantaneo da un tutor IA disponibile 24/7, e riprendi da dove hai lasciato sul web o nell'app.

Corsi
20
Lezioni
76

Domande Frequenti

La lezione «DTO e pipe di validazione» è gratuita?

Sì — il testo completo di «DTO e pipe di validazione» è gratuito qui sul web. Per esercitarvi in modo interattivo (un editor di codice integrato e un tutor IA 24/7) e sbloccare il resto del corso NestJS Enterprise Backend APIs, passa a CoddyKit PRO. Il corso NestJS Enterprise Backend APIs include 3 lezioni in totale.

Cosa imparerò in «DTO e pipe di validazione»?

Implementi i Data Transfer Object (DTO) e utilizzi pipe di validazione per garantire che i dati delle richieste in ingresso rispettino i criteri definiti. Eserciti NestJS Enterprise Backend APIs con codice pratico che esegui direttamente nel browser, e un tutor IA 24/7 risponde alle tue domande mentre lavori sulla lezione.

Ho bisogno di esperienza per iniziare NestJS Enterprise Backend APIs?

Non è richiesta alcuna esperienza precedente. NestJS Enterprise Backend APIs su CoddyKit è strutturato per principianti e studenti avanzati, quindi puoi iniziare da qui o dall'inizio e procedere al tuo ritmo. Questa è la lezione 2 di 3.

Quanto tempo richiede la lezione «DTO e pipe di validazione»?

La maggior parte delle lezioni CoddyKit richiede circa 5–10 minuti. Ogni lezione è breve e interattiva, quindi fai progressi costanti e riprendi esattamente da dove hai lasciato su web e app.

Posso scrivere ed eseguire codice in questa lezione NestJS Enterprise Backend APIs?

Sì. Ogni lezione NestJS Enterprise Backend APIs include un editor di codice integrato, quindi scrivi ed esegui codice reale direttamente nel tuo browser e ricevi feedback istantaneo dall'IA — nessuna configurazione locale necessaria.

Tutte le lezioni di questo corso

  1. Dependency injection spiegata
  2. DTO e pipe di validazione
  3. Nozioni di base sull'integrazione di TypeORM
← Torna a NestJS Enterprise Backend APIs