DTO 与验证管道
实现数据传输对象(DTO),并使用验证管道确保传入的请求数据符合既定条件。
DTO 与验证管道 是 CoddyKit 上的免费 NestJS Enterprise Backend APIs 课时。 这是第 2 节课,共 3 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 NestJS Enterprise Backend APIs 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 NestJS Enterprise Backend APIs 课程共包含 3 节课。
本课时的部分内容尚未翻译,以英文显示。
Why Data Transfer Objects?
When building APIs, your application receives data from users. This data needs to be structured and safe.
Data Transfer Objects (DTOs) are plain classes that define the expected shape of the data coming into your application (e.g., from a request body) or going out (e.g., as a response).
Using DTOs helps with:
- Clarity: Clearly shows what data is expected.
- Consistency: Ensures data adheres to a specific format.
- Security: Prevents unexpected or malicious data from being processed.
Defining a Simple DTO
A DTO is essentially a TypeScript class with properties that match the data you expect. It's a blueprint for your data.
Here's a basic example for creating a new product:
export class CreateProductDto {
name: string;
description: string;
price: number;
}DTOs in NestJS Context
In a NestJS application, you'll typically create DTO files in a dto folder within your module (e.g., src/products/dto/create-product.dto.ts).
These classes are then used in your controllers to type the incoming request body.
import { Body, Controller, Post } from '@nestjs/common';
import { CreateProductDto } from './dto/create-product.dto';
@Controller('products')
export class ProductsController {
@Post()
create(@Body() createProductDto: CreateProductDto) {
// createProductDto will have 'name', 'description', 'price'
console.log(createProductDto);
return 'Product created!';
}
}Why Validate Input?
Just defining a DTO isn't enough. What if a user sends invalid data?
- A
namethat's too short? - A
pricethat's negative or not a number? - Missing required fields?
Without validation, your application could:
- Store bad data.
- Crash unexpectedly.
- Be vulnerable to security exploits.
This is where NestJS Validation Pipes come in!
Introducing Validation Pipes
A Validation Pipe is a special type of middleware in NestJS that automatically validates incoming request data against your DTO definitions.
If the data doesn't match the rules you've set, the pipe will automatically throw an error, preventing invalid data from reaching your controller logic.
The Validation Duo: `class-validator` & `class-transformer`
NestJS leverages two powerful libraries for DTO validation:
class-validator: Provides decorators (like@IsString(),@IsInt()) to define validation rules directly on your DTO properties.class-transformer: Helps convert plain JavaScript objects (from the request body) into instances of your DTO classes, which is crucial forclass-validatorto work correctly.
You'll need to install them:
npm i class-validator class-transformer
Decorating Your DTOs for Validation
Let's add some validation rules to our CreateProductDto using decorators from class-validator.
These decorators ensure that the incoming data meets specific criteria, like being a string, a number, or not empty.
import { IsString, IsNumber, IsNotEmpty, IsPositive } from 'class-validator';
export class CreateProductDto {
@IsString()
@IsNotEmpty()
name: string;
@IsString()
@IsNotEmpty()
description: string;
@IsNumber()
@IsPositive()
price: number;
}Applying `ValidationPipe` to a Route
Now that our DTO has validation decorators, we need to tell NestJS to use the ValidationPipe for a specific route.
You can apply it using the @UsePipes() decorator on your controller method. This makes the pipe active only for that particular route.
import { Controller, Post, Body, UsePipes, ValidationPipe } from '@nestjs/common';
import { CreateProductDto } from './dto/create-product.dto';
@Controller('products')
export class ProductsController {
@Post()
@UsePipes(new ValidationPipe()) // Apply pipe here
create(@Body() createProductDto: CreateProductDto) {
// If validation fails, this code won't run
return `Product '${createProductDto.name}' created!`;
}
}Global Validation Pipe
Applying @UsePipes(new ValidationPipe()) to every method can be repetitive. For consistency, you can register the ValidationPipe globally in your main.ts file.
This will apply the validation pipe to all incoming requests across your entire application, simplifying your code and ensuring consistent validation.
import { NestFactory } from '@nestjs/core';
import { AppModule } from './app.module';
import { ValidationPipe } from '@nestjs/common';
async function bootstrap() {
const app = await NestFactory.create(AppModule);
app.useGlobalPipes(new ValidationPipe()); // Apply pipe globally
await app.listen(3000);
}
bootstrap();Check Your Knowledge
Time to test what you've learned about DTOs and Validation Pipes!
Recap: DTOs & Validation Pipes
You've mastered DTOs and Validation Pipes!
- DTOs are TypeScript classes that define the structure of data for your API.
- They bring clarity, consistency, and security to your data handling.
- Validation Pipes automatically enforce rules defined by
class-validatordecorators. class-transformerensures incoming data is converted to DTO instances for validation.- Pipes can be applied per-route with
@UsePipes()or globally inmain.ts.
This ensures your NestJS API always receives and processes clean, valid data.
常见问题解答
「DTO 与验证管道」课时是免费的吗?
是的 — 「DTO 与验证管道」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 NestJS Enterprise Backend APIs 课程的其余内容,请升级到 CoddyKit PRO。 NestJS Enterprise Backend APIs 课程共包含 3 节课。
「DTO 与验证管道」这节课中我会学到什么?
实现数据传输对象(DTO),并使用验证管道确保传入的请求数据符合既定条件。 你通过在浏览器中直接运行的动手代码来练习 NestJS Enterprise Backend APIs,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 NestJS Enterprise Backend APIs 需要有经验吗?
无需任何先前经验。CoddyKit 上的 NestJS Enterprise Backend APIs 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 3 节。
「DTO 与验证管道」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 NestJS Enterprise Backend APIs 课中编写并运行代码吗?
能。每节 NestJS Enterprise Backend APIs 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- 依赖注入详解
- DTO 与验证管道
- TypeORM 集成基础