4.9 KiB
NestJS Backend Audit Report
- Auditor Role: NestJS Backend Auditor
- Date: 2026-08-06
- Repository HEAD:
715873b2ecc3a72ba974bb2a2be87c5ba82bd4e7 - Included Scope:
backend/src/**/*,backend/package.json,backend/tsconfig.json,backend/nest-cli.json, backend tests. - Excluded Scope:
**/node_modules/**,backend/dist/**,frontend/**. - Files Inspected:
backend/src/orders/orders.service.ts,backend/src/common/metrics.controller.ts,backend/prisma/seed.ts,backend/src/pets/pets.controller.spec.ts,backend/src/users/users.controller.spec.ts,backend/src/main.ts. - Commands Executed:
cmd /c "backend\node_modules\.bin\tsc.cmd --noEmit -p backend\tsconfig.json". - Commands Blocked:
npm run lint(contains--fix),nest start,prisma db push. - Audit Limitations: Evaluated via static AST and TypeScript compiler diagnostics.
Domain Overview & Confirmed Strengths
- Modular NestJS Architecture: Clear domain encapsulation (
auth,users,pets,products,orders,settings,redis,prisma). - Global Pipes & Filters: Configured
ValidationPipewithwhitelist: true,forbidNonWhitelisted: true, and customHttpExceptionFilter.
Evaluation of 6 Existing TypeScript Compiler Diagnostics
backend/prisma/seed.ts(54,7): Propertyslugmissing inProductCreateInput. -> Seed-only schema mismatch error.backend/src/common/metrics.controller.ts(18,32): Type referenced in decorated signature requiring type import. -> Production type-import declaration error.backend/src/pets/pets.controller.spec.ts(71,19): Propertysuccessdoes not exist on pet object. -> Stale spec test error.backend/src/settings/settings.controller.spec.ts(65,19): Propertysuccessdoes not exist on setting object. -> Stale spec test error.backend/src/users/users.controller.spec.ts(42,12):resultis possibly null. -> Strict null check test error.backend/src/users/users.controller.spec.ts(89,19): Propertysuccessdoes not exist on address object. -> Stale spec test error.
Findings
BE-001
Title
Unsafe Floating Point arithmetic and Non-Atomic Calculation in Order Total Service
Domain
NestJS Backend
Category
Financial Calculations / Transaction Integrity
Severity
HIGH
Confidence
CONFIRMED
Status
OPEN
Affected Application
NestJS Backend (backend/)
Affected Files
backend/src/orders/orders.service.ts
Relevant Symbols or Lines
backend/src/orders/orders.service.ts#L10-L23(createmethod)
Evidence
In OrdersService.create:
let totalAmount = 0;
for (const item of createOrderDto.items) {
const product = await this.prisma.product.findUnique({ where: { id: item.productId } });
...
totalAmount += Number(product.priceValue) * item.quantity;
}
Problem
- Converts database
Decimal(priceValue) to JavaScript native IEEE-754 floating-pointNumber, inducing rounding precision errors on large currency values or Iranian Rial/Toman amounts. - Performs N+1 synchronous database queries inside an un-transactional
forloop to look up product prices individually.
Root Cause
Use of native JS primitive numbers for monetary arithmetic instead of Prisma Decimal or Decimal.js instance operations.
Why It Matters
Causes decimal truncation rounding inaccuracies in order subtotals and introduces N+1 performance bottlenecks during checkout under load.
User or Business Impact
Discrepancies between calculated order totals and actual line-item sums in financial reporting and invoice billing.
Technical Impact
Increases database latency and risks database lock timeouts during batch checkouts.
Security or Data-Integrity Impact
High risk of financial balance miscalculations.
Recommended Direction
Use Decimal.js (included with Prisma) to accumulate monetary amounts and batch product lookup using findMany({ where: { id: { in: ids } } }).
Alternative Direction
Calculate total amount on the database level via interactive Prisma transaction $transaction.
Implementation Complexity
MEDIUM
Dependencies
None.
Risks
None.
Verification Requirements
Test creating order with 10 products having precision decimals (e.g. 150000.50 * 3) and verify total sum matches exactly without floating-point expansion (450001.50000000006).
Testing Requirements
Unit test OrdersService.create with large decimal inputs.
Acceptance Criteria
totalAmount maintains exact decimal precision in database insertion.
Notes and Limitations
Prisma schema defines totalAmount as @db.Decimal(15,2).
Finding Summary
-
CRITICAL: 0
-
HIGH: 1
-
MEDIUM: 0
-
LOW: 0
-
INFO: 0
-
CONFIRMED: 1
-
HIGH_CONFIDENCE: 0
-
NEEDS_VERIFICATION: 0
-
SPECULATIVE: 0
Completion Statement
NestJS Backend audit completed. 1 HIGH severity finding confirmed. 6 compiler diagnostics classified.