Questions
5 of 25
1How do you build a reusable pagination and sorting query DTO that can be extended by feature-specific DTOs in NestJS?
2How do you use ClassSerializerInterceptor with @Exclude() and @Expose() to control response shape in NestJS?
3What versioning strategies does NestJS support and how do you enable versioning?
4How do you implement idempotency keys for POST requests to prevent duplicate operations in NestJS?
5How do you implement API rate limiting per user or per IP in NestJS?
6How do you handle raw body access for webhook signature verification in NestJS?
7How do you stream a large file or dataset as a response without loading it fully into memory in NestJS?
8How do you implement content negotiation so an endpoint returns JSON or CSV based on the Accept header in NestJS?
9How do you set a default version so unversioned requests are handled by a specific version in NestJS?
10How do you document DTO properties for Swagger and handle optional vs required fields in NestJS?
11How do you handle HATEOAS hypermedia links in NestJS REST responses?
12What decorators does NestJS provide for route parameters and how do they differ from query params?
13How do you handle a route where the param can be either a numeric ID or the literal string 'me' in NestJS?
14How do you handle multi-value query parameters (arrays) in NestJS?
15What is the difference between @Body(), @Body('field'), and using a full DTO class in NestJS?
16How do you implement a PATCH endpoint correctly with partial validation using PartialType in NestJS?
17How do you implement discriminated union body validation where the DTO shape depends on a type field in NestJS?
18How do you set HTTP status codes, response headers, and redirects in NestJS without using @Res()?
19What is the recommended file structure for versioned controllers in a NestJS project?
20How do wildcard and optional route segments work in NestJS?
21What is the difference between @Param('id') and @Param() with no argument in NestJS?
22How do you extract and type query parameters in NestJS including optional ones with defaults?
23How do you implement a standard paginated response envelope across all list endpoints in NestJS?
24How do you apply versioning at controller and method level in NestJS and how do you mark a route as version-neutral?
25How do you set up Swagger in a NestJS application and annotate your controllers?
05 / 25

How do you implement API rate limiting per user or per IP in NestJS?

Use @nestjs/throttler — the official rate limiting package. Register ThrottlerModule.forRoot() with TTL and limit arrays for multiple time windows, then register ThrottlerGuard globally via APP_GUARD. Override per-route limits with @Throttle() and skip specific routes with @SkipThrottle(). Extend ThrottlerGuard and override getTracker() to rate limit per user ID instead of IP.

ThrottlerModule setup with per-user rate limiting
Rate limiting best practices:
  1. 1

    Register ThrottlerGuard globally via APP_GUARD so all routes are protected by default.

  2. 2

    Define multiple time windows (short + long) to catch both burst and sustained abuse.

  3. 3

    Override getTracker() to rate limit per authenticated user ID — IP-based limits are easily bypassed behind proxies.

  4. 4

    @Throttle() at the route level overrides the global default — use for sensitive endpoints like login.

  5. 5

    @SkipThrottle() exempts health checks and public status endpoints from rate limiting.