> For the complete documentation index, see [llms.txt](https://app-sec.gitbook.io/application-security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://app-sec.gitbook.io/application-security/secure-coding/nest.js-secure-coding-practices/building-an-insecure-nest.js-application.md).

# Building an insecure Nest.js Application

To gain a better understanding of known vulnerabilities we would create a vulnerable Nest.js Application and examine what makes it exploitable

You can absolutely skip this step and just dive into the git repository holding the code.

### But

You could actually learn a lot from tackling development yourself. Understanding design difficulties, and overcoming dev pitfalls would eventually help strengthen the mindset required to solve complicated secure design problems.

## Refrences and useful links

* [Nest.js documentation](https://docs.nestjs.com/first-steps)
* [Node.js Typescript learn](https://nodejs.dev/learn/nodejs-with-typescript)
* [TypeOrm documentation](https://typeorm.io/#/)
* [Swagger (OpenAPI) documentation](https://swagger.io/)
* [Docker documentation](https://docs.docker.com/)
