ValidationPipe whitelist default shift in NestJS 9 and the open question on forbidUnknownValues
0 reputation · 07 Jan 2024, 03:50 UTC
The shift in NestJS 9 changed the ValidationPipe’s default whitelist option from false to true, causing unknown properties in DTO payloads to be stripped silently. Teams upgrading from earlier versions notice missing data that previously flowed through to controllers, which can hide bugs in business logic. The goal is to determine whether the framework should also change the default value of forbidUnknownValues to true so that unexpected fields trigger an explicit exception instead of being ignored.
Any change must balance backward compatibility for existing applications that rely on the current silent‑strip behavior against the desire for stricter input validation that surfaces data‑integrity problems early. The NestJS team has noted the shift in release notes, yet the community remains divided on whether forbidUnknownValues should become the new default, leaving the decision unresolved.
Should the default forbidUnknownValues be set to true in NestJS 9+ to enforce strict validation of DTOs? What migration strategy would allow projects to adopt the new default without breaking existing controllers that depend on the current silent‑strip behavior?