Skip to content

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
    • Help
    • Submit feedback
    • Contribute to GitLab
  • Sign in
F
finwise-miniapp-be
  • Project
    • Project
    • Details
    • Activity
    • Releases
    • Cycle Analytics
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Charts
  • Issues 0
    • Issues 0
    • List
    • Board
    • Labels
    • Milestones
  • Merge Requests 0
    • Merge Requests 0
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
    • Charts
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Charts
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • ThinhNC
  • finwise-miniapp-be
  • Merge Requests
  • !22

Merged
Opened Aug 11, 2026 by ThinhNC@ThinhNC
  • Report abuse
Report abuse

feat(uploads): add R2 avatar upload flow

Summary

  • Add an authenticated POST /uploads/presign endpoint for direct browser uploads to Cloudflare R2.
  • Generate short-lived presigned PUT URLs with user-scoped, UUID-based object keys.
  • Restrict avatar uploads to JPEG, PNG, and WebP files with configurable size limits.
  • Add Cloudflare R2 environment configuration and AWS S3-compatible SDK dependencies.
  • Persist avatar horizontal and vertical crop positions in the user profile.
  • Support avatar removal and reset crop positions to their default values when an avatar is deleted.
  • Return the updated user object from the profile update endpoint.
  • Normalize the authenticated user response across login, profile, and current-user APIs.
  • Update API documentation and Swagger schemas for the upload and profile flows.

Configuration

The following environment variables must be configured:

  • R2_ACCOUNT_ID
  • R2_BUCKET_NAME
  • R2_ACCESS_KEY_ID
  • R2_SECRET_ACCESS_KEY
  • R2_PUBLIC_BASE_URL
  • R2_PRESIGNED_URL_EXPIRES_IN_SECONDS
  • R2_AVATAR_MAX_FILE_SIZE_MB

The R2 bucket must also allow browser PUT requests from the frontend origins.

Check out, review, and merge locally

Step 1. Fetch and check out the branch for this merge request

git fetch origin
git checkout -b feat/r2-avatar-upload origin/feat/r2-avatar-upload

Step 2. Review the changes locally

Step 3. Merge the branch and fix any conflicts that come up

git fetch origin
git checkout origin/develop
git merge --no-ff feat/r2-avatar-upload

Step 4. Push the result of the merge to GitLab

git push origin develop

Note that pushing to GitLab requires write access to this repository.

Tip: You can also checkout merge requests locally by following these guidelines.

  • Discussion 0
  • Commits 1
  • Changes 26
Assignee
No assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
0
Labels
None
Assign labels
  • View project labels
Reference: ThinhNC/finwise-miniapp-be!22

Revert this merge request

This will create a new commit in order to revert the existing changes.

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.

Cherry-pick this merge request

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.