Skip to content

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
    • Help
    • Submit feedback
    • Contribute to GitLab
  • Sign in
F
finwise-miniapp-be
  • Project
    • Project
    • Details
    • Activity
    • Releases
    • Cycle Analytics
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Charts
  • Issues 0
    • Issues 0
    • List
    • Board
    • Labels
    • Milestones
  • Merge Requests 0
    • Merge Requests 0
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
    • Charts
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Charts
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • ThinhNC
  • finwise-miniapp-be
  • Merge Requests
  • !3

Merged
Opened Jul 23, 2026 by ThinhNC@ThinhNC
  • Report abuse
Report abuse

feat(auth): implement social login support, forgot password, email...

1. Hệ thống vai trò & Hằng số phân quyền (Role Constants)

  • Chuyển đổi và chuẩn hóa hệ thống phân quyền sang hằng số ROLES lưu tại src/common/constants/role.constant.ts.
  • Ba vai trò mới phù hợp với ứng dụng quản lý tài chính FinWise gồm: ADMIN, MANAGER và USER.
  • Thay thế toàn bộ chuỗi vai trò hardcode tại tầng validation, router và services.

2. Bảo mật token bằng HttpOnly Cookies

  • Tích hợp middleware cookie-parser để lưu trữ accessToken và refreshToken trong HttpOnly Cookies bảo mật.
  • Hỗ trợ cơ chế đọc token song song: Ưu tiên đọc từ Cookies cho Web client, và tự động dự phòng (fallback) đọc từ Header Authorization: Bearer <token> để giữ tính tương thích ngược cho Zalo Mini App hoặc Mobile client.

3. Luồng xác thực & Khôi phục mật khẩu qua Email

  • Đăng ký tài khoản: Giới hạn đăng ký chỉ cho phép email @gmail.com. Tài khoản mới tạo ở trạng thái chưa kích hoạt (isActive: false).
  • Kích hoạt tài khoản: Tự động sinh VerificationToken và gửi link kích hoạt có thời hạn 24 giờ qua email (sử dụng thư viện nodemailer).
  • Gửi lại mã xác nhận: Bổ sung API POST /auth/resend-verification gửi lại email xác thực.
  • Quên mật khẩu: Triển khai bảng PasswordResetToken và 2 API /auth/forgot-password (gửi mail khôi phục mật khẩu, hiệu lực 1 giờ) và /auth/reset-password (đặt lại mật khẩu bằng token).

4. Tính năng Xóa mềm (Soft Delete)

  • Thêm trường deletedAt (thời gian xóa) và deletedBy (ID Admin thực hiện xóa) vào bảng User để làm vết phát triển Activity Log.
  • Khi tài khoản bị xóa mềm:
    • Trạng thái isActive chuyển sang false.
    • Toàn bộ RefreshToken của người dùng bị thu hồi ngay trong cơ sở dữ liệu để ép buộc đăng xuất trên mọi thiết bị.
    • Các API truy vấn danh sách và chi tiết người dùng được tự động cấu hình để lọc bỏ các tài khoản đã bị xóa mềm (deletedAt: null).

Check out, review, and merge locally

Step 1. Fetch and check out the branch for this merge request

git fetch origin
git checkout -b feat/auth-cookies-verification origin/feat/auth-cookies-verification

Step 2. Review the changes locally

Step 3. Merge the branch and fix any conflicts that come up

git fetch origin
git checkout origin/develop
git merge --no-ff feat/auth-cookies-verification

Step 4. Push the result of the merge to GitLab

git push origin develop

Note that pushing to GitLab requires write access to this repository.

Tip: You can also checkout merge requests locally by following these guidelines.

  • Discussion 0
  • Commits 2
  • Changes 23
Assignee
No assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
0
Labels
None
Assign labels
  • View project labels
Reference: ThinhNC/finwise-miniapp-be!3

Revert this merge request

This will create a new commit in order to revert the existing changes.

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.

Cherry-pick this merge request

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.