Skip to content

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
    • Help
    • Submit feedback
    • Contribute to GitLab
  • Sign in
F
finwise-miniapp-be
  • Project
    • Project
    • Details
    • Activity
    • Releases
    • Cycle Analytics
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Charts
  • Issues 0
    • Issues 0
    • List
    • Board
    • Labels
    • Milestones
  • Merge Requests 0
    • Merge Requests 0
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
    • Charts
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Charts
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • ThinhNC
  • finwise-miniapp-be
  • Merge Requests
  • !32

Merged
Opened Aug 20, 2026 by ThinhNC@ThinhNC
  • Report abuse
Report abuse

feat(rbac): refactor authorization to dynamic permission-based rbac and centralize constants

Overview

Refactored the authorization architecture from hardcoded role checking (requireRole) to fully dynamic permission-based authorization (requirePermission), where roles contain dynamic permissions and authorization is evaluated strictly against user permissions.

Key Changes

  • Dynamic RBAC Middleware: Replaced requireRole with requirePermission across all API route modules (wallets, transactions, transfers, categories, budgets, saving-goals, reports, forecast, simulations, anomalies, subscriptions, query, recurring-transactions, notifications, reminders, ai-assistant, uploads, users, rbac).
  • Centralized Constants (src/common/constants/):
    • PERMISSIONS: Centralized dictionary of 55 granular system permissions across 18 resources in permission.constant.ts.
    • SYSTEM_ROLES: Centralized constants (ADMIN, USER, MANAGER) for system bootstrapping and lifecycle protections in system-role.constant.ts.
    • Removed obsolete role.constant.ts and role.middleware.ts.
  • System Invariants & Safety:
    • Protected system roles (ADMIN, USER, MANAGER) from physical deletion.
    • Protected the ADMIN role from renaming.
    • Added protection to prevent soft-deleting the last active system administrator.
  • Audit Logging: Recorded detailed audit logs for all role and permission assignment mutations.
  • Dynamic User Filter: Updated findAllUserSchema to accept dynamic roleName string filter.

Check out, review, and merge locally

Step 1. Fetch and check out the branch for this merge request

git fetch origin
git checkout -b feat/upgrade-7-dynamic-rbac-be origin/feat/upgrade-7-dynamic-rbac-be

Step 2. Review the changes locally

Step 3. Merge the branch and fix any conflicts that come up

git fetch origin
git checkout origin/develop
git merge --no-ff feat/upgrade-7-dynamic-rbac-be

Step 4. Push the result of the merge to GitLab

git push origin develop

Note that pushing to GitLab requires write access to this repository.

Tip: You can also checkout merge requests locally by following these guidelines.

  • Discussion 0
  • Commits 1
  • Changes 43
Assignee
No assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
0
Labels
None
Assign labels
  • View project labels
Reference: ThinhNC/finwise-miniapp-be!32

Revert this merge request

This will create a new commit in order to revert the existing changes.

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.

Cherry-pick this merge request

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.