Skip to content

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
    • Help
    • Submit feedback
    • Contribute to GitLab
  • Sign in
F
finwise-miniapp-be
  • Project
    • Project
    • Details
    • Activity
    • Releases
    • Cycle Analytics
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Charts
  • Issues 0
    • Issues 0
    • List
    • Board
    • Labels
    • Milestones
  • Merge Requests 0
    • Merge Requests 0
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
    • Charts
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Charts
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • ThinhNC
  • finwise-miniapp-be
  • Merge Requests
  • !33

Merged
Opened Aug 21, 2026 by ThinhNC@ThinhNC
  • Report abuse
Report abuse

feat(admin-rbac): implement user management, audit remediation, distributed...

Overview

This PR implements comprehensive administrative user management APIs, remediates security and reliability findings from the code audit, hardens the distributed lock mechanism, and expands the RBAC test coverage.


Key Changes

  • Admin User Management Module:
    • Added GET /api/v1/users with pagination, search, role filtering, and status filtering.
    • Added GET /api/v1/users/:id for detailed profile inspection.
    • Added PATCH /api/v1/users/:id/status (activate/deactivate user accounts).
    • Added PATCH /api/v1/users/:id/role for assigning system and custom roles with permission boundary enforcement.
  • Dynamic RBAC & Permission Matrix:
    • Centralized all permission constants (permission.constant.ts) and system role definitions (system-role.constant.ts).
    • Added granular permission guards (users:read, users:update, users:assign_role, roles:read, roles:write).
    • Seed script updated to initialize baseline permissions, default system roles, and administrator accounts.
  • Security & Reliability Hardening (Audit Remediation):
    • Distributed Lock Service: Implemented UUID fencing tokens, safe release script, TTL validation, and exponential backoff retry.
    • Query Safety: Parameterized date bounds in anomaly detection and cash flow forecasting repositories to eliminate injection/overflow risks.
    • Input Validation: Enforced strict Zod schemas for all user management, authentication, and RBAC endpoints.
    • Worker Lifecycle: Graceful shutdown and signal handling for notification and scheduled workers.
  • Testing & Quality Assurance:
    • Added 300+ lines of comprehensive RBAC unit and integration tests covering role assignment, permission caching/invalidation, and edge cases.

Check out, review, and merge locally

Step 1. Fetch and check out the branch for this merge request

git fetch origin
git checkout -b feat/fe-admin-portal-user-management-and-audit-logs origin/feat/fe-admin-portal-user-management-and-audit-logs

Step 2. Review the changes locally

Step 3. Merge the branch and fix any conflicts that come up

git fetch origin
git checkout origin/develop
git merge --no-ff feat/fe-admin-portal-user-management-and-audit-logs

Step 4. Push the result of the merge to GitLab

git push origin develop

Note that pushing to GitLab requires write access to this repository.

Tip: You can also checkout merge requests locally by following these guidelines.

  • Discussion 0
  • Commits 1
  • Changes 35
Assignee
No assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
0
Labels
None
Assign labels
  • View project labels
Reference: ThinhNC/finwise-miniapp-be!33

Revert this merge request

This will create a new commit in order to revert the existing changes.

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.

Cherry-pick this merge request

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.