Skip to content

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
    • Help
    • Submit feedback
    • Contribute to GitLab
  • Sign in
F
finwise-miniapp-be
  • Project
    • Project
    • Details
    • Activity
    • Releases
    • Cycle Analytics
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Charts
  • Issues 0
    • Issues 0
    • List
    • Board
    • Labels
    • Milestones
  • Merge Requests 0
    • Merge Requests 0
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
    • Charts
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Charts
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • ThinhNC
  • finwise-miniapp-be
  • Merge Requests
  • !34

Merged
Opened Aug 23, 2026 by ThinhNC@ThinhNC
  • Report abuse
Report abuse

feat(be): implement admin control center, api key auth, webhooks, and ssrf protection

Features & Enhancements

  • Admin AI Assistant Management:
    • Added feature toggles (chat, insights, categorizer, forecasting, query).
    • Added prompt template management, rate limit dynamic overrides, cache invalidation, and request audit logging.
  • Admin Notification Engine & Broadcasts:
    • Added multi-channel broadcasting (IN_APP, EMAIL, TELEGRAM) with variable interpolation.
    • Implemented template CRUD, delivery status tracking, and manual retry for failed deliveries.
  • System Settings & Maintenance Mode:
    • Implemented global maintenance mode with configurable bypass for admin roles and whitelisted IPs.
    • Added /api/v1/system/public-config and cache purge capabilities.
  • API Keys & Webhooks Infrastructure:
    • Added secure SHA-256 hashed API Key authentication with granular scopes, rate limiting, and IP whitelisting.
    • Implemented HMAC-SHA256 signature verification (X-Finwise-Signature, X-Finwise-Timestamp) for Webhook delivery with exponential backoff & jitter.
  • Security & SSRF Hardening:
    • Added safeFetch, DNS rebinding validation (validateUrlAsync), and comprehensive IPv4/IPv6 private CIDR checks.
    • Hardened /api/v1/health to prevent internal infrastructure disclosure.
    • Added AES-256-GCM secret encryption helper (crypto.helper.ts).

Check out, review, and merge locally

Step 1. Fetch and check out the branch for this merge request

git fetch origin
git checkout -b feat/admin-control-center-api-keys-and-webhooks origin/feat/admin-control-center-api-keys-and-webhooks

Step 2. Review the changes locally

Step 3. Merge the branch and fix any conflicts that come up

git fetch origin
git checkout origin/develop
git merge --no-ff feat/admin-control-center-api-keys-and-webhooks

Step 4. Push the result of the merge to GitLab

git push origin develop

Note that pushing to GitLab requires write access to this repository.

Tip: You can also checkout merge requests locally by following these guidelines.

  • Discussion 0
  • Commits 1
  • Changes 88
Assignee
No assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
0
Labels
None
Assign labels
  • View project labels
Reference: ThinhNC/finwise-miniapp-be!34

Revert this merge request

This will create a new commit in order to revert the existing changes.

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.

Cherry-pick this merge request

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.