Skip to content

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
    • Help
    • Submit feedback
    • Contribute to GitLab
  • Sign in
F
finwise-miniapp-be
  • Project
    • Project
    • Details
    • Activity
    • Releases
    • Cycle Analytics
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Charts
  • Issues 0
    • Issues 0
    • List
    • Board
    • Labels
    • Milestones
  • Merge Requests 0
    • Merge Requests 0
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
    • Charts
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Charts
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • ThinhNC
  • finwise-miniapp-be
  • Merge Requests
  • !36

Merged
Opened Aug 25, 2026 by ThinhNC@ThinhNC
  • Report abuse
Report abuse

feat(auth): add dedicated avatar endpoints, session pagination, and audit log idempotency

Summary of Changes

This PR introduces dedicated avatar management endpoints with S3/MinIO cleanup, adds pagination support for active sessions, optimizes audit log creation through idempotency checks, and enhances user projection security.

Key Changes

  • Dedicated Avatar Endpoints:
    • Added PUT /api/v1/auth/avatar: Updates avatarUrl, avatarPositionX, and avatarPositionY.
    • Added DELETE /api/v1/auth/avatar: Deletes user avatar, resets position to default (50/50), and deletes stored image object via UploadService.deleteObject.
    • Decoupled avatar payload from general profile update (PUT /api/v1/auth/profile).
  • Session Pagination:
    • Updated GET /api/v1/auth/sessions with page and limit query validation and standard pagination metadata (meta: { total, page, limit, totalPages }).
  • Audit Log Idempotency & Optimization:
    • Prevented redundant audit logs in updateProfile, updateAvatar, and assignPermissions when incoming payload matches existing database state.
  • Security & Data Projections:
    • Added userSelect masking across user repository queries to avoid leaking passwordHash on soft delete and projection updates.
    • Added fullName support during admin user creation.
  • Testing:
    • Added comprehensive integration tests covering avatar lifecycle, profile updates, session pagination query validation, and RBAC idempotency.

Check out, review, and merge locally

Step 1. Fetch and check out the branch for this merge request

git fetch origin
git checkout -b feat/avatar-management-and-session-pagination origin/feat/avatar-management-and-session-pagination

Step 2. Review the changes locally

Step 3. Merge the branch and fix any conflicts that come up

git fetch origin
git checkout origin/develop
git merge --no-ff feat/avatar-management-and-session-pagination

Step 4. Push the result of the merge to GitLab

git push origin develop

Note that pushing to GitLab requires write access to this repository.

Tip: You can also checkout merge requests locally by following these guidelines.

  • Discussion 0
  • Commits 1
  • Changes 17
Assignee
No assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
0
Labels
None
Assign labels
  • View project labels
Reference: ThinhNC/finwise-miniapp-be!36

Revert this merge request

This will create a new commit in order to revert the existing changes.

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.

Cherry-pick this merge request

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.