Skip to content

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
    • Help
    • Submit feedback
    • Contribute to GitLab
  • Sign in
F
finwise-miniapp-be
  • Project
    • Project
    • Details
    • Activity
    • Releases
    • Cycle Analytics
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Charts
  • Issues 0
    • Issues 0
    • List
    • Board
    • Labels
    • Milestones
  • Merge Requests 0
    • Merge Requests 0
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
    • Charts
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Charts
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • ThinhNC
  • finwise-miniapp-be
  • Merge Requests
  • !39

Merged
Opened Aug 29, 2026 by ThinhNC@ThinhNC
  • Report abuse
Report abuse

feat(auth): support server-side Zalo phoneToken decoding with resilient...

Features & Enhancements

1. Zalo Phone Token Resolution (Server-to-Server)

  • Updated ZaloLoginDto and zaloLoginSchema to support phoneToken returned by zmp-sdk's getPhoneNumber().
  • Implemented fetchZaloPhoneNumber() querying GET https://graph.zalo.me/v2.0/me/info with access_token, code (phoneToken), and secret_key (ZALO_APP_SECRET).
  • Automated phone number normalization (e.g., converting 84xxxxxxxxx or +84xxxxxxxxx to Vietnamese domestic standard 0xxxxxxxxx).

2. Resilient Hybrid Auth for Global Deployments (Fixes Zalo IP Error -501)

  • Handled Zalo Open API geographical restriction (error: -501: Personal information is limited due to IP address not inside Vietnam) when hosted on global cloud providers (Render/AWS/GCP).
  • Added graceful fallbacks allowing authentication via client-verified zaloId / deterministic identity while still resolving phone numbers when permissible.
  • Fixed response parsing logic where successful Zalo profile API calls (which do not return an error key) were previously falsely flagged as invalid credentials.

Check out, review, and merge locally

Step 1. Fetch and check out the branch for this merge request

git fetch origin
git checkout -b feat/zalo-phone-token-auth origin/feat/zalo-phone-token-auth

Step 2. Review the changes locally

Step 3. Merge the branch and fix any conflicts that come up

git fetch origin
git checkout origin/develop
git merge --no-ff feat/zalo-phone-token-auth

Step 4. Push the result of the merge to GitLab

git push origin develop

Note that pushing to GitLab requires write access to this repository.

Tip: You can also checkout merge requests locally by following these guidelines.

  • Discussion 0
  • Commits 1
  • Changes 4
Assignee
No assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
0
Labels
None
Assign labels
  • View project labels
Reference: ThinhNC/finwise-miniapp-be!39

Revert this merge request

This will create a new commit in order to revert the existing changes.

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.

Cherry-pick this merge request

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.