Skip to content

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
    • Help
    • Submit feedback
    • Contribute to GitLab
  • Sign in
F
finwise-miniapp-be
  • Project
    • Project
    • Details
    • Activity
    • Releases
    • Cycle Analytics
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Charts
  • Issues 0
    • Issues 0
    • List
    • Board
    • Labels
    • Milestones
  • Merge Requests 0
    • Merge Requests 0
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
    • Charts
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Charts
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • ThinhNC
  • finwise-miniapp-be
  • Merge Requests
  • !8

Merged
Opened Jul 24, 2026 by ThinhNC@ThinhNC
  • Report abuse
Report abuse

feat(auth): implement unrecognized device warning and session management

Mô tả tính năng (PR Description)

Tính năng này triển khai hệ thống cảnh báo khi người dùng đăng nhập bằng thiết bị lạ (chưa từng được ghi nhận trong cơ sở dữ liệu) và bổ sung các API để quản lý các phiên đăng nhập (sessions) đang hoạt động.

Các thay đổi chính:

  1. Cơ sở dữ liệu:
    • Thêm bảng UserDevice để lưu trữ dấu vân tay thiết bị của người dùng (tạo từ mã MD5 của User-Agent).
  2. Logic nhận diện & Cảnh báo thiết bị lạ:
    • Tích hợp bước kiểm tra thiết bị khi người dùng đăng nhập thành công.
    • Nếu phát hiện thiết bị lạ (chưa từng đăng ký), hệ thống sẽ lưu thiết bị mới và tự động gửi email cảnh báo bảo mật qua MailService.
    • Tiến hành cải tiến sinh Refresh Token đi kèm jti (JWT ID) để ngăn chặn trùng lặp token trong cơ sở dữ liệu.
  3. Quản lý phiên đăng nhập (Session Management):
    • Thêm API lấy danh sách phiên đăng nhập hoạt động: GET /auth/sessions (có chỉ rõ phiên hiện tại).
    • Thêm API đăng xuất một thiết bị cụ thể từ xa: DELETE /auth/sessions/:id.
    • Thêm API đăng xuất khỏi tất cả các thiết bị khác: DELETE /auth/sessions.
  4. Tài liệu:
    • Cập nhật định nghĩa Swagger (swagger.config.ts) cho các schemas và endpoints mới.

Check out, review, and merge locally

Step 1. Fetch and check out the branch for this merge request

git fetch origin
git checkout -b feat/unrecognized-device-warning origin/feat/unrecognized-device-warning

Step 2. Review the changes locally

Step 3. Merge the branch and fix any conflicts that come up

git fetch origin
git checkout origin/develop
git merge --no-ff feat/unrecognized-device-warning

Step 4. Push the result of the merge to GitLab

git push origin develop

Note that pushing to GitLab requires write access to this repository.

Tip: You can also checkout merge requests locally by following these guidelines.

  • Discussion 0
  • Commits 1
  • Changes 8
Assignee
No assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
0
Labels
None
Assign labels
  • View project labels
Reference: ThinhNC/finwise-miniapp-be!8

Revert this merge request

This will create a new commit in order to revert the existing changes.

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.

Cherry-pick this merge request

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.