Disha2002 opened a new pull request, #6260:
URL: https://github.com/apache/fineract/pull/6260
Add office hierarchy authorization checks after account and loan reads in
write services. Add focused unit tests and account transfer integration tests
for sibling-office denial and same-hierarchy success. Include Office hierarchy
regeneration test support changes.
## Description
This PR implements **FINERACT-2639** by enforcing office-hierarchy
authorization checks across write flows that read loan, savings, and account
entities before performing operations.
## What changed
* Added office-hierarchy access validation to the **account transfer write
flow** to prevent cross-branch access when the authenticated user is outside
the target office hierarchy.
* Added authorization checks across **loan write-service paths** after
entity assembly/read points to ensure office scope is consistently enforced.
* Added authorization checks across **savings write-service paths** after
entity assembly/read points to ensure office scope is consistently enforced.
* Added focused unit tests verifying that loan and savings write-service
operations invoke office-hierarchy validation.
* Added integration tests for account-transfer authorization:
* **Negative case:** a user scoped to a sibling branch is denied.
* **Positive case:** a user scoped within the same hierarchy is allowed.
* Added office-hierarchy regeneration test coverage to protect hierarchy
propagation behavior.
## Why
Previously, some write operations could read domain entities and proceed
without a consistent office-hierarchy authorization check at all relevant entry
points.
This change closes those authorization gaps and makes office-hierarchy
enforcement explicit and test-covered across the affected write flows.
## Testing
* Added/updated targeted unit tests for loan and savings write authorization
checks.
* Added integration tests for account-transfer authorization:
* Deny sibling-branch access.
* Allow same-hierarchy access.
* Added office-hierarchy regeneration test coverage.
* Full test execution in this workspace is currently blocked by unrelated
compilation issues in `fineract-working-capital-loan`.
## Risk and impact
* Security behavior becomes stricter where authorization checks were
previously missing.
* Unauthorized cross-hierarchy operations are now rejected.
* No expected functional impact to authorized flows; existing authorized
scenarios are covered by positive tests.
## Checklist
Please make sure these boxes are checked before submitting your pull request
- thanks!
- [ ] Write the commit message as per [our
guidelines](https://github.com/apache/fineract/blob/develop/CONTRIBUTING.md#pull-requests)
- [ ] Acknowledge that we will not review PRs that are not passing the build
_("green")_ - it is your responsibility to get a proposed PR to pass the build,
not primarily the project's maintainers.
- [ ] Create/update [unit or integration
tests](https://fineract.apache.org/docs/current/#_testing) for verifying the
changes made.
- [ ] Follow our [coding
conventions](https://cwiki.apache.org/confluence/display/FINERACT/Coding+Conventions).
- [ ] Add required Swagger annotation and update API documentation at
fineract-provider/src/main/resources/static/legacy-docs/apiLive.htm with
details of any API changes
- [ ] [This PR must not be a "code
dump"](https://cwiki.apache.org/confluence/display/FINERACT/Pull+Request+Size+Limit).
Large changes can be made in a branch, with assistance. Ask for help on the
[developer mailing list](https://fineract.apache.org/#contribute).
- [ ] If merging this PR resolves a JIRA issue, I will mark that issue as
resolved and set "Fix Version/s" appropriately.
Your assigned reviewer(s) will follow our [guidelines for code
reviews](https://cwiki.apache.org/confluence/display/FINERACT/Code+Review+Guide).
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]