rymghosn commented on code in PR #6197:
URL: https://github.com/apache/fineract/pull/6197#discussion_r4183234396


##########
fineract-provider/src/main/java/org/apache/fineract/infrastructure/entityaccess/service/FineractEntityAccessReadServiceImpl.java:
##########
@@ -204,6 +204,19 @@ public FineractEntityRelationData mapRow(final ResultSet 
rs, @SuppressWarnings("
     @Override
     public Collection<FineractEntityToEntityMappingData> 
retrieveEntityToEntityMappings(Long mapId, Long fromId, Long toId) {
 
+        if (fromId == 0) {
+            final String fromEntityTypeSql = "SELECT er.from_entity_type FROM 
m_entity_relation er WHERE er.id = ?";

Review Comment:
   Done. The native query (and the recursive CTE) is gone. Scoping now uses the 
office `hierarchy` through a JPQL repository method, 
`OfficeRepository.findIdsByHierarchyLike`, and the relation type comes from 
`FineractEntityRelationRepository.findById`. The existing mapping read is 
unchanged; for office-based relations its rows are filtered by the user's 
office ids. This also closes the same leak when the caller asks for one 
specific office outside their hierarchy, not only `fromId = 0`. The integration 
test covers that case too.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to