KRYSTALM7 opened a new issue, #159:
URL: https://github.com/apache/fineract-loan-origination/issues/159

   ## Problem
   
   Requests that are correctly denied by method-level authorization currently 
return `HTTP 500`.
   
   For example, a customer attempting to invoke a staff-only endpoint is 
blocked, but the API reports an internal server error instead of `403 
Forbidden`.
   
   ## Runtime Evidence
   
   Customer JWT:
   
   `POST /api/v1/loan-applications/{ref}/start-review`
   
   → `HTTP 500`
   
   Customer JWT:
   
   `POST /api/v1/loan-applications/{ref}/disburse`
   
   → `HTTP 500`
   
   The requests are blocked before the protected method executes.
   
   ## Root Cause
   
   `GlobalExceptionHandler` contains a broad `Exception` handler returning 
`500`.
   
   There are no explicit handlers for the Spring Security authorization 
exceptions raised by method security.
   
   ## Proposed Fix
   
   Add explicit handling for:
   
   - `AccessDeniedException`
   - `AuthorizationDeniedException`
   
   Return:
   
   `HTTP 403 Forbidden`
   
   with a consistent error response.
   
   ## Acceptance Criteria
   
   - [ ] Authenticated users without permission receive `403`.
   - [ ] No protected method executes after authorization failure.
   - [ ] No Fineract request is made.
   - [ ] Error response follows the project's standard API error format.
   - [ ] Existing authorization behavior remains unchanged.
   
   ## Regression Tests
   
   - [ ] Customer → staff endpoint → `403`
   - [ ] Unauthorized staff role → restricted operation → `403`
   - [ ] Verify no downstream service call occurs.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to