Skip to content

FINERACT-2639: enforce office hierarchy access checks - #6260

Open
Disha2002 wants to merge 1 commit into
apache:developfrom
Disha2002:FINERACT-2639
Open

FINERACT-2639: enforce office hierarchy access checks#6260
Disha2002 wants to merge 1 commit into
apache:developfrom
Disha2002:FINERACT-2639

Conversation

@Disha2002

@Disha2002 Disha2002 commented Aug 11, 2026

Copy link
Copy Markdown

Add office hierarchy authorization checks after account and loan reads in write services. Add focused unit tests and account transfer integration tests for sibling-office denial and same-hierarchy success. Include Office hierarchy regeneration test support changes.

Description

This PR implements FINERACT-2639 by enforcing office-hierarchy authorization checks across write flows that read loan, savings, and account entities before performing operations.

What changed

  • Added office-hierarchy access validation to the account transfer write flow to prevent cross-branch access when the authenticated user is outside the target office hierarchy.

  • Added authorization checks across loan write-service paths after entity assembly/read points to ensure office scope is consistently enforced.

  • Added authorization checks across savings write-service paths after entity assembly/read points to ensure office scope is consistently enforced.

  • Added focused unit tests verifying that loan and savings write-service operations invoke office-hierarchy validation.

  • Added integration tests for account-transfer authorization:

    • Negative case: a user scoped to a sibling branch is denied.
    • Positive case: a user scoped within the same hierarchy is allowed.
  • Added office-hierarchy regeneration test coverage to protect hierarchy propagation behavior.

Why

Previously, some write operations could read domain entities and proceed without a consistent office-hierarchy authorization check at all relevant entry points.

This change closes those authorization gaps and makes office-hierarchy enforcement explicit and test-covered across the affected write flows.

Testing

  • Added/updated targeted unit tests for loan and savings write authorization checks.

  • Added integration tests for account-transfer authorization:

    • Deny sibling-branch access.
    • Allow same-hierarchy access.
  • Added office-hierarchy regeneration test coverage.

  • Full test execution in this workspace is currently blocked by unrelated compilation issues in fineract-working-capital-loan.

Risk and impact

  • Security behavior becomes stricter where authorization checks were previously missing.
  • Unauthorized cross-hierarchy operations are now rejected.
  • No expected functional impact to authorized flows; existing authorized scenarios are covered by positive tests.

Checklist

Please make sure these boxes are checked before submitting your pull request - thanks!

  • Write the commit message as per our guidelines
  • Acknowledge that we will not review PRs that are not passing the build ("green") - it is your responsibility to get a proposed PR to pass the build, not primarily the project's maintainers.
  • Create/update unit or integration tests for verifying the changes made.
  • Follow our coding conventions.
  • Add required Swagger annotation and update API documentation at fineract-provider/src/main/resources/static/legacy-docs/apiLive.htm with details of any API changes
  • This PR must not be a "code dump". Large changes can be made in a branch, with assistance. Ask for help on the developer mailing list.
  • If merging this PR resolves a JIRA issue, I will mark that issue as resolved and set "Fix Version/s" appropriately.

Your assigned reviewer(s) will follow our guidelines for code reviews.

@Disha2002

Copy link
Copy Markdown
Author

@adamsaghy Please review the when you have a chance.

@Disha2002
Disha2002 marked this pull request as draft August 11, 2026 14:24
@adamsaghy
adamsaghy marked this pull request as ready for review August 11, 2026 14:25
- add office hierarchy authorization checks in transfer, loan, and savings write flows

- add unit tests and integration tests for deny/allow office-scope scenarios

- wire PlatformSecurityContext in account configuration

@elnafateh elnafateh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run these first before pushing any changes :
./gradlew --no-daemon spotlessApply spotbugsMain spotbugsTest checkstyleMain checkstyleTest
./gradlew --no-daemon build -x test -x cucumber -x doc

@elnafateh

Copy link
Copy Markdown
Contributor

you also need to sign your commits

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants