[ 
https://issues.apache.org/jira/browse/FINERACT-2480?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18062311#comment-18062311
 ] 

Ashhar Ahmad Khan commented on FINERACT-2480:
---------------------------------------------

While working on this issuue,  I kept running into traces of the old module and 
one thing caught my attention: {{0017_fix_stretchy_reports.xml}} still has 
stretchy parameter SQL queries filtering on {{{}${isSelfServiceUser}{}}}. With 
the removal done, that flag will never be true again, which made me think about 
what a clean replacement would actually need to account for.

That line of thinking led me here. I noticed this is tagged as a GSoC 2026 idea 
and I wanted to say I am genuinely interested in putting a proposal together 
for this. The removal work gave me a pretty detailed view of what the old 
module did wrong and why, which I think is useful context for designing 
something better.

Looking forward to the process kicking off James Dailey.

> Remove insecure self service feature
> ------------------------------------
>
>                 Key: FINERACT-2480
>                 URL: https://issues.apache.org/jira/browse/FINERACT-2480
>             Project: Apache Fineract
>          Issue Type: Task
>            Reporter: Victor Romero
>            Priority: Major
>
> Remove insecure self service feature
> As a second phase of disabling the Self Service APIs addressed in this PR 
> [https://github.com/apache/fineract/pull/4671] we are now doing the removal 
> of the insecure self service APIs



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to