[
https://issues.apache.org/jira/browse/FINERACT-2480?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18062311#comment-18062311
]
Ashhar Ahmad Khan edited comment on FINERACT-2480 at 3/3/26 12:43 AM:
----------------------------------------------------------------------
While working on this issue, I kept running into traces of the old module and
one thing caught my attention: {{0017_fix_stretchy_reports.xml}} still has
stretchy parameter SQL queries filtering on {{{}${isSelfServiceUser}{}}}. With
the removal done, that flag will never be true again, which made me think about
what a clean replacement would actually need to account for.
That line of thinking led me to FINERACT-2439. I noticed it is tagged as a GSoC
2026 idea and I am genuinely interested in putting a proposal together for it.
The removal work gave me a detailed view of what the old module did wrong and
why, which I think is useful context for designing something better.
Looking forward to the process kicking off James Dailey.
was (Author: JIRAUSER312352):
While working on this issue, I kept running into traces of the old module and
one thing caught my attention: {{0017_fix_stretchy_reports.xml}} still has
stretchy parameter SQL queries filtering on {{{}${isSelfServiceUser}{}}}. With
the removal done, that flag will never be true again, which made me think about
what a clean replacement would actually need to account for.
That line of thinking led me to FINERACT-2439. I noticed it is tagged as a GSoC
2026 idea and I am genuinely interested in putting a proposal together for it.
The removal work gave me a detailed view of what the old module did wrong and
why, which I think is useful context for designing something better.
Looking forward to the process kicking off James Dailey.
> Remove insecure self service feature
> ------------------------------------
>
> Key: FINERACT-2480
> URL: https://issues.apache.org/jira/browse/FINERACT-2480
> Project: Apache Fineract
> Issue Type: Task
> Reporter: Victor Romero
> Priority: Major
>
> Remove insecure self service feature
> As a second phase of disabling the Self Service APIs addressed in this PR
> [https://github.com/apache/fineract/pull/4671] we are now doing the removal
> of the insecure self service APIs
--
This message was sent by Atlassian Jira
(v8.20.10#820010)