[
https://issues.apache.org/jira/browse/FINERACT-1988?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18099901#comment-18099901
]
Siva Sai Udayagiri commented on FINERACT-1988:
----------------------------------------------
Hi, I reviewed the current {{develop}} branch for this issue. I could not find
an existing OPA/Rego implementation or a related completed PR.
Fineract’s security architecture appears to have changed since this issue was
created, including OAuth2/OIDC support and more authorization rules using
Spring Security’s {{{}AuthorizationManager{}}}. Existing authorization still
seems to rely mainly on Fineract roles, permissions, and command-level checks.
Is FINERACT-1988 still valid with the original scope? If it is, could you
please confirm where maintainers would prefer OPA to integrate with the current
architecture?
I would like to start with a small, reviewable PR, possibly an optional
authorization-provider extension point and configuration structure, rather than
implementing the full OPA integration immediately. I can share a design
proposal before making code changes.
> Modular Security Architecture: Phase 5
> --------------------------------------
>
> Key: FINERACT-1988
> URL: https://issues.apache.org/jira/browse/FINERACT-1988
> Project: Apache Fineract
> Issue Type: Sub-task
> Reporter: Aleksandar Vidakovic
> Priority: Major
>
> Add Open Policy Agent based authorization module.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)