[ 
https://issues.apache.org/jira/browse/FINERACT-1988?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18099901#comment-18099901
 ] 

Siva Sai Udayagiri commented on FINERACT-1988:
----------------------------------------------

Hi, I reviewed the current {{develop}} branch for this issue. I could not find 
an existing OPA/Rego implementation or a related completed PR.

Fineract’s security architecture appears to have changed since this issue was 
created, including OAuth2/OIDC support and more authorization rules using 
Spring Security’s {{{}AuthorizationManager{}}}. Existing authorization still 
seems to rely mainly on Fineract roles, permissions, and command-level checks.

Is FINERACT-1988 still valid with the original scope? If it is, could you 
please confirm where maintainers would prefer OPA to integrate with the current 
architecture?

I would like to start with a small, reviewable PR, possibly an optional 
authorization-provider extension point and configuration structure, rather than 
implementing the full OPA integration immediately. I can share a design 
proposal before making code changes.

> Modular Security Architecture: Phase 5
> --------------------------------------
>
>                 Key: FINERACT-1988
>                 URL: https://issues.apache.org/jira/browse/FINERACT-1988
>             Project: Apache Fineract
>          Issue Type: Sub-task
>            Reporter: Aleksandar Vidakovic
>            Priority: Major
>
> Add Open Policy Agent based authorization module.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to