KRYSTALM7 opened a new issue, #152:
URL: https://github.com/apache/fineract-loan-origination/issues/152
## Problem
Customer-authenticated users can access endpoints under the staff loan
application API using a valid customer JWT.
In particular:
`GET /api/v1/loan-applications/{applicationRef}/staff-detail`
accepts a customer JWT and returns the full staff-facing application details.
The response can contain sensitive applicant and loan information such as:
- Applicant name
- National ID
- Monthly income
- Existing loan obligations
- Credit score
- Fineract client/loan identifiers
- Approval stages
- Approver identities
- Approval decisions, notes and timestamps
The endpoint is intended to be available only to authenticated staff users.
## Runtime Evidence
A customer JWT was used against:
`GET /api/v1/loan-applications/LOS-2026-00023/staff-detail`
The endpoint returned `HTTP 200` with staff-level application information.
## Root Cause
`LoanApplicationController.getStaffDetail()` does not currently enforce a
staff-role restriction.
The staff security filter chain only requires:
`authenticated()`
rather than requiring `ROLE_STAFF`.
Additionally, the service method retrieves the application using tenant
information but does not perform an authorization check against the caller.
## Impact
A registered customer may access sensitive information belonging to other
applicants in the same tenant if they know or can determine an application
reference.
Application references also follow a predictable format, increasing the risk
of enumeration.
## Proposed Fix
- Restrict `LoanApplicationController` to staff users.
- Add an explicit staff route rule for `/api/v1/loan-applications/**`.
- Ensure customer JWTs receive `403 Forbidden`.
- Add regression tests covering customer and staff access.
## Acceptance Criteria
- [ ] Customer JWT receives `403 Forbidden` for
`/api/v1/loan-applications/{ref}/staff-detail`.
- [ ] No application data is returned in the denied response.
- [ ] Loan Officer JWT can access the endpoint.
- [ ] Branch Manager JWT can access the endpoint.
- [ ] Customer JWT cannot access any endpoint exposed by
`LoanApplicationController`.
## Regression Tests
- [ ] Customer token → staff detail → `403`
- [ ] Loan Officer token → staff detail → `200`
- [ ] Branch Manager token → staff detail → `200`
- [ ] Customer token → staff application list → `403`
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]