KRYSTALM7 opened a new issue, #159:
URL: https://github.com/apache/fineract-loan-origination/issues/159
## Problem
Requests that are correctly denied by method-level authorization currently
return `HTTP 500`.
For example, a customer attempting to invoke a staff-only endpoint is
blocked, but the API reports an internal server error instead of `403
Forbidden`.
## Runtime Evidence
Customer JWT:
`POST /api/v1/loan-applications/{ref}/start-review`
→ `HTTP 500`
Customer JWT:
`POST /api/v1/loan-applications/{ref}/disburse`
→ `HTTP 500`
The requests are blocked before the protected method executes.
## Root Cause
`GlobalExceptionHandler` contains a broad `Exception` handler returning
`500`.
There are no explicit handlers for the Spring Security authorization
exceptions raised by method security.
## Proposed Fix
Add explicit handling for:
- `AccessDeniedException`
- `AuthorizationDeniedException`
Return:
`HTTP 403 Forbidden`
with a consistent error response.
## Acceptance Criteria
- [ ] Authenticated users without permission receive `403`.
- [ ] No protected method executes after authorization failure.
- [ ] No Fineract request is made.
- [ ] Error response follows the project's standard API error format.
- [ ] Existing authorization behavior remains unchanged.
## Regression Tests
- [ ] Customer → staff endpoint → `403`
- [ ] Unauthorized staff role → restricted operation → `403`
- [ ] Verify no downstream service call occurs.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]