KRYSTALM7 opened a new issue, #160:
URL: https://github.com/apache/fineract-loan-origination/issues/160

   ## Problem
   
   A customer attempting to access an application they do not own is correctly 
blocked, but the API currently returns `HTTP 500`.
   
   The API should return `404 Not Found` so that unauthorized users cannot 
distinguish between a nonexistent application and an application belonging to 
another customer.
   
   ## Runtime Evidence
   
   Customer A attempted to access Customer B's:
   
   - Application details
   - Credit score
   
   Both requests resulted in `HTTP 500`.
   
   ## Root Cause
   
   `CustomerLoanApplicationController.assertOwnedByCaller()` throws an 
access-denial exception.
   
   The exception is caught by the generic exception handler and converted into 
`500`.
   
   ## Proposed Fix
   
   Map customer ownership failures to `404 Not Found`.
   
   Do not expose whether the application exists for another customer.
   
   ## Acceptance Criteria
   
   - [ ] Owner can access their application.
   - [ ] Non-owner receives `404`.
   - [ ] Non-owner receives no application data.
   - [ ] Non-owner cannot distinguish an unauthorized application from a 
nonexistent one.
   
   ## Regression Tests
   
   - [ ] Owner → detail → `200`
   - [ ] Non-owner → detail → `404`
   - [ ] Owner → credit score → `200`
   - [ ] Non-owner → credit score → `404`
   
   ## Dependencies 
   
   None


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to