KRYSTALM7 opened a new issue, #160: URL: https://github.com/apache/fineract-loan-origination/issues/160
## Problem A customer attempting to access an application they do not own is correctly blocked, but the API currently returns `HTTP 500`. The API should return `404 Not Found` so that unauthorized users cannot distinguish between a nonexistent application and an application belonging to another customer. ## Runtime Evidence Customer A attempted to access Customer B's: - Application details - Credit score Both requests resulted in `HTTP 500`. ## Root Cause `CustomerLoanApplicationController.assertOwnedByCaller()` throws an access-denial exception. The exception is caught by the generic exception handler and converted into `500`. ## Proposed Fix Map customer ownership failures to `404 Not Found`. Do not expose whether the application exists for another customer. ## Acceptance Criteria - [ ] Owner can access their application. - [ ] Non-owner receives `404`. - [ ] Non-owner receives no application data. - [ ] Non-owner cannot distinguish an unauthorized application from a nonexistent one. ## Regression Tests - [ ] Owner → detail → `200` - [ ] Non-owner → detail → `404` - [ ] Owner → credit score → `200` - [ ] Non-owner → credit score → `404` ## Dependencies None -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
