Skip to content

FINERACT-2455: WC - Add missing permissions for transaction undo and charge creation - #6449

Merged
adamsaghy merged 2 commits into
apache:developfrom
openMF:FINERACT-2455/wc-missing-command-permissions
Sep 24, 2026
Merged

adamsaghy merged 2 commits into
apache:developfrom
openMF:FINERACT-2455/wc-missing-command-permissions

Conversation

@oleksii-novikov-onix

Copy link
Copy Markdown
Contributor

Description

Undoing a Working Capital loan transaction and adding a charge to a Working Capital loan both check permission codes that have no row in m_permission, so only a super user can run them. Transaction undo also had a typo in its entity constant, which made the checked code UNDO_ENTITY_WORKINGCAPITALLOANTRANSACTION.

  1. Fixed the entity constant value to WORKINGCAPITALLOANTRANSACTION.
  2. Seeded UNDO_WORKINGCAPITALLOANTRANSACTION, CREATE_WORKINGCAPITALLOANCHARGE and CREATE_WORKINGCAPITALLOANCHARGE_CHECKER, all in grouping transaction_loan.
  3. Added e2e scenarios: a non-super user holding the permission can undo a repayment and add a charge; without the undo permission the request is rejected with 403.
  4. Updated the recovery payment and charges docs.

Checklist

Please make sure these boxes are checked before submitting your pull request - thanks!

  • Write the commit message as per our guidelines
  • Acknowledge that we will not review PRs that are not passing the build ("green") - it is your responsibility to get a proposed PR to pass the build, not primarily the project's maintainers.
  • Create/update unit or integration tests for verifying the changes made.
  • Follow our coding conventions.
  • Add required Swagger annotation and update API documentation at fineract-provider/src/main/resources/static/legacy-docs/apiLive.htm with details of any API changes
  • This PR must not be a "code dump". Large changes can be made in a branch, with assistance. Ask for help on the developer mailing list.
  • If merging this PR resolves a JIRA issue, I will mark that issue as resolved and set "Fix Version/s" appropriately.
  • I followed the AI Policy.

Your assigned reviewer(s) will follow our guidelines for code reviews.

@oleksii-novikov-onix
oleksii-novikov-onix force-pushed the FINERACT-2455/wc-missing-command-permissions branch 3 times, most recently from 5f3a8a4 to 8fbea6b Compare September 16, 2026 14:23
@oleksii-novikov-onix
oleksii-novikov-onix marked this pull request as ready for review September 18, 2026 13:17
@adamsaghy

Copy link
Copy Markdown
Contributor

@oleksii-novikov-onix Please review the below finding / concern:

  • 0081_wc_loan_missing_command_permissions.xml:26 — UNDO_WORKINGCAPITALLOANTRANSACTION_CHECKER is not seeded, unlike the charge permission which does get its CHECKER row. UNDO_WORKINGCAPITALLOANTRANSACTION is maker-checkerable (grouping isn't special, code isn't READ*), so once a tenant enables maker-checker for it, validateHasCheckerPermissionTo requires UNDO_WORKINGCAPITALLOANTRANSACTION_CHECKER, which no role can be granted — leaving approval to CHECKER_SUPER_USER only, the same restriction the PR is removing.

Lets fix this as well please

  • One prose nit, not reported as a finding: working-capital-recovery-payment.adoc:278 now reads "The reversal adds no permission of its own ... and is guarded by UNDO_WORKINGCAPITALLOANTRANSACTION", which reads as a contradiction unless you know the permission is the shared transaction-undo one.

@oleksii-novikov-onix
oleksii-novikov-onix force-pushed the FINERACT-2455/wc-missing-command-permissions branch from eeaebf4 to a5f8258 Compare September 21, 2026 12:49
@oleksii-novikov-onix

Copy link
Copy Markdown
Contributor Author

@oleksii-novikov-onix Please review the below finding / concern:

  • 0081_wc_loan_missing_command_permissions.xml:26 — UNDO_WORKINGCAPITALLOANTRANSACTION_CHECKER is not seeded, unlike the charge permission which does get its CHECKER row. UNDO_WORKINGCAPITALLOANTRANSACTION is maker-checkerable (grouping isn't special, code isn't READ*), so once a tenant enables maker-checker for it, validateHasCheckerPermissionTo requires UNDO_WORKINGCAPITALLOANTRANSACTION_CHECKER, which no role can be granted — leaving approval to CHECKER_SUPER_USER only, the same restriction the PR is removing.

Lets fix this as well please

  • One prose nit, not reported as a finding: working-capital-recovery-payment.adoc:278 now reads "The reversal adds no permission of its own ... and is guarded by UNDO_WORKINGCAPITALLOANTRANSACTION", which reads as a contradiction unless you know the permission is the shared transaction-undo one.
  1. Fixed - added changeset wcl-0081-4 seeding UNDO_WORKINGCAPITALLOANTRANSACTION_CHECKER (grouping transaction_loan, entity WORKINGCAPITALLOANTRANSACTION, action UNDO_CHECKER, can_maker_checker false), same shape as wcl-0044-6.
  2. Fixed - reworded so the shared transaction-undo permission comes first and the negation last.

@adamsaghy

Copy link
Copy Markdown
Contributor

@oleksii-novikov-onix Please review my finding:

CommandWrapperConstants.java:186 — the entity rename is persisted into m_portfolio_command_source.entity_name, but no backfill ships with it, so pre-upgrade WC undo audit rows stay under ENTITY_WORKINGCAPITALLOANTRANSACTION: like 'WORKINGCAPITALLOANTRANSACTION%' audit filters miss them, and the limited-checker join on p.entity_name = aud.entity_name will never match them against the new _CHECKER permission.

@oleksii-novikov-onix
oleksii-novikov-onix force-pushed the FINERACT-2455/wc-missing-command-permissions branch from a5f8258 to c437ec6 Compare September 23, 2026 06:13
@oleksii-novikov-onix

Copy link
Copy Markdown
Contributor Author

@oleksii-novikov-onix Please review my finding:

CommandWrapperConstants.java:186 — the entity rename is persisted into m_portfolio_command_source.entity_name, but no backfill ships with it, so pre-upgrade WC undo audit rows stay under ENTITY_WORKINGCAPITALLOANTRANSACTION: like 'WORKINGCAPITALLOANTRANSACTION%' audit filters miss them, and the limited-checker join on p.entity_name = aud.entity_name will never match them against the new _CHECKER permission.

Fixed, added changeset wcl-0081-5 to 0081_wc_loan_missing_command_permissions.xml, backfilling m_portfolio_command_source.entity_name from ENTITY_WORKINGCAPITALLOANTRANSACTION to WORKINGCAPITALLOANTRANSACTION.

@ruzeynalov
ruzeynalov force-pushed the FINERACT-2455/wc-missing-command-permissions branch from c437ec6 to 83b1bcd Compare September 23, 2026 10:23
galovics
galovics previously approved these changes Sep 23, 2026

@galovics galovics left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checked the permission codes against what the command framework actually derives: undoWorkingCapitalLoanTransaction pairs ACTION_UNDO with ENTITY_WORKINGCAPITALLOANTRANSACTION, which after the constant fix resolves to UNDO_WORKINGCAPITALLOANTRANSACTION (before it was UNDO_ENTITY_WORKINGCAPITALLOANTRANSACTION, which matched no seeded row). createWorkingCapitalLoanCharge resolves to CREATE_WORKINGCAPITALLOANCHARGE. The handler's @CommandType uses the same constant so routing is unaffected, and the _CHECKER codes match what AppUser builds. I also compared all 36 WC @CommandType pairs against the seeded m_permission rows - after this PR every WC command has a matching permission, so nothing else is left super-user-only.

Liquibase follows the module conventions (idempotent sqlCheck/MARK_RAN, _CHECKER rows with can_maker_checker=false, no deletes, no edits to existing changesets), and renaming entity_name in m_portfolio_command_source (wcl-0081-5) keeps the audit history searchable. E2E covers allowed and 403 paths for both undo and charge creation, plus a user with only the undo permission undoing a charge adjustment.

Non-blocking:

  • Five other open WC PRs (#6454, #6446, #6425, #6399, #6398) also add a 0081_* part. Not a real Liquibase conflict (identity is id + author + file), but whoever merges second needs to renumber.
  • The columnExists precondition on m_portfolio_command_source.entity_name in wcl-0081-5 can never fail (column is in the base schema) - either drop it or replace it with a sqlCheck for rows still holding the old value.
  • The description says three rows but the diff also seeds UNDO_..._CHECKER and does the command-source rewrite.
  • Admins now have to grant the two permissions themselves (no m_role_permission touch, which is the convention) - worth a line in the release notes.

Recommendation: APPROVE

@adamsaghy
adamsaghy force-pushed the FINERACT-2455/wc-missing-command-permissions branch from 83b1bcd to b0121b3 Compare September 24, 2026 15:40
adamsaghy
adamsaghy previously approved these changes Sep 24, 2026

@adamsaghy adamsaghy left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

…issions for transaction undo and charge creation
@adamsaghy
adamsaghy force-pushed the FINERACT-2455/wc-missing-command-permissions branch from b0121b3 to 4db1e17 Compare September 24, 2026 16:34

@adamsaghy adamsaghy left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@adamsaghy
adamsaghy merged commit ca2222b into apache:develop Sep 24, 2026
94 checks passed
@adamsaghy
adamsaghy deleted the FINERACT-2455/wc-missing-command-permissions branch September 24, 2026 18:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants