Skip to content

FINERACT-2455: WC - Add missing permissions for transaction undo and charge creation - #6449

Open
oleksii-novikov-onix wants to merge 2 commits into
apache:developfrom
openMF:FINERACT-2455/wc-missing-command-permissions
Open

oleksii-novikov-onix wants to merge 2 commits into
apache:developfrom
openMF:FINERACT-2455/wc-missing-command-permissions

Conversation

@oleksii-novikov-onix

Copy link
Copy Markdown
Contributor

Description

Undoing a Working Capital loan transaction and adding a charge to a Working Capital loan both check permission codes that have no row in m_permission, so only a super user can run them. Transaction undo also had a typo in its entity constant, which made the checked code UNDO_ENTITY_WORKINGCAPITALLOANTRANSACTION.

  1. Fixed the entity constant value to WORKINGCAPITALLOANTRANSACTION.
  2. Seeded UNDO_WORKINGCAPITALLOANTRANSACTION, CREATE_WORKINGCAPITALLOANCHARGE and CREATE_WORKINGCAPITALLOANCHARGE_CHECKER, all in grouping transaction_loan.
  3. Added e2e scenarios: a non-super user holding the permission can undo a repayment and add a charge; without the undo permission the request is rejected with 403.
  4. Updated the recovery payment and charges docs.

Checklist

Please make sure these boxes are checked before submitting your pull request - thanks!

  • Write the commit message as per our guidelines
  • Acknowledge that we will not review PRs that are not passing the build ("green") - it is your responsibility to get a proposed PR to pass the build, not primarily the project's maintainers.
  • Create/update unit or integration tests for verifying the changes made.
  • Follow our coding conventions.
  • Add required Swagger annotation and update API documentation at fineract-provider/src/main/resources/static/legacy-docs/apiLive.htm with details of any API changes
  • This PR must not be a "code dump". Large changes can be made in a branch, with assistance. Ask for help on the developer mailing list.
  • If merging this PR resolves a JIRA issue, I will mark that issue as resolved and set "Fix Version/s" appropriately.
  • I followed the AI Policy.

Your assigned reviewer(s) will follow our guidelines for code reviews.

@oleksii-novikov-onix
oleksii-novikov-onix force-pushed the FINERACT-2455/wc-missing-command-permissions branch 3 times, most recently from 5f3a8a4 to 8fbea6b Compare September 16, 2026 14:23
@oleksii-novikov-onix
oleksii-novikov-onix marked this pull request as ready for review September 18, 2026 13:17
@adamsaghy

Copy link
Copy Markdown
Contributor

@oleksii-novikov-onix Please review the below finding / concern:

  • 0081_wc_loan_missing_command_permissions.xml:26 — UNDO_WORKINGCAPITALLOANTRANSACTION_CHECKER is not seeded, unlike the charge permission which does get its CHECKER row. UNDO_WORKINGCAPITALLOANTRANSACTION is maker-checkerable (grouping isn't special, code isn't READ*), so once a tenant enables maker-checker for it, validateHasCheckerPermissionTo requires UNDO_WORKINGCAPITALLOANTRANSACTION_CHECKER, which no role can be granted — leaving approval to CHECKER_SUPER_USER only, the same restriction the PR is removing.

Lets fix this as well please

  • One prose nit, not reported as a finding: working-capital-recovery-payment.adoc:278 now reads "The reversal adds no permission of its own ... and is guarded by UNDO_WORKINGCAPITALLOANTRANSACTION", which reads as a contradiction unless you know the permission is the shared transaction-undo one.

@oleksii-novikov-onix
oleksii-novikov-onix force-pushed the FINERACT-2455/wc-missing-command-permissions branch from eeaebf4 to a5f8258 Compare September 21, 2026 12:49
@oleksii-novikov-onix

Copy link
Copy Markdown
Contributor Author

@oleksii-novikov-onix Please review the below finding / concern:

  • 0081_wc_loan_missing_command_permissions.xml:26 — UNDO_WORKINGCAPITALLOANTRANSACTION_CHECKER is not seeded, unlike the charge permission which does get its CHECKER row. UNDO_WORKINGCAPITALLOANTRANSACTION is maker-checkerable (grouping isn't special, code isn't READ*), so once a tenant enables maker-checker for it, validateHasCheckerPermissionTo requires UNDO_WORKINGCAPITALLOANTRANSACTION_CHECKER, which no role can be granted — leaving approval to CHECKER_SUPER_USER only, the same restriction the PR is removing.

Lets fix this as well please

  • One prose nit, not reported as a finding: working-capital-recovery-payment.adoc:278 now reads "The reversal adds no permission of its own ... and is guarded by UNDO_WORKINGCAPITALLOANTRANSACTION", which reads as a contradiction unless you know the permission is the shared transaction-undo one.
  1. Fixed - added changeset wcl-0081-4 seeding UNDO_WORKINGCAPITALLOANTRANSACTION_CHECKER (grouping transaction_loan, entity WORKINGCAPITALLOANTRANSACTION, action UNDO_CHECKER, can_maker_checker false), same shape as wcl-0044-6.
  2. Fixed - reworded so the shared transaction-undo permission comes first and the negation last.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants