Conversation
|
Hi @Tanjim003 , Tested on branch 7b7a56d locally. LoanCancellationControllerTest — 15 tests, 0 failures Correct annotation — @notblank handles null + empty + whitespace for string fields. Consistent with PR #69. Note: MifosWorkflowApplicationTests.contextLoads failure is pre-existing (baseUrl == null for Fineract config) — unrelated to this PR. Approving. |
|
BLOCKED CLA NOT SIGNED |
|
CLA Block Removed |
|
FYI: see #74 for the new direction/architecture of this project |
fix: Fineract SDK dependencies
chore: Update security note
@NotNull on String fields only prevents null values but allows empty strings to pass validation silently. This caused blank loanType and cancellationReason values to bypass local validation and reach the workflow service with meaningless empty strings. - LoanCreateRequestDTO: @NotNull → @notblank on loanType field - LoanCancellationRequestDTO: @NotNull → @notblank on cancellationReason field - Added descriptive validation messages to both fields Part of the broader validation improvement across all workflow DTOs.
7b7a56d to
979d161
Compare
|
I think this is not relevant anymore. |
Thanks for the review and for closing this , understood. Since the project has moved to the new architecture, I'll re-check whether Appreciate the guidance ! |
Summary
Replace @NotNull with @notblank on String fields in LoanCreateRequestDTO
and LoanCancellationRequestDTO.
Problem
@NotNull on String fields only blocks null values — it allows empty
strings "" and whitespace " " to pass validation silently. This meant:
workflow service with a meaningless empty loan type
with no meaningful reason provided
This is the same issue fixed in PR #69 for ClientCreateRequestDTO.
Changes
Before / After
Before: POST /api/v1/workflow/loan-origination/start with empty loanType
→ Request passed validation and reached workflow service
After: POST /api/v1/workflow/loan-origination/start with empty loanType
→ 400 Bad Request
{
"title": "VALIDATION_FAILED",
"status": 400,
"fieldErrors": {
"loanType": "Loan type is required"
}
}
Same behaviour confirmed for cancellationReason in loan cancellation endpoint.
Test Results
LoanCancellationControllerTest — 15 tests, 0 failures
LoanOriginationControllerTest — 10 tests, 0 failures
All 25 tests pass with no failures.
Related
Continues validation improvements from PR #69 which fixed
ClientCreateRequestDTO and added spring-boot-starter-validation.