SecurityService read-proxy for MLOS Documents (doc + doc-orchestration)

FeatureSecurityService
Shipped
July 3, 2026 at 1:57 AM UTC
Author
Kamo
Commit
179ecde

Two browser-facing read-proxy controller/client pairs fronting MLOSDocService (/api/docs) and MLOSDocOrchestrationService (/api/doc-orchestration) for the Documents steward screen. organizationId resolved from the OTK session, never from the browser. Tenant guards: org-injected passthrough for the loan requirements + borrower-actionable catalog + closing-package list; flat top-level-org fail-closed (404) for the by-id template extension + closing package; org post-filter for the loan MERS ledger. by-MIN ledger and the org-blind package branch are deliberately not exposed. Adds parseLong to MlosBaseController + mlos.doc/doc-orchestration URLs to the configmap.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing