- Shipped
- 3 Julai 2026, 01:57 UTC
- Author
- Kamo
- Commit
- 179ecde
Two browser-facing read-proxy controller/client pairs fronting MLOSDocService (/api/docs) and MLOSDocOrchestrationService (/api/doc-orchestration) for the Documents steward screen. organizationId resolved from the OTK session, never from the browser. Tenant guards: org-injected passthrough for the loan requirements + borrower-actionable catalog + closing-package list; flat top-level-org fail-closed (404) for the by-id template extension + closing package; org post-filter for the loan MERS ledger. by-MIN ledger and the org-blind package branch are deliberately not exposed. Adds parseLong to MlosBaseController + mlos.doc/doc-orchestration URLs to the configmap.