SecurityService relay to TimecardService

FeatureSecurityService
Ya
12 Agosti 2026, 00:33 UTC
Mwandishi
Kamo
Ahadi ya
e8f8a2e

The authorization boundary. TimecardService holds the data and the engine but no session; this holds the session and decides who may do what, then relays. The engine can therefore never be reached without passing through here. SecurityService runs anyRequest().permitAll() with hand-rolled per-handler auth, so every method opens with a guard that returns non-null to refuse. Self-service endpoints take NO member id at all -- the member comes from the session, making them structurally incapable of acting on someone else. HR endpoints gate on MANAGE_TIMECARDS (183). Enrollment is answered from the persisted employment row rather than a right, so a god-mode operator does not appear enrolled in every org they look at. SUDO_MEMBER_ID is carried through: isSelf() upstream treats an impersonated session as the target member, so without it an impersonator's punch would be recorded as the employee's own. timecard.service.url is set EXPLICITLY in the configmap. commission.service.url is set nowhere and production depends on a literal in Java, which a Service rename would break at runtime with nothing in config to grep for.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei