KamoCRM

PatchLoanFile is no longer a status backdoor; unblocking a condition needs the underwrite right; clear cascades

FixSecurityService
Shipped
7 ஜூலை, 2026 அன்று 11:43 PM UTC
Author
Kamo
Commit
1e52573

**************** status changes are the pipeline state machine's job (POST /transitions enforces legal arrows + per-arrow role gate + open-blocking-condition gate). patchLoanFile now rejects EVERY status change except the borrower's own submit (DRAFT->APPLICATION_TAKEN by a non-operator party) — previously any LOS-write operator could PATCH loan-file {statusId:8} to FUND past unmet conditions, skipping underwriting. **************** pass whether the caller holds LOS_UNDERWRITE_LOAN to update() so a true->false downgrade of a blocking condition is underwriter-only (SecurityException -> 403). **************** cascade suppressConditionRequirements (NOT_APPLICABLE) like waive/delete, so a manually-cleared condition stops the borrower being asked for its now-moot documents.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing