Skip to content

Resource Doc matching fix + lock down currency decimal places + lock down sandbox SIMPLE TR + treat currency codes as case insensitive (they will be UPPER case in DB) - #2935

Merged
simonredfern merged 9 commits into
OpenBankProject:developfrom
simonredfern:develop
Oct 7, 2026

Conversation

@simonredfern

Copy link
Copy Markdown
Member

No description provided.

Requests are upper-cased in ResourceDocMiddleware, lookups and
comparisons ignore case, and the upperCaseStoredCurrencyCodes migration
rewrites stored codes in upper case, logging each column it changed.
 transaction-request type and SCA method as a literal URL segment. The
 hand-kept literal list had fallen behind, so the v7 MOBILE_WALLET
 template claimed UTILITY, BULK and OPEN_CORRIDOR_PROMISE requests and
 gave HOLD, CARDANO and Ethereum on v7 an empty 404 instead of falling
 through to v6; v6 HOLD claimed CARDANO and Ethereum, the v4
 TRANSACTION_REQUEST_TYPE doc claimed every v4 type, and Berlin Group
 getPaymentInformation claimed the signing-basket status
 and authorisation requests. ResourceDocSelfResolveTest checks that
 every registered doc's own URL resolves to that doc, and
 TransactionRequestTypeRoutingTest checks the v7-to-v6 fall-through and
 that disabling one type leaves the others on.
allows with 400 (OBP-10068) instead of cutting it off when stored.
ResourceDocMiddleware checks amounts paired with a currency in the
request body and query string; crypto assets are not checked until their
real precision is recorded.
upperCaseStoredCurrencyCodes migration, so it also works on H2, which
stores names in upper case and is what CI runs on.
createTransactionRequestFreeForm, which now behaves as its ResourceDoc
says. Its odd answer came from the matcher treating FREE_FORM as a
placeholder, not from a design choice, and went away when FREE_FORM
became a literal segment.
request's challenge could credit wrong sandbox account, because the
payee was looked up again by routing as the payer wrote it and the empty
secondary-routing fallback matched anyone's counterparty. SIMPLE and
OPEN_CORRIDOR_PROMISE requests now record their counterparty id at
creation and the challenge pays that counterparty.
@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

@simonredfern
simonredfern merged commit 94b2dac into OpenBankProject:develop Oct 7, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant