Error codes
Every mistake rowfence reports ends with its code: line 4: folder.owner: unknown type 'person' [AZ201]. rowfence help AZ201 prints its page in the terminal.
Reading the policy
- AZ101: A line the language doesn't read
- AZ102: An expression that doesn't parse
- AZ103: A relation written wrongly
- AZ104: A permission written wrongly
- AZ105: A rule written wrongly
- AZ106: A test or an invariant written wrongly
- AZ107: A name the policy can't use
- AZ108: An included file that can't be read
- AZ109: Declared twice
- AZ110: A dollar-quote tag in a condition
- AZ111: No app role
- AZ112:
thiswhere there is no row
Types and relations
- AZ201: Unknown type
- AZ202: No user type
- AZ203: A relation or permission that isn't there
- AZ204: anyone, link and type:*
- AZ205: A source that can't hold these subjects
- AZ206: A key written wrongly, or of the wrong shape
- AZ207: Sharing needs a permission
- AZ208: A relation nothing uses
- AZ209: A group made only of itself
- AZ210: Custom roles written where they can't be
- AZ211: Custom roles from a relation that can't name their owner
Permissions and inheritance
- AZ301: Following a relation that can't be followed
- AZ302: A permission that depends on itself
- AZ303: Inheritance with no starting point
- AZ304: Inheritance limited by something other than a condition
- AZ305: A condition inheritance can't store
- AZ306: A deny that doesn't fit its inheritance
- AZ307: A permission the runtime asks for, where it doesn't
Rules, masks and scopes
- AZ401: Rules for a table no type maps to
- AZ402: Masks need a view
- AZ403: An update refinement without an update rule
- AZ404: A scope written wrongly
Tests
Applying and deploying
- AZ601: A table or column that isn't there
- AZ602: A key of another type
- AZ603: An inheritance condition that isn't the same for everyone at any time
- AZ604: An inheritance condition reading a view
- AZ605: Links used for inheritance can't expire
- AZ606: authz.uid() returns another type
- AZ607: A migration applied out of order
- AZ608: A tree swapped in that wasn't built
- AZ609: No policy is applied
- AZ610: Not a development database
- AZ611: Masked columns still readable
- AZ612: A schema on the search path others may create in
- AZ613: A condition that doesn't run
- AZ614: Something uses a function this policy no longer makes
- AZ615: A migration run outside a transaction
- AZ616: An older command, a newer database
- AZ617: Something is built on a masked view that can't be replaced in place
- AZ618: The owner may not switch to the app role
What apps see
- AZ701: Nobody signed in
- AZ702: Who is signed in was changed
- AZ703: Login refused
- AZ704: A read-only session
- AZ705: Not allowed
- AZ706: The policy doesn't allow this share
- AZ707: Not in the policy
- AZ708: No such thing
- AZ709: A write refused by a rule
- AZ710: A missing or wrong argument
- AZ711: The audit trail can't be changed
- AZ712: The change feed was trimmed
- AZ713: Moved inside itself
These pages are written from core/authzlib/errors.py; edit it, then python3 core/tests/unit_test.py --update.