Skip to content

Error codes ​

Every mistake rowfence reports ends with its code: line 4: folder.owner: unknown type 'person' [AZ201]. rowfence help AZ201 prints its page in the terminal.

Reading the policy ​

  • AZ101: A line the language doesn't read
  • AZ102: An expression that doesn't parse
  • AZ103: A relation written wrongly
  • AZ104: A permission written wrongly
  • AZ105: A rule written wrongly
  • AZ106: A test or an invariant written wrongly
  • AZ107: A name the policy can't use
  • AZ108: An included file that can't be read
  • AZ109: Declared twice
  • AZ110: A dollar-quote tag in a condition
  • AZ111: No app role
  • AZ112: this where there is no row

Types and relations ​

  • AZ201: Unknown type
  • AZ202: No user type
  • AZ203: A relation or permission that isn't there
  • AZ204: anyone, link and type:*
  • AZ205: A source that can't hold these subjects
  • AZ206: A key written wrongly, or of the wrong shape
  • AZ207: Sharing needs a permission
  • AZ208: A relation nothing uses
  • AZ209: A group made only of itself
  • AZ210: Custom roles written where they can't be
  • AZ211: Custom roles from a relation that can't name their owner

Permissions and inheritance ​

  • AZ301: Following a relation that can't be followed
  • AZ302: A permission that depends on itself
  • AZ303: Inheritance with no starting point
  • AZ304: Inheritance limited by something other than a condition
  • AZ305: A condition inheritance can't store
  • AZ306: A deny that doesn't fit its inheritance
  • AZ307: A permission the runtime asks for, where it doesn't

Rules, masks and scopes ​

  • AZ401: Rules for a table no type maps to
  • AZ402: Masks need a view
  • AZ403: An update refinement without an update rule
  • AZ404: A scope written wrongly

Tests ​

  • AZ501: A $name used before it is given
  • AZ502: A test acting as a type that doesn't sign in

Applying and deploying ​

  • AZ601: A table or column that isn't there
  • AZ602: A key of another type
  • AZ603: An inheritance condition that isn't the same for everyone at any time
  • AZ604: An inheritance condition reading a view
  • AZ605: Links used for inheritance can't expire
  • AZ606: authz.uid() returns another type
  • AZ607: A migration applied out of order
  • AZ608: A tree swapped in that wasn't built
  • AZ609: No policy is applied
  • AZ610: Not a development database
  • AZ611: Masked columns still readable
  • AZ612: A schema on the search path others may create in
  • AZ613: A condition that doesn't run
  • AZ614: Something uses a function this policy no longer makes
  • AZ615: A migration run outside a transaction
  • AZ616: An older command, a newer database
  • AZ617: Something is built on a masked view that can't be replaced in place
  • AZ618: The owner may not switch to the app role

What apps see ​

  • AZ701: Nobody signed in
  • AZ702: Who is signed in was changed
  • AZ703: Login refused
  • AZ704: A read-only session
  • AZ705: Not allowed
  • AZ706: The policy doesn't allow this share
  • AZ707: Not in the policy
  • AZ708: No such thing
  • AZ709: A write refused by a rule
  • AZ710: A missing or wrong argument
  • AZ711: The audit trail can't be changed
  • AZ712: The change feed was trimmed
  • AZ713: Moved inside itself

These pages are written from core/authzlib/errors.py; edit it, then python3 core/tests/unit_test.py --update.