Skip to content

AZ102: An expression that doesn't parse ​

Permissions, rules and invariants are expressions: names joined by or, and and not, in parentheses where needed, relation.permission to follow a relation, and SQL conditions in { } on the row's own columns. The message says what was unexpected, or what is missing: a ), a closing }, or the rest of the expression. Where and and or meet, parentheses say which goes first: a or b and c reads two ways, so it is refused with the parentheses to add, a or (b and c).

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner : user = owner_id
  can view = owner or
line 5: expression ends too early [AZ102]

Fixed ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner : user = owner_id
  can view = owner or {is_public}