Skip to content

AZ103: A relation written wrongly ​

A relation is name : subjects = source, or name : subjects shared [by permission] [if {condition}].

Subjects are a type (user), a group's relation (team#member), any signed-in user (user:*), anyone or link, separated by commas.

The source is a column of the type's table (owner_id), two columns for a subject of several types ((subject_type, subject_id)), or a link table: app.folder_editors(folder_id -> user_id), or app.grants(object: folder_id, subject: (kind, who)).

Custom roles are roles : subjects [from relation], and roles in each permission a role may give (can edit = editor or roles). They were once written roles : subjects grant perm1, perm2.

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner user = owner_id
  can view = owner
line 4: write relations as: name : subject = source   (or: name : subjects shared [by perm] [if {sql}]) [AZ103]

Fixed ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner : user = owner_id
  can view = owner