Skip to content

AZ107: A name the policy can't use ​

Names can't contain __: generated names use it (view__base), and a policy can't refer to those. signed_in, anyone, nobody, or, and, not, if, where and grant are words of the language (so is everyone, which anyone replaced), and a permission can't be called like a command (select, insert, update, delete). Choose another name.

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner : user = owner_id
  can select = owner
line 5: 'select' is a command name; call the permission something else [AZ107]

Fixed ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner : user = owner_id
  can read = owner