Skip to content

AZ108: An included file that can't be read ​

include "roles.authz" names a file relative to the file that includes it. The command reads it from disk; code that compiles a policy passes it in the files map (name -> text). A file can be included only once, and never by itself. It is in the policy's folder or below it: named with /, without .. out of the folder, a drive or a / at the start (the review runs on a pull request's files, and must not read others).

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
app role app_user
type user = app.users
include "teams.authz"
type folder = app.folders
  owner : user = owner_id
  can view = owner
line 3: can't find teams.authz: pass it in the files argument, e.g. '{"teams.authz": "..."}' [AZ108]

Fixed ​

authz
app role app_user
type user = app.users
include "teams.authz"
type folder = app.folders
  owner : user = owner_id
  can view = owner

With teams.authz:

authz
type team = app.teams
  member : user = app.team_members(team_id -> user_id)
  can see = member