AZ109: Declared twice
Each type, relation, permission, caveat, named test, view and custom roles line is declared once, and a table has one rule of each kind (one select, one update, ...) and masks each column once. A relation and a permission can't share a name. Join the two into one: can view = owner or editor.
Reported when the policy is compiled: rowfence check, the editor, rowfence dev.
The mistake
authz
app role app_user
type user = app.users
type folder = app.folders
owner : user = owner_id
editor : user = editor_id
can view = owner
can view = editorline 7: folder.view is defined twice [AZ109]Fixed
authz
app role app_user
type user = app.users
type folder = app.folders
owner : user = owner_id
editor : user = editor_id
can view = owner or editor