Skip to content

AZ111: No app role ​

A policy names the app role, the Postgres role your app connects as, on a line of its own: app role app_user. The rules apply to it, it may call authz.act_as to say who is signing in, and it is the role tests run their statements as. It is one role: not PUBLIC, which would let every role in the database sign in as anyone.

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
type user = app.users
type folder = app.folders
  owner : user = owner_id
  can view = owner
line 1: name the app role, the Postgres role your app connects as, which the rules apply to: app role app_user [AZ111]

Fixed ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner : user = owner_id
  can view = owner