AZ112: this where there is no row
In a condition, this.column is the row the condition is about: the object, in a permission, a rule or an invariant; the type's row in its where; the link table's row in a link table's where; the share being made in shared if. Inside a subquery a bare column name can be another table's, so the row's columns are best written this.id. A caveat has no row: it is checked with each request, on any share it goes with, and reads the request (authz.ctx('ip')) and what the share was made with (arg('ip')). And this is no other name: call a table in a condition something else.
Reported when the policy is compiled: rowfence check, the editor, rowfence dev.
The mistake
authz
app role app_user
type user = app.users
type folder = app.folders
owner : user = owner_id
viewer : user shared
can share = owner
can view = owner or viewer
caveat own_ip = {this.ip = authz.ctx('ip')}line 8: caveat own_ip: a caveat is checked with each request, on any share it goes with, so there is no row for `this`: it reads the request (authz.ctx('ip')) and what the share was made with (arg('ip')) [AZ112]Fixed
authz
app role app_user
type user = app.users
type folder = app.folders
owner : user = owner_id
viewer : user shared
can share = owner
can view = owner or viewer
caveat own_ip = {arg('ip') = authz.ctx('ip')}