Skip to content

AZ112: this where there is no row ​

In a condition, this.column is the row the condition is about: the object, in a permission, a rule or an invariant; the type's row in its where; the link table's row in a link table's where; the share being made in shared if. Inside a subquery a bare column name can be another table's, so the row's columns are best written this.id. A caveat has no row: it is checked with each request, on any share it goes with, and reads the request (authz.ctx('ip')) and what the share was made with (arg('ip')). And this is no other name: call a table in a condition something else.

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner : user = owner_id
  viewer : user  shared
  can share = owner
  can view = owner or viewer
caveat own_ip = {this.ip = authz.ctx('ip')}
line 8: caveat own_ip: a caveat is checked with each request, on any share it goes with, so there is no row for `this`: it reads the request (authz.ctx('ip')) and what the share was made with (arg('ip')) [AZ112]

Fixed ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner : user = owner_id
  viewer : user  shared
  can share = owner
  can view = owner or viewer
caveat own_ip = {arg('ip') = authz.ctx('ip')}