Skip to content

AZ204: anyone, link and type:* ​

anyone (signed in or not), link (whoever has the link) and user:* (anyone signed in) stand alone, without #relation, and are given only by sharing: they go in a shared relation. team:* needs team to sign in (type team = ... principal). No type may be called anyone or link. For something every row says for itself, use a condition: can view = owner or {is_public}.

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner  : user = owner_id
  public : anyone = is_public
  can view = owner or public
line 5: user:* (or another type:*), anyone and link can only be used with 'shared' [AZ204]

Fixed ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner  : user = owner_id
  viewer : user, anyone  shared
  can share = owner
  can view  = owner or viewer or {is_public}