Skip to content

AZ210: Custom roles written where they can't be ​

roles : user, team#member from org says who may hold the type's custom roles. A permission writes roles where a role that includes it gives it: can edit = editor or roles or (parent.edit and {inherit}), and the roles people create may include the permissions that write it. So roles goes in a permission of a type with a roles line: not under not (a role gives, it doesn't take away), not followed by a dot (it isn't a relation to objects), and not in a rule or an invariant, which don't say what a role gives (name the permission there). A roles line no permission uses is refused too.

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
app role app_user
type user = app.users
type org = app.orgs
  admin : user = app.org_members(org_id -> user_id)
  can manage_roles = admin
type folder = app.folders
  editor : user = editor_id
  roles  : user
  can edit = editor and not roles
line 9: folder.edit: `not roles` would take a permission away from whoever holds a custom role that includes it; a role only gives [AZ210]

Fixed ​

authz
app role app_user
type user = app.users
type org = app.orgs
  admin : user = app.org_members(org_id -> user_id)
  can manage_roles = admin
type folder = app.folders
  editor : user = editor_id
  roles  : user
  can edit = editor or roles