AZ210: Custom roles written where they can't be
roles : user, team#member from org says who may hold the type's custom roles. A permission writes roles where a role that includes it gives it: can edit = editor or roles or (parent.edit and {inherit}), and the roles people create may include the permissions that write it. So roles goes in a permission of a type with a roles line: not under not (a role gives, it doesn't take away), not followed by a dot (it isn't a relation to objects), and not in a rule or an invariant, which don't say what a role gives (name the permission there). A roles line no permission uses is refused too.
Reported when the policy is compiled: rowfence check, the editor, rowfence dev.
The mistake
authz
app role app_user
type user = app.users
type org = app.orgs
admin : user = app.org_members(org_id -> user_id)
can manage_roles = admin
type folder = app.folders
editor : user = editor_id
roles : user
can edit = editor and not rolesline 9: folder.edit: `not roles` would take a permission away from whoever holds a custom role that includes it; a role only gives [AZ210]Fixed
authz
app role app_user
type user = app.users
type org = app.orgs
admin : user = app.org_members(org_id -> user_id)
can manage_roles = admin
type folder = app.folders
editor : user = editor_id
roles : user
can edit = editor or roles