Skip to content

AZ211: Custom roles from a relation that can't name their owner ​

roles : user from org says whose roles count on an object: only those of the object its org relation links it to, now (an assignment of another owner's role grants nothing, and authz.share refuses it). That relation must be the type's own, kept in a column or a table (not shared), and link to objects of one type: the type whose manage_roles people create the roles.

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
app role app_user
type user = app.users
type org = app.orgs
  admin : user = app.org_members(org_id -> user_id)
  can manage_roles = admin
type folder = app.folders
  owner : user = owner_id
  can view = owner or roles
  roles : user from owner_org
line 9: custom roles on folder come from 'owner_org', which must be a relation of folder kept in a column or a table and linking to one type, as `org : org = org_id` [AZ211]

Fixed ​

authz
app role app_user
type user = app.users
type org = app.orgs
  admin : user = app.org_members(org_id -> user_id)
  can manage_roles = admin
type folder = app.folders
  org   : org = org_id
  owner : user = owner_id
  can view = owner or roles
  roles : user from org