Skip to content

AZ302: A permission that depends on itself ​

A permission may use itself only through a relation between objects of one type, parent.view: that is inheritance, stored as a tree. Any other loop (a = b, b = a, or two permissions inheriting through each other) has no answer.

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner : user = owner_id
  can edit = owner or view
  can view = edit
line 6: folder.view depends on itself; a permission can only recurse as 'or rel.perm' (optionally 'and {condition}') through a relation to objects, and a group only as 'member : group#member' [AZ302]

Fixed ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner : user = owner_id
  can edit = owner
  can view = edit