AZ304: Inheritance limited by something other than a condition
Inheritance is stored as a tree, so what may stop it is a condition on the object's own columns: (parent.view and {inherit}). A relation or permission can't narrow it; write it beside: can view = (owner or parent.view) ... with a deny (and not blocked) if someone must lose it.
Reported when the policy is compiled: rowfence check, the editor, rowfence dev.
The mistake
authz
app role app_user
type user = app.users
type folder = app.folders
owner : user = owner_id
editor : user = editor_id
parent : folder = parent_id
can view = owner or (parent.view and editor)line 7: inheritance through parent can only be narrowed with {conditions} on the row, e.g. (parent.view and {inherit}) [AZ304]Fixed
authz
app role app_user
type user = app.users
type folder = app.folders
owner : user = owner_id
editor : user = editor_id
parent : folder = parent_id
can view = owner or editor or (parent.view and {inherit})