Skip to content

AZ304: Inheritance limited by something other than a condition ​

Inheritance is stored as a tree, so what may stop it is a condition on the object's own columns: (parent.view and {inherit}). A relation or permission can't narrow it; write it beside: can view = (owner or parent.view) ... with a deny (and not blocked) if someone must lose it.

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner  : user = owner_id
  editor : user = editor_id
  parent : folder = parent_id
  can view = owner or (parent.view and editor)
line 7: inheritance through parent can only be narrowed with {conditions} on the row, e.g. (parent.view and {inherit}) [AZ304]

Fixed ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner  : user = owner_id
  editor : user = editor_id
  parent : folder = parent_id
  can view = owner or editor or (parent.view and {inherit})