Skip to content

AZ306: A deny that doesn't fit its inheritance ​

can view = (reader or parent.view) and not blocked: the deny must reach everything below, so blocked is a permission of the same type that inherits through the same relation (can blocked = blocker or parent.blocked), and the inheritance is joined with and only by the deny. blocked has no deny of its own: that could cut it below a blocked object.

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner   : user = owner_id
  parent  : folder = parent_id
  blocker : user = app.folder_blocks(folder_id -> user_id)
  can blocked = blocker
  can view = (owner or parent.view) and not blocked
line 8: folder.view: `not blocked` must cover everything below, so blocked must inherit through parent as view does, e.g. `can blocked = ... or parent.blocked` [AZ306]

Fixed ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner   : user = owner_id
  parent  : folder = parent_id
  blocker : user = app.folder_blocks(folder_id -> user_id)
  can blocked = blocker or parent.blocked
  can view = (owner or parent.view) and not blocked