Skip to content

AZ307: A permission the runtime asks for, where it doesn't ​

Some permissions are asked for by name: share (who shares a type's shared relations, sees who has access and decides requests), break_glass (who may use authz.break_glass on an object), impersonate (on the user type: who may view the app as that user, authz.view_as), manage_keys (on a type that signs in: who makes and revokes its API keys) and manage_roles (on the type that owns custom roles: who creates them). Declared where nothing asks for them, they would never be used: impersonate on another type, manage_keys on a type that doesn't sign in, break_glass on a type with no relation shared with a user (which it would give), manage_roles on a type no roles line counts the roles of. And custom roles need someone who may create them: roles : user from org needs can manage_roles on the org's type.

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
app role app_user
type user = app.users
type org = app.orgs
  admin : user = app.org_members(org_id -> user_id)
  can see = admin
type folder = app.folders
  org   : org = org_id
  owner : user = owner_id
  roles : user from org
  can view = owner or roles
line 9: custom roles on folder are the roles of its org, which people with manage_roles on a org create, and org has no `can manage_roles` [AZ307]

Fixed ​

authz
app role app_user
type user = app.users
type org = app.orgs
  admin : user = app.org_members(org_id -> user_id)
  can see = admin
  can manage_roles = admin
type folder = app.folders
  org   : org = org_id
  owner : user = owner_id
  roles : user from org
  can view = owner or roles