AZ307: A permission the runtime asks for, where it doesn't
Some permissions are asked for by name: share (who shares a type's shared relations, sees who has access and decides requests), break_glass (who may use authz.break_glass on an object), impersonate (on the user type: who may view the app as that user, authz.view_as), manage_keys (on a type that signs in: who makes and revokes its API keys) and manage_roles (on the type that owns custom roles: who creates them). Declared where nothing asks for them, they would never be used: impersonate on another type, manage_keys on a type that doesn't sign in, break_glass on a type with no relation shared with a user (which it would give), manage_roles on a type no roles line counts the roles of. And custom roles need someone who may create them: roles : user from org needs can manage_roles on the org's type.
Reported when the policy is compiled: rowfence check, the editor, rowfence dev.
The mistake
app role app_user
type user = app.users
type org = app.orgs
admin : user = app.org_members(org_id -> user_id)
can see = admin
type folder = app.folders
org : org = org_id
owner : user = owner_id
roles : user from org
can view = owner or rolesline 9: custom roles on folder are the roles of its org, which people with manage_roles on a org create, and org has no `can manage_roles` [AZ307]Fixed
app role app_user
type user = app.users
type org = app.orgs
admin : user = app.org_members(org_id -> user_id)
can see = admin
can manage_roles = admin
type folder = app.folders
org : org = org_id
owner : user = owner_id
roles : user from org
can view = owner or roles