Skip to content

AZ404: A scope written wrongly ​

A scope limits what a token may do: scope files = app.files.select, app.files.update, file.view. Items are a command (select), a command on a table (app.files.update), or a permission of a type (file.edit); a bare word must be a command, or a permission some type has.

Reported when the policy is compiled: rowfence check, the editor, rowfence dev.

The mistake ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner : user = owner_id
  can view = owner
scope read = folder.see
line 6: scope read: folder has no permission 'see' [AZ404]

Fixed ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner : user = owner_id
  can view = owner
scope read = folder.view