AZ604: An inheritance condition reading a view
rowfence watches the tables an inheritance condition reads, so it can keep the tree up to date. A view can't be watched: read its tables directly.
Reported when the policy is applied (rowfence push, apply, a migration), against the database.
The mistake
authz
app role app_user
type user = app.users
type folder = app.folders
owner : user = owner_id
parent : folder = parent_id
can view = owner or (parent.view and {not exists (select 1 from app.locked_v l where l.folder_id = id)})Fixed
authz
app role app_user
type user = app.users
type folder = app.folders
owner : user = owner_id
parent : folder = parent_id
can view = owner or (parent.view and {not exists (select 1 from app.locks l where l.folder_id = id)})