Skip to content

AZ604: An inheritance condition reading a view ​

rowfence watches the tables an inheritance condition reads, so it can keep the tree up to date. A view can't be watched: read its tables directly.

Reported when the policy is applied (rowfence push, apply, a migration), against the database.

The mistake ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner  : user = owner_id
  parent : folder = parent_id
  can view = owner or (parent.view and {not exists (select 1 from app.locked_v l where l.folder_id = id)})

Fixed ​

authz
app role app_user
type user = app.users
type folder = app.folders
  owner  : user = owner_id
  parent : folder = parent_id
  can view = owner or (parent.view and {not exists (select 1 from app.locks l where l.folder_id = id)})