Skip to content

AZ709: A write refused by a rule ​

The table's rule for this insert or update doesn't hold for the signed-in principal on this row: SQLSTATE 42501, the constraint authz_insert or authz_update, and the DETAIL says why, one reason per line. The SDKs raise Refused (403, with the reason). An update or delete the rules hide changes 0 rows instead, without an error: authz.explain_rule(table, command, id) says why (the SDKs' expect).

Reported to the app, by the authz.* functions and the policy's rules: the code is in the error's HINT (rowfence help AZ709), and the SDKs' errors carry it as code.