Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

traders_is_in_group_scope

The is Type in Group scope constraint: the principal slot both tests the entity type (is Drupe::OAuthUser) AND requires hierarchy membership (in Drupe::Team::"traders"). The policy permits GetStockInfo only for principals that are OAuthUsers belonging to the traders team.

This uses a bespoke schema (schema.cedarschema) that adds entity Team; and entity OAuthUser in [Team] = { id: String } tags String; so the membership target Drupe::Team::"traders" type-checks — the stock GetStockInfo schema has no Team type.

Referenced by guide/02-policy-language.md — The Policy Language.

Policy

// `is Type in Group` scope: principal must be an OAuthUser AND a member of
// the traders team.
@id("traders_only_scope")
permit (
    principal is Drupe::OAuthUser in Drupe::Team::"traders",
    action == Drupe::Action::"GetStockInfo",
    resource
);

Schema

namespace Drupe {
  type GetStockInfoInput = { stock: String };
  type GetStockInfoOutput = { info: String };
  type SystemContext = { now: datetime };

  entity Gateway;
  entity Team;
  entity OAuthUser in [Team] = { id: String } tags String;

  action "GetStockInfo" appliesTo {
    principal: [OAuthUser],
    resource: [Gateway],
    context: {
      input: GetStockInfoInput,
      output?: GetStockInfoOutput,
      system: SystemContext
    }
  };
}