blob: 17156d65cc9f587132d7901f47d675c0cd634e29 [file] [log] [blame]
[request_definition]
r = sub, obj, act
[policy_definition]
p = sub, obj, act
[role_definition]
g = _, _
[policy_effect]
e = some(where (p.eft == allow))
[matchers]
m = (p.sub == "*" || g(r.sub, p.sub)) && keyMatch(r.obj, p.obj) && (p.act == "*" || r.act == p.act)