blob: efe93e0f77dd19a7d439c4d1e2308cbab0b67842 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
|
[request_definition]
r = subject, domain, action, object
[policy_definition]
p = subject, domain, action, object
[policy_effect]
e = some(where (p.eft == allow))
[matchers]
m =\
(\
(p.subject == "*" || r.subject == p.subject || regexMatch(r.subject, p.subject))\
&& (p.domain == "*" || r.domain == p.domain)\
&& (p.action == "*" || regexMatch(r.action, p.action))\
&& keyMatch(r.object, p.object)\
)
|