Jesum Yip
08/18/2023, 1:03 PMJesum Yip
08/18/2023, 1:03 PMJesum Yip
08/18/2023, 1:07 PMJesum Yip
08/18/2023, 1:09 PMCharith (Cerbos)
Jesum Yip
08/18/2023, 1:33 PMrules:
- resource: "*"
actions:
- action: read
condition:
match:
all:
of:
- expr: R.kind == "123"
- expr: R.attr.data_org_id == "456"
effect: EFFECT_ALLOW
so putting something like the above means if you submit a request with a resource.kind = "xxxx", it would not match the principal policy above. it would only match if your resource.kind = "123".Jesum Yip
08/18/2023, 1:34 PMJesum Yip
08/18/2023, 1:37 PMexpr: R.kind != "123"
works.Andrew Haines (Cerbos)
EFFECT_DENY
and a condition like R.kind != "123"
.