Joe Cantwell
04/15/2025, 1:21 PMif a user action request matches an ALLOW and a DENY, what is the resolution strategy?My initial thought was that its unlikely to happen but I guess if a user is added to multiple Roles and the resource policy grants access to one of those roles and explicitly denies access to a second role containing the user then it could be a thing. My assumption is that Cerbos is deny by default and the response will be
DENY
but I haven't tested this yet. Does anyone have any experience of a scenario like this?Emre (Cerbos)
Joe Cantwell
04/15/2025, 2:50 PM