AbstractProtected ReadonlycreateList of rules to evaluate for create authorization.
Protected ReadonlydeleteList of rules to evaluate for delete authorization.
Protected ReadonlyreadList of rules to evaluate for read authorization.
Protected ReadonlyupdateList of rules to evaluate for update authorization.
Authorize an entity against creation policy.
viewer context of user creating the entity
query context in which to perform the create authorization
entity to authorize
entity if authorized
Authorize an entity against deletion policy.
viewer context of user deleting the entity
query context in which to perform the delete authorization
context about the reason for this privacy policy evaluation
entity to authorize
adapter for logging metrics about this authorization
entity if authorized
Authorize an entity against read policy.
viewer context of user reading the entity
query context in which to perform the read authorization
context about the reason for this privacy policy evaluation
entity to authorize
adapter for logging metrics about this authorization
entity if authorized
Authorize an entity against update policy.
viewer context of user updating the entity
query context in which to perform the update authorization
context about the reason for this privacy policy evaluation
entity to authorize
adapter for logging metrics about this authorization
entity if authorized
ProtectedgetGet the privacy policy evaluation mode and deny handler for this policy. Defaults to normal enforcing policy.
DRY_RUN mode is useful for testing and logging the effects of a policy without actually enforcing it, such as when first rolling out a new policy. Entities that fail the policy will be allowed so caution should be take when using.
ProtectedgetProduce an end-user-safe explanation for a denial of this policy. The result is attached to the
thrown EntityNotAuthorizedError as userFacingReason.
viewer context that was denied
the action that was denied
structured, developer-facing reason for the denial
The default returns null, meaning no user-facing explanation is available and callers should
display a generic message. Override to map denials to messages appropriate for end users.
When all rules skip, denialReason.skippedRules holds each skipped rule with the reason codes it
contributed, so the policy can select a message for a specific reason, for example "You must be a
member of this account to view this project." when a rule skipped with a NOT_ACCOUNT_MEMBER reason.
The denied entity and the evaluation context are intentionally not passed to this method. The viewer is not authorized to see the entity, and the evaluation context may contain it (as the previous value or the cascading deletion cause), so neither may influence or appear in the user-facing message. Rules should instead communicate what is needed through reason codes.
Privacy policy for an entity.
Remarks
A privacy policy declares lists of PrivacyPolicyRule for create, read, update, and delete actions for an entity and provides logic for authorizing an entity against rules.
Evaluation of a list of rules is performed according the following example. This allows constructing of complex yet testable permissioning logic for an entity.
Example