Class EvaluateIfEntityFieldPredicatePrivacyPolicyRule<TFields, TIDField, TViewerContext, TEntity, N, TSelectedFields>
A single unit of which declarative privacy policies are composed, allowing for simple
expression and testing of authorization logic.
Remarks
Each rule is responsible for returning a ruling of ALLOW, DENY, or SKIP for a condition
that it is checking for. While rules can return any of these, it is most common for
rules to return ALLOW or SKIP, explicitly authorizing or deferring authorization to the next
rule in the privacy policy. If all rules in the policy SKIP, the policy is denied.
A rule may attach reason codes to a SKIP or DENY (see skipWithReasons and denyWithReasons).
When the policy is denied, the reasons from all skipped rules (or from the denying rule) are
passed to EntityPrivacyPolicy.getUserFacingDenialReason and attached to the thrown
EntityNotAuthorizedError.
Returning DENY from a rule is useful in a few notable cases:
Preventing a CRUD action on an entity (AlwaysDenyPrivacyPolicyRule)
Blocking. For example, a user blocks another user from seeing their posts, and the rule
would be named something like DenyIfViewerHasBeenBlockedPrivacyPolicyRule.
A single unit of which declarative privacy policies are composed, allowing for simple expression and testing of authorization logic.
Remarks
Each rule is responsible for returning a ruling of ALLOW, DENY, or SKIP for a condition that it is checking for. While rules can return any of these, it is most common for rules to return ALLOW or SKIP, explicitly authorizing or deferring authorization to the next rule in the privacy policy. If all rules in the policy SKIP, the policy is denied.
A rule may attach reason codes to a SKIP or DENY (see skipWithReasons and denyWithReasons). When the policy is denied, the reasons from all skipped rules (or from the denying rule) are passed to EntityPrivacyPolicy.getUserFacingDenialReason and attached to the thrown EntityNotAuthorizedError.
Returning DENY from a rule is useful in a few notable cases:
DenyIfViewerHasBeenBlockedPrivacyPolicyRule.