Establish a default-deny Ash policy baseline #12
Labels
No labels
area
auth
area
data
area
domain
area
infra
area
stats
area
study
area
tooling
area
ui
duplicate
future
kind
bug
kind
chore
kind
decision
kind
docs
kind
feature
kind
spike
kind
test
prio
blocker
risk
high
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
nickkeers/first-thousand-words#12
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Objective: New resources are closed by default, so a forgotten policy fails closed rather
than leaking another user's data.
Files:
lib/first_thousand_words/policies.ex(shared policy helpers)authorization do ... end)Steps:
Studyresources:by_default :deny; per-user state readable only whenactor.id == resource.user_id.Lexiconreference data: allow:readfor any authenticated actor; deny writes tonon-admins.
Verify: the cross-user test fails loudly if a policy is removed. Do not ship Study
resources without this issue.
Refs:
config/config.exsalready sets Ash policy defaults — read those before writing policies.