Establish a default-deny Ash policy baseline #12

Open
opened 2026-09-26 13:58:31 +00:00 by belvedere · 0 comments
Collaborator

Objective: New resources are closed by default, so a forgotten policy fails closed rather
than leaking another user's data.

Files:

  • Create: lib/first_thousand_words/policies.ex (shared policy helpers)
  • Modify: each domain (authorization do ... end)

Steps:

  1. For Study resources: by_default :deny; per-user state readable only when
    actor.id == resource.user_id.
  2. For Lexicon reference data: allow :read for any authenticated actor; deny writes to
    non-admins.
  3. Add a test that a second user cannot read or review the first user's cards.

Verify: the cross-user test fails loudly if a policy is removed. Do not ship Study
resources without this issue.

Refs: config/config.exs already sets Ash policy defaults — read those before writing policies.

**Objective:** New resources are closed by default, so a forgotten policy fails closed rather than leaking another user's data. **Files:** - Create: `lib/first_thousand_words/policies.ex` (shared policy helpers) - Modify: each domain (`authorization do ... end`) **Steps:** 1. For `Study` resources: `by_default :deny`; per-user state readable only when `actor.id == resource.user_id`. 2. For `Lexicon` reference data: allow `:read` for any authenticated actor; deny writes to non-admins. 3. Add a test that a second user cannot read or review the first user's cards. **Verify:** the cross-user test fails loudly if a policy is removed. **Do not** ship Study resources without this issue. **Refs:** `config/config.exs` already sets Ash policy defaults — read those before writing policies.
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
nickkeers/first-thousand-words#12
No description provided.