AbacQueryOptions

data class AbacQueryOptions(val requirePrincipalTags: Boolean = false, val matchMissingTagKey: Boolean = true)

The optional tightenings of AbacQueryPolicy. The defaults keep its permissive semantics.

Constructors

Link copied to clipboard
constructor(requirePrincipalTags: Boolean = false, matchMissingTagKey: Boolean = true)

Types

Link copied to clipboard
object Companion

Properties

Link copied to clipboard

lets a resource that lacks one of the principal's tag keys (or has it empty) match, as a public resource. Off, a resource matches only when it carries every non-wildcard key with a value the principal holds.

Link copied to clipboard

rejects an HTTP snapshot query whose principal has no ABAC tags, instead of letting it match every resource. In-process queries are trusted and never rejected for this.