auth/opa/ad/read.rego

12 lines
123 B
Plaintext

package AD.READ
default allow := false
allow {
input.owner == input.requester
}
allow {
input.role == "admin"
}