Skip to content

Conversation

@ZohebShaikh
Copy link
Collaborator

@ZohebShaikh ZohebShaikh commented Nov 19, 2025

  1. Add enpoints to get all the sessions a subject is allowed to access.
  2. The scopes that a subject can have depending on the audience claims
  3. Add allow if all the tags are valid(visible) sessions for the subject

@ZohebShaikh ZohebShaikh changed the title Add policy to get sessions for a given subject feat: Add policy to get sessions for a given subject Nov 19, 2025
Copy link
Collaborator

@tpoliaw tpoliaw left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks like it's very specific to tiled. Should we be using a separate application policy that imports the central version?

@ZohebShaikh
Copy link
Collaborator Author

ZohebShaikh commented Nov 24, 2025

Are you suggesting to move the policy to authz/policy/tiled from authz/policy/diamond/policy ?
Did you find any issue in the actual policy other than this ?

@tpoliaw
Copy link
Collaborator

tpoliaw commented Nov 24, 2025

I meant more having a separate bundle, something like this. For the policy itself, it looks ok but I might need a walk through to explain what it's doing - rego is baffling.

@ZohebShaikh
Copy link
Collaborator Author

Closing in favour of this #293

@ZohebShaikh ZohebShaikh closed this Dec 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants