Appends a block of checks to a biscuit, deriving a narrower token without calling the AS (RFC 9767 section 2.2).
The token is verified first; a block holding a policy (allow if) is refused by the library.
allow if
the biscuit to attenuate
the Datalog checks of the new block
{ publicKey } the biscuit verifies against
{ publicKey }
Optional
values for the block's parameters
{ ok: true, value, format }, or a refusal
{ ok: true, value, format }
Appends a block of checks to a biscuit, deriving a narrower token without calling the AS (RFC 9767 section 2.2).
The token is verified first; a block holding a policy (
allow if) is refused by the library.