iya-sts
    Preparing search index...
    decide: (asked: AccessQuestion) => AccessAnswer = decide

    Type Declaration

      • (asked: AccessQuestion): AccessAnswer
      • Decides whether the subject may perform the action on the resource.

        Allows everything when xacml.enabled is off or when no policy loads (logged at error level), so a broken policy cannot lock operators out of the console. A Deny, Indeterminate or NotApplicable is refused and audited with its error code.

        Parameters

        • asked: AccessQuestion

          the resource, action, owner, subject and optional required roles

        Returns AccessAnswer

        whether it is allowed, the decision, the reason and the policy