Decides whether an issuance is permitted; the decider installed in
common/issuance_gate.js.
Synchronous throughout. With xacml.enabled off everything is allowed.
With no loadable policy an application that is not narrowed is allowed
and a narrowed one is refused. A question with preview set is a dry
run: nothing is audited or counted.
Parameters
asked: IssuanceQuestion
the issuance question
Returns IssuanceAnswer
the answer: allowed, decision, why, the roles held and
required, the policy name and, on a refusal, the status
Decides whether an issuance is permitted; the decider installed in
common/issuance_gate.js.Synchronous throughout. With
xacml.enabledoff everything is allowed. With no loadable policy an application that is not narrowed is allowed and a narrowed one is refused. A question withpreviewset is a dry run: nothing is audited or counted.