Algorithm · Okta · Medium
A system grants or denies access to individual named properties through roles. Each role may carry an explicit "allow" or "deny" rule for a property, and a user can be assigned several roles at the same time. The effective result for a given user and property is decided by these rules: If any role assigned to the user has a "deny" rule for that property, the user is denied access. Deny always overrides allow. Otherwise, if at least one assigned role has an "allow" rule for…
Checking your access…