Replies: 1 comment
|
Hi Max, Short answer: yes, this is by design — KAS rewrap (the call that gates decryption) is hardcoded to authorize against the var decryptAction = &policy.Action{
Name: actions.ActionNameRead, // "read"
}That action is what gets passed to The intended pattern for custom actions is:
So KAS only answers "can this subject read these attributes?" — anything finer-grained (full vs. print-only, etc.) is the PEP's responsibility, after the rewrap has succeeded. If your use case really needs decryption itself to be gated by a custom action instead of |
Uh oh!
There was an error while loading. Please reload this page.
Hi
I created custom actions, "full-permission", "print". In both cases i want to decrypt the file and PEP will take care of the actions. But is see that without "read" action in subject-mapping, decryption does not happen. Any way to change that behavior ?
Regards
Max
All reactions