OPA controls access to all endpoints and the list of authenticated resources and public URLs is defined in a single place in that file. The url_allow function in acl.rego is an overloaded function that replicates the OR condition in Rego. Either the user is authenticated and has permissions to access those resources, or the URL is public and accessible by any user. |
||
|---|---|---|
| .. | ||
| server | ||