Skip to content

fix: use authzed.v1/ prefix for FGAM permission names - #584

Open
ivanauth wants to merge 1 commit into
authzed:mainfrom
ivanauth:fix/fgam-grant-prefix
Open

fix: use authzed.v1/ prefix for FGAM permission names#584
ivanauth wants to merge 1 commit into
authzed:mainfrom
ivanauth:fix/fgam-grant-prefix

Conversation

@ivanauth

@ivanauth ivanauth commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

FGAM permission names are namespaced with authzed.v1/, but two places in the docs use an authzed.api/ prefix that does not exist:

  • restricted-api-access — the zed backup/zed restore section (7 names)
  • authzed/guides/postgres-fdw — the FDW role definitions (20 names)

The `zed backup`/`zed restore` section of restricted-api-access and the
role definitions in the Postgres FDW guide used an `authzed.api/` prefix
for FGAM permission names. That prefix does not exist: FGAM permissions
are namespaced with `authzed.v1/` (PermissionNamePrefix in the FGAM
schema), which is also what the role example further down the same
restricted-api-access page uses.

A reader following either section would grant permission names that match
nothing and get PermissionDenied with no indication of the cause.
@github-actions

Copy link
Copy Markdown
Contributor

Preview deployment skipped — @ivanauth does not have write access to this repository.

A maintainer can trigger a preview deployment by re-running this workflow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant