ditto icon indicating copy to clipboard operation
ditto copied to clipboard

Expired subjects work as non-expired, in case Ditto fails to delete it

Open vvasilevbosch opened this issue 3 months ago • 0 comments

In addition to #2233, it seems once Ditto gives up on deleting an expired subject, it remains inside the policy and gets treated like a normal, active subject, with the permissions granted. This is extremely rare condition, but still possible in theory, because the current enforcer implementation only checks if certain permission is granted, ignoring the expiration of subjects.

vvasilevbosch avatar Nov 06 '25 10:11 vvasilevbosch