main
1[request_definition]
2r = subject, domain, action, object
3
4[policy_definition]
5p = subject, domain, action, object
6
7[policy_effect]
8e = some(where (p.eft == allow))
9
10[matchers]
11m =\
12 (\
13 (p.subject == "*" || r.subject == p.subject || regexMatch(r.subject, p.subject))\
14 && (p.domain == "*" || r.domain == p.domain)\
15 && (p.action == "*" || regexMatch(r.action, p.action))\
16 && keyMatch(r.object, p.object)\
17 )