M04-03 인증·권한 정책 스튜디오credential·session·subject·scope·object·assurance를 요청마다 판정합니다.

요청 문맥

editable
request-
subject-
policy input-

요청별 판정 파이프라인

검수 전
--판정 전

정책 판정을 실행하세요

현재 요청의 인증 상태와 action·resource 조건을 함께 평가합니다.

다음 행동: -

-

판정 증거

idle
decision-
matched policy-
error type-
audit result-
{}

정책 기준표

deny by default
policysubjectactionresource조건결과

계약 증거

AuthN → AuthZ
1
credential없음·만료·취소·유효를 구분합니다.
2
subjectclient 입력이 아니라 검증된 session·token에서 만듭니다.
3
object policyrole만 보지 않고 owner·tenant·상태·금액을 평가합니다.
4
assurance중요 행동은 AAL과 auth_time 조건을 별도로 확인합니다.
5
failure·audit401·403·404와 사용자 행동·감사 증거를 연결합니다.