mirror of
https://github.com/SikongJueluo/pi-extensions.git
synced 2026-10-05 11:52:55 +08:00
docs: refine enforce mode and add judge participation term
- clarify enforce mode to approve only on allow verdicts - add judge participation glossary term
This commit is contained in:
+5
-1
@@ -17,9 +17,13 @@ An observation mode in which an Authorization Judge records a verdict without ch
|
|||||||
_Avoid_: Dry run
|
_Avoid_: Dry run
|
||||||
|
|
||||||
**Enforce Mode**:
|
**Enforce Mode**:
|
||||||
An authority mode in which selected Authorization Judge verdicts may directly determine whether an operation executes.
|
An authority mode in which an Authorization Judge's allow verdict may approve an operation. In the initial rollout, deny and defer still pass to the next authority.
|
||||||
_Avoid_: Production mode
|
_Avoid_: Production mode
|
||||||
|
|
||||||
|
**Judge Participation**:
|
||||||
|
The presence of an Authorization Judge in the configured authorizer chain. Participation determines whether the Judge is consulted, independently of whether it is in Shadow Mode or Enforce Mode.
|
||||||
|
_Avoid_: Enabled, installed
|
||||||
|
|
||||||
**Defer**:
|
**Defer**:
|
||||||
A verdict stating that the available information or the judge itself is insufficient to decide, leaving the decision to the next authority.
|
A verdict stating that the available information or the judge itself is insufficient to decide, leaving the decision to the next authority.
|
||||||
_Avoid_: Deny, error
|
_Avoid_: Deny, error
|
||||||
|
|||||||
Reference in New Issue
Block a user