問題文
An administrator uploads a policy document that contains no path stanzas at all and attaches it to a token. The administrator expects the token to be usable for reading anything that is not explicitly forbidden. What will the token actually be able to do?
選択肢
- Read only the paths under the mount where the token was issued, because the auth mount's own path is implicitly granted to tokens it creates.
- Nothing, because policies grant no permission unless a path stanza allows it.
- Read every path, because a policy with no stanzas restricts nothing.
- Read and write anywhere below the system backend, because an empty policy is treated as an administrative policy and the system backend is where the administrative endpoints live.