1(self.webpackChunkopa_website=self.webpackChunkopa_website||[]).push([[4e3],{135:(e,n,t)=>{"use strict";t.r(n),t.d(n,{default:()=>s});const s='package play\n\ndefault is_sudo(_) := false\n\nis_sudo(user) if {\n\tuser.role == "admin"\n}\n\nis_sudo(user) if {\n\tuser.sudo == true\n}\n\nallow if is_sudo(input.user)\n'},2945:(e,n,t)=>{"use strict";t.r(n),t.d(n,{contentTitle:()=>o,default:()=>l,frontMatter:()=>i,toc:()=>a});var s=t(74848),r=t(28453);const i={},o=void 0,a=[];function c(e){const n={code:"code",em:"em",p:"p",...(0,r.R)(),...e.components};return(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.code,{children:"if"})," is ",(0,s.jsx)(n.em,{children:"everywhere"})," in Rego, but there are some cases where it is not used.\nIn this example, using ",(0,s.jsx)(n.code,{children:"if"})," for a rule name is a parse error."]})}function l(e={}){const{wrapper:n}={...(0,r.R)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(c,{...e})}):c(e)}},5028:e=>{"use strict";e.exports=JSON.parse('{"missing_paths":["request.method","role"],"validations":{"email":["email [email protected] must end with @example.com"],"request.method":["path must be set"],"role":["path must be set"]}}')},21274:(e,n,t)=>{"use strict";t.r(n),t.d(n,{assets:()=>c,contentTitle:()=>a,default:()=>u,frontMatter:()=>o,metadata:()=>s,toc:()=>l});const s=JSON.parse('{"id":"policy-reference/keywords/if","title":"Rego Keyword: if","description":"The if keyword is used when defining rules in Rego. if separates the","source":"@site/docs/policy-reference/keywords/if.md","sourceDirName":"policy-reference/keywords","slug":"/policy-reference/keywords/if","permalink":"/docs/policy-reference/keywords/if","draft":false,"unlisted":false,"tags":[],"version":"current","frontMatter":{"sidebar_label":"if","title":"Rego Keyword: if"},"sidebar":"docsSidebar","previous":{"title":"every","permalink":"/docs/policy-reference/keywords/every"},"next":{"title":"import","permalink":"/docs/policy-reference/keywords/import"}}');var r=t(74848),i=t(28453);const o={sidebar_label:"if",title:"Rego Keyword: if"},a=void 0,c={},l=[{value:"Examples",id:"examples",level:2},{value:"Further Reading",id:"further-reading",level:2}];function d(e){const n={a:"a",code:"code",h2:"h2",li:"li",p:"p",pre:"pre",ul:"ul",...(0,i.R)(),...e.components},{PlaygroundExample:s}=n;return s||function(e,n){throw new Error("Expected "+(n?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}("PlaygroundExample",!0),(0,r.jsxs)(r.Fragment,{children:[(0,r.jsxs)(n.p,{children:["The ",(0,r.jsx)(n.code,{children:"if"})," keyword is used when defining rules in Rego. ",(0,r.jsx)(n.code,{children:"if"})," separates the\nrule head from the rule body, making it clear which part of the rule\nis the condition (the part following the ",(0,r.jsx)(n.code,{children:"if"}),")."]}),"\n",(0,r.jsx)(n.p,{children:"The keyword is also use to make the policy rules written in Rego easier to\nread by being more 'English-like'. For example:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-rego",children:'rule := "some value" if some_condition\n'})}),"\n",(0,r.jsx)(n.h2,{id:"examples",children:"Examples"}),"\n",(0,r.jsx)(s,{dir:t(77441)}),"\n",(0,r.jsx)(s,{dir:t(55630)}),"\n",(0,r.jsx)(s,{dir:t(63806)}),"\n",(0,r.jsx)(s,{dir:t(26927)}),"\n",(0,r.jsx)(n.h2,{id:"further-reading",children:"Further Reading"}),"\n",(0,r.jsxs)(n.p,{children:["Below are some links that provide more information about the ",(0,r.jsx)(n.code,{children:"if"})," keyword:"]}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["If you are interested in learning about why ",(0,r.jsx)(n.code,{children:"if"})," was added to Rego, see the\nnotes in the\n",(0,r.jsx)(n.a,{href:"/docs/v0-upgrade",children:"OPA v1.0"}),"\ndocumentation."]}),"\n",(0,r.jsxs)(n.li,{children:["Read the release notes from when the ",(0,r.jsx)(n.code,{children:"if"})," keyword was added to Rego in\n",(0,r.jsx)(n.a,{href:"https://github.com/open-policy-agent/opa/releases/tag/v0.42.0",children:"OPA v0.42.0"}),"."]}),"\n",(0,r.jsxs)(n.li,{children:["Using ",(0,r.jsx)(n.code,{children:"if"})," is also\n",(0,r.jsx)(n.a,{href:"/projects/regal/rules/idiomatic/use-if",children:"recommended by Regal"}),"."]}),"\n"]})]})}function u(e={}){const{wrapper:n}={...(0,i.R)(),...e.components};return n?(0,r.jsx)(n,{...e,children:(0,r.jsx)(d,{...e})}):d(e)}},26927:(e,n,t)=>{var s={"./config":28430,"./config.json":28430,"./data":65100,"./data.json":65100,"./input":59952,"./input.json":59952,"./intro.md":2945,"./policy.rego":89561,"./title.txt":43536};function r(e){var n=i(e);return t(n)}function i(e){if(!t.o(s,e)){var n=new Error("Cannot find module '"+e+"'");throw n.code="MODULE_NOT_FOUND",n}return s[e]}r.keys=function(){return Object.keys(s)},r.resolve=i,e.exports=r,r.id=26927},27074:(e,n,t)=>{"use strict";t.r(n),t.d(n,{contentTitle:()=>o,default:()=>l,frontMatter:()=>i,toc:()=>a});var s=t(74848),r=t(28453);const i={},o=void 0,a=[];function c(e){const n={code:"code",p:"p",...(0,r.R)(),...e.components};return(0,s.jsxs)(n.p,{children:["The ",(0,s.jsx)(n.code,{children:"if"})," keyword is used for all rules though, including rules that create\nobjects and sets."]})}function l(e={}){const{wrapper:n}={...(0,r.R)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(c,{...e})}):c(e)}},28430:e=>{"use strict";e.exports=JSON.parse('{"showInput":false,"showOutput":false,"titleSize":4,"skip_output_reason":"example of invalid syntax"}')},28453:(e,n,t)=>{"use strict";t.d(n,{R:()=>o,x:()=>a});var s=t(96540);const r={},i=s.createContext(r);function o(e){const n=s.useContext(i);return s.useMemo((function(){return"function"==typeof e?e(n):{...n,...e}}),[n,e])}function a(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:o(e.components),s.createElement(i.Provider,{value:n},e.children)}},29747:e=>{"use strict";e.exports={allow:!0}},30618:e=>{"use strict";e.exports=JSON.parse('{"role":"admin","path":["payments","approve"]}')}
1,36425:(e,n,t)=>{"use strict";t.r(n),t.d(n,{default:()=>s});const s="Defining functions\n"},37723:e=>{"use strict";e.exports=JSON.parse('{"roles":["admin"],"email":"[email protected]","request":{"headers":{},"path":"/v1/payments"}}')},41292:e=>{"use strict";e.exports=JSON.parse('{"showInput":true,"showData":true,"titleSize":4}')},43536:(e,n,t)=>{"use strict";t.r(n),t.d(n,{default:()=>s});const s="When if is not used\n"},51297:e=>{"use strict";e.exports=JSON.parse('{"required_paths":["request.method","request.path","request.headers","role","email"]}')},54532:e=>{"use strict";e.exports={allow:!0}},55630:(e,n,t)=>{var s={"./config":41292,"./config.json":41292,"./data":51297,"./data.json":51297,"./input":37723,"./input.json":37723,"./intro.md":27074,"./output":5028,"./output.json":5028,"./policy.rego":72676,"./title.txt":97817};function r(e){var n=i(e);return t(n)}function i(e){if(!t.o(s,e)){var n=new Error("Cannot find module '"+e+"'");throw n.code="MODULE_NOT_FOUND",n}return s[e]}r.keys=function(){return Object.keys(s)},r.resolve=i,e.exports=r,r.id=55630},56415:e=>{"use strict";e.exports=JSON.parse('{"showInput":true,"titleSize":4}')},56571:e=>{"use strict";e.exports=JSON.parse('{"user":{"sudo":true}}')},59782:(e,n,t)=>{"use strict";t.r(n),t.d(n,{contentTitle:()=>o,default:()=>l,frontMatter:()=>i,toc:()=>a});var s=t(74848),r=t(28453);const i={},o=void 0,a=[];function c(e){const n={code:"code",p:"p",...(0,r.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.code,{children:"if"})," is also used in functions. Much like rules, in Rego functions can have one\nor more heads. The head and body of a function are also separated by the ",(0,s.jsx)(n.code,{children:"if"}),"\nkeyword for consistency and readability."]}),"\n",(0,s.jsxs)(n.p,{children:["In this example, the ",(0,s.jsx)(n.code,{children:"is_sudo"})," function is incrementally defined\nwhere each head adds new cases to the functionality. In this case, each head\ndefines scenarios where the user is a 'sudoer' - both when the user is an admin\nor when the user has the sudo field set."]})]})}function l(e={}){const{wrapper:n}={...(0,r.R)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(c,{...e})}):c(e)}},59952:e=>{"use strict";e.exports={}},60042:(e,n,t)=>{"use strict";t.r(n),t.d(n,{default:()=>s});const s="Defining simple rules\n"},61847:(e,n,t)=>{"use strict";t.r(n),t.d(n,{default:()=>s});const s='package play\n\ndefault allow := false\n\nallow if input.role == "admin"\n\nallow if {\n\tinput.path[0] == "users"\n\tinput.path[1] == input.user_id\n}\n'},63806:(e,n,t)=>{var s={"./config":56415,"./config.json":56415,"./data":77601,"./data.json":77601,"./input":56571,"./input.json":56571,"./intro.md":59782,"./output":54532,"./output.json":54532,"./policy.rego":135,"./title.txt":36425};function r(e){var n=i(e);return t(n)}function i(e){if(!t.o(s,e)){var n=new Error("Cannot find module '"+e+"'");throw n.code="MODULE_NOT_FOUND",n}return s[e]}r.keys=function(){return Object.keys(s)},r.resolve=i,e.exports=r,r.id=63806},65100:e=>{"use strict";e.exports={}},72676:(e,n,t)=>{"use strict";t.r(n),t.d(n,{default:()=>s});const s='package play\n\n# missing_paths creates a set missing input paths\nmissing_paths contains path if {\n\tsome path in data.required_paths\n\n\tparts := split(path, ".")\n\n\tobject.get(input, parts, "") == ""\n}\n\n# validations is a mapping of input paths to error messages\nvalidations[path] contains "path must be set" if {\n\tsome path, _ in missing_paths\n}\n\n# role and email have additional validation rules\nvalidations.role contains "role cannot be blank" if {\n\tinput.role == ""\n}\n\nvalidations.email contains message if {\n\tnot endswith(input.email, "@example.com")\n\n\tmessage := sprintf("email %s must end with @example.com", [input.email])\n}\n'},77441:(e,n,t)=>{var s={"./config":94972,"./config.json":94972,"./input":30618,"./input.json":30618,"./intro.md":80447,"./output":29747,"./output.json":29747,"./policy.rego":61847,"./title.txt":60042};function r(e){var n=i(e);return t(n)}function i(e){if(!t.o(s,e)){var n=new Error("Cannot find module '"+e+"'");throw n.code="MODULE_NOT_FOUND",n}return s[e]}r.keys=function(){return Object.keys(s)},r.resolve=i,e.exports=r,r.id=77441},77601:e=>{"use strict";e.exports={}},80447:(e,n,t)=>{"use strict";t.r(n),t.d(n,{contentTitle:()=>o,default:()=>l,frontMatter:()=>i,toc:()=>a});var s=t(74848),r=t(28453);const i={},o=void 0,a=[];function c(e){const n={code:"code",li:"li",p:"p",ul:"ul",...(0,r.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsxs)(n.p,{children:["Most commonly, ",(0,s.jsx)(n.code,{children:"if"})," is used to create boolean rules where if any rule head is\ntrue, then the whole rule is true. In this simple example, when both:"]}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsxs)(n.li,{children:["the ",(0,s.jsx)(n.code,{children:"input.role"})," field is present,"]}),"\n",(0,s.jsx)(n.li,{children:'and set to the value of "admin"'}),"\n"]}),"\n",(0,s.jsxs)(n.p,{children:["Then, the ",(0,s.jsx)(n.code,{children:"allow"})," rule will be ",(0,s.jsx)(n.code,{children:"true"}),". If either of these conditions is not met,\nthe rule will be ",(0,s.jsx)(n.code,{children:"false"}),"."]})]})}function l(e={}){const{wrapper:n}={...(0,r.R)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(c,{...e})}):c(e)}},89561:(e,n,t)=>{"use strict";t.r(n),t.d(n,{default:()=>s});const s="package play\n\ndefault allow := false # not in default cases\n\nmy_constant := 42 # not for constants\n\n# not for rule names\nif {\n\tinput.admin\n}\n\nallow if {\n\t# not inside rules\n\tinput.admin if input.roles.admin == true\n}\n\n"},94972:e=>{"use strict";e.exports=JSON.parse('{"showInput":true,"titleSize":4}')},97817:(e,n,t)=>{"use strict";t.r(n),t.d(n,{default:()=>s});const s="Defining multi-value rules\n"}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.