{
  "ok": true,
  "tool": "api_access_check",
  "report": {
    "proven": false,
    "specError": null,
    "findings": [
      {
        "package": "Yichus/Examples/SupportAccess",
        "binding": "view_case",
        "resource": "support_cases",
        "operation": "db_read_opt",
        "kind": "GuardedRead",
        "status": "holds",
        "detail": "rows of \"support_cases\" are tainted from here; every use must sit under owns_case"
      },
      {
        "package": "Yichus/Examples/SupportAccess",
        "binding": "reply_to_case",
        "resource": "support_cases",
        "operation": "db_read_opt",
        "kind": "GuardedRead",
        "status": "holds",
        "detail": "rows of \"support_cases\" are tainted from here; every use must sit under owns_case"
      },
      {
        "package": "Yichus/Examples/SupportAccess",
        "binding": "reply_to_case",
        "resource": "support_cases",
        "operation": "db_write",
        "kind": "GuardProven",
        "status": "holds",
        "detail": "dominated by owns_case(Principal.user_id, row of support_cases), on the row it was applied to (key case_id)"
      },
      {
        "package": "Yichus/Examples/SupportAccess",
        "binding": "load_for_staff",
        "resource": "support_cases",
        "operation": "db_read_opt",
        "kind": "GuardedRead",
        "status": "holds",
        "detail": "rows of \"support_cases\" are tainted from here; every use must sit under owns_case"
      },
      {
        "package": "Yichus/Examples/SupportAccess",
        "binding": "load_for_staff",
        "resource": "support_cases",
        "operation": "use",
        "kind": "RowEscapesGuard",
        "status": "violated",
        "detail": "a value derived from a row of \"support_cases\" is passed to a call outside any branch on owns_case applied to Principal.user_id and the row"
      },
      {
        "package": "Yichus/Examples/SupportAccess",
        "binding": "load_for_staff",
        "resource": "support_cases",
        "operation": "use",
        "kind": "RowEscapesGuard",
        "status": "violated",
        "detail": "a value derived from a row of \"support_cases\" is passed to a call outside any branch on owns_case applied to Principal.user_id and the row"
      },
      {
        "package": "Yichus/Examples/SupportAccess",
        "binding": "load_for_staff",
        "resource": "support_cases",
        "operation": "use",
        "kind": "RowEscapesGuard",
        "status": "violated",
        "detail": "a value derived from a row of \"support_cases\" is returned outside any branch on owns_case applied to Principal.user_id and the row"
      },
      {
        "package": "Yichus/Examples/SupportAccess",
        "binding": "resolve_case",
        "resource": "support_cases",
        "operation": "db_read_opt",
        "kind": "RoleAuthorityProven",
        "status": "holds",
        "detail": "every route reaching this binding requires every role (support)"
      },
      {
        "package": "Yichus/Examples/SupportAccess",
        "binding": "resolve_case",
        "resource": "support_cases",
        "operation": "db_write",
        "kind": "RoleAuthorityProven",
        "status": "holds",
        "detail": "every route reaching this binding requires every role (support)"
      }
    ],
    "resources": [
      {
        "resource": "support_cases",
        "policy": "GuardedOrRoles(owns_case; requires support)",
        "status": "violated",
        "proven": false,
        "findings": [
          {
            "package": "Yichus/Examples/SupportAccess",
            "binding": "view_case",
            "resource": "support_cases",
            "operation": "db_read_opt",
            "kind": "GuardedRead",
            "status": "holds",
            "detail": "rows of \"support_cases\" are tainted from here; every use must sit under owns_case"
          },
          {
            "package": "Yichus/Examples/SupportAccess",
            "binding": "reply_to_case",
            "resource": "support_cases",
            "operation": "db_read_opt",
            "kind": "GuardedRead",
            "status": "holds",
            "detail": "rows of \"support_cases\" are tainted from here; every use must sit under owns_case"
          },
          {
            "package": "Yichus/Examples/SupportAccess",
            "binding": "reply_to_case",
            "resource": "support_cases",
            "operation": "db_write",
            "kind": "GuardProven",
            "status": "holds",
            "detail": "dominated by owns_case(Principal.user_id, row of support_cases), on the row it was applied to (key case_id)"
          },
          {
            "package": "Yichus/Examples/SupportAccess",
            "binding": "load_for_staff",
            "resource": "support_cases",
            "operation": "db_read_opt",
            "kind": "GuardedRead",
            "status": "holds",
            "detail": "rows of \"support_cases\" are tainted from here; every use must sit under owns_case"
          },
          {
            "package": "Yichus/Examples/SupportAccess",
            "binding": "load_for_staff",
            "resource": "support_cases",
            "operation": "use",
            "kind": "RowEscapesGuard",
            "status": "violated",
            "detail": "a value derived from a row of \"support_cases\" is passed to a call outside any branch on owns_case applied to Principal.user_id and the row"
          },
          {
            "package": "Yichus/Examples/SupportAccess",
            "binding": "load_for_staff",
            "resource": "support_cases",
            "operation": "use",
            "kind": "RowEscapesGuard",
            "status": "violated",
            "detail": "a value derived from a row of \"support_cases\" is passed to a call outside any branch on owns_case applied to Principal.user_id and the row"
          },
          {
            "package": "Yichus/Examples/SupportAccess",
            "binding": "load_for_staff",
            "resource": "support_cases",
            "operation": "use",
            "kind": "RowEscapesGuard",
            "status": "violated",
            "detail": "a value derived from a row of \"support_cases\" is returned outside any branch on owns_case applied to Principal.user_id and the row"
          },
          {
            "package": "Yichus/Examples/SupportAccess",
            "binding": "resolve_case",
            "resource": "support_cases",
            "operation": "db_read_opt",
            "kind": "RoleAuthorityProven",
            "status": "holds",
            "detail": "every route reaching this binding requires every role (support)"
          },
          {
            "package": "Yichus/Examples/SupportAccess",
            "binding": "resolve_case",
            "resource": "support_cases",
            "operation": "db_write",
            "kind": "RoleAuthorityProven",
            "status": "holds",
            "detail": "every route reaching this binding requires every role (support)"
          }
        ]
      }
    ]
  }
}
