# \[Bug\] @auth on interface does not respect or-rules

**URL:** <https://discuss.dgraph.io/t/bug-auth-on-interface-does-not-respect-or-rules/12371>\
**Category:** GraphQL\
**Tags:** status:accepted, kind:bug, ticket:created\
**Created:** [January 20, 2021, 11:03am UTC](https://discuss.dgraph.io/t/bug-auth-on-interface-does-not-respect-or-rules/12371 "2021-01-20T11:03:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![maaft](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@maaft](https://discuss.dgraph.io/u/maaft)\
**Post date:** [January 20, 2021, 11:03am UTC](https://discuss.dgraph.io/t/bug-auth-on-interface-does-not-respect-or-rules/12371/1 "2021-01-20T11:03:16Z")

</div>

**Steps to reproduce** :

Schema:

```auto
interface Ownable
  @auth(
    query: {
      or: [
        { rule: "{$ROLE: { eq: \"ADMIN\" }}" }
        {
          rule: "query($USERNAME: String!) { queryOwnable(filter: { username: {eq: $USERNAME }}) { username }}"
        }
      ]
    }
  ) {
  username: String! @search(by: [hash])
}

type Foo implements Ownable {
  value: Int!
}

# Dgraph.Authorization {"VerificationKey":"totallysecret","Header":"Auth","Namespace":"lol","Algo":"HS256"}

```

Admin-Token: `eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJsb2wiOnsiUk9MRSI6IkFETUlOIiwiVVNFUk5BTUUiOiJhZG1pbiJ9LCJpYXQiOjE1MTYyMzkwMjJ9.9KgpRXR-OhOBiw7Ay-VTqhitIjtHKW_Fj6cmjIO3dAo`

User-Token: `eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJsb2wiOnsiUk9MRSI6IlVTRVIiLCJVU0VSTkFNRSI6InVzZXIifSwiaWF0IjoxNTE2MjM5MDIyfQ._3dQECNABiKoE3lptCDaw5xCKMTxSeewak1Mzc2wUCE`

**1. Create Foo**

```auto
mutation {
  addFoo(input: {
    username: "user"
    value: 1
  }) {
    foo {
      value
    }
  }
}

```

**2. Set User-Token and queryOwnable**

```auto
query {
  queryOwnable {
    username
  }
}

```

→ you see the requested data

**3. Set Admin-Token and queryOwnable**

→ List is empty

**Expected behaviour**

I expect that the or-rule is used also on the interface for auth-checking and that the result is not empty when using the admin-token.

**When using queryFoo instead, results are as expected!**

**Current workaround**

When omitting USERNAME from the JWT, it’s working.

Admin-Token-Without-USERNAME:  
`eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJsb2wiOnsiUk9MRSI6IkFETUlOIn0sImlhdCI6MTUxNjIzOTAyMn0.DMVfg1723D85RoHfpN8YG2F4U_Gd-M7IjyrzdM0zjE4`

---

<div class="post-metadata">

**Author:** ![maaft](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@maaft](https://discuss.dgraph.io/u/maaft)\
**Post date:** [February 5, 2021, 8:47am UTC](https://discuss.dgraph.io/t/bug-auth-on-interface-does-not-respect-or-rules/12371/3 "2021-02-05T08:47:57Z")

</div>

Hi! Did you manage to reproduce this?

I have the same behavior using the delete-mutation.

---

<div class="post-metadata">

**Author:** ![minhaj](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/minhaj/32/3468_2.png) [@minhaj](https://discuss.dgraph.io/u/minhaj)\
**Post date:** [February 5, 2021, 10:05am UTC](https://discuss.dgraph.io/t/bug-auth-on-interface-does-not-respect-or-rules/12371/5 "2021-02-05T10:05:11Z")

</div>

Hey @maaft, Thanks for reporting the issue. I have reproduced it locally and will try to come up with the fix soon.

---

<div class="post-metadata">

**Author:** ![minhaj](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/minhaj/32/3468_2.png) [@minhaj](https://discuss.dgraph.io/u/minhaj)\
**Post date:** [February 8, 2021, 10:50am UTC](https://discuss.dgraph.io/t/bug-auth-on-interface-does-not-respect-or-rules/12371/9 "2021-02-08T10:50:30Z")

</div>

This bug is fixed in the master. See this [PR](https://github.com/dgraph-io/dgraph/pull/7401)

---

<div class="post-metadata">

**Author:** ![maaft](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@maaft](https://discuss.dgraph.io/u/maaft)\
**Post date:** [February 8, 2021, 10:50am UTC](https://discuss.dgraph.io/t/bug-auth-on-interface-does-not-respect-or-rules/12371/10 "2021-02-08T10:50:57Z")

</div>

Awesome - that was! Thank you !
