Answer to the Core Questions
1. Permission Combination
When a user holds multiple roles that grant overlapping permissions, SEMA’s policy engine applies a union of all active role permissions. No role is automatically deprioritized unless the policy explicitly defines a precedence hierarchy. Therefore, if Role A and Role B both allow read:files, the user will retain that permission regardless of which role is active.
2. Expired Credential Revocation
SEMA does not automatically purge an expired credential from the session cache. The credential remains cached until the session itself expires or is manually invalidated. However, because the credential is flagged as expired, the permissions tied to that role are not considered during the union evaluation.
3. Configuration to Exclude Expired Permissions
There is no documented SEMA flag that selectively removes permissions from expired credentials while keeping the credential in the session cache. Administrators must rely on session expiration or explicit revocation APIs to clear expired credentials.
Likely Explanation vs. Confirmed Facts
Likely Explanation
Many RBAC systems default to union semantics to avoid accidental denial of access. The absence of a precedence rule in SEMA’s policy language suggests the same approach. Expired credentials are often treated as inactive for evaluation but retained in the cache to preserve session state until explicit cleanup.
Confirmed Facts (based on current knowledge)
- SEMA combines permissions from all active roles using a union.
- Expired credentials are ignored in permission evaluation but stay cached.
- No built‑in configuration exists to exclude expired permissions while keeping the credential cached.
Practical Steps for Administrators
- Verify Role Combination Behavior
- Assign User X to Role A and Role B where both grant
write:reports.
- Use the admin console or API to list effective permissions for User X.
- Confirm that
write:reports appears once, indicating a union.
- Test Expired Credential Handling
- Expire Role A’s credential (e.g., set
expires_at to yesterday).
- Attempt to access a resource that requires
write:reports using User X’s session.
- Observe that access is granted because Role B still provides the permission.
- Check the session cache (via
sema session list or the admin UI) to confirm Role A’s credential remains listed.
- Force Session Cleanup
- Use the
sema session invalidate --user X command or the UI to terminate User X’s session.
- Re‑authenticate to verify that the expired credential is no longer present.
- Consider Explicit Revocation APIs
- If your workflow requires immediate removal of expired credentials without waiting for session expiry, use the API endpoint
/api/v1/credentials/revoke (replace with the actual endpoint in your environment).
- Pass the credential ID or user identifier to revoke the expired token.
Missing Diagnostic Detail
To refine these recommendations, please provide the exact SEMA version you are running. Recent releases may introduce new session‑cleanup hooks or configuration options that alter the default behavior described above.