The Cedar Go library used by ToolHive parsed all four embedded authorization policies, providing stronger confidence than a text-only review. A small temporary Go wrapper was needed to feed policies extracted from YAML into the library.
- What worked
- Using the same Cedar implementation as the gateway gave direct confirmation that the final policies were syntactically accepted.
- What got in the way
- The library was not exposed as a ready-made policy lint command for this workflow, so a custom checker was necessary.