The examples at https://jackrabbit.apache.org/oak/docs/security/authorization/restriction.html#Examples do not explicitly mention the root node. For the root node you must never use a rep:glob starting with /.
Also the following points should be clarified:
- rep:glob affects both (child)node as well as property access
- a link towards https://jackrabbit.apache.org/api/2.8/org/apache/jackrabbit/core/security/authorization/GlobPattern.html would be helpful
- make clearer how a rep:glob ending with / is different from one not ending with /
Also the description for
/cat/ and cat/ seem wrong because IMHO descendants are only considered if the glob uses a *.
This was originally triggered via https://issues.apache.org/jira/browse/OAK-7233.