When Rbac filter denies a request, it does not set a reponse flag.
From access logs, it is not possible to disambiguate a 403 emitted by the filter vs 403 emitted by the application.
- Set response flag(s) to indicate
a. denied by policy
b. Potentially indicate that the response was generated within the proxy. This can be more generic than just rbac.
- Indicate which rule or condition matched.
@yangminzhu @kyessenov