The AuthPolicy resource is managed by the developer persona. AuthPolicy is enforced by a single instance of the Authorino service, running in the kuadrant-system (that developers personas do not have access to). It was discovered that it is possible to edit the AuthPolicy and add a large number of callbacks (post-authorization actions) that causes a Denial of Service in Authorino.