1 { cert, group, groups, user }: {
2 assertion = cert.group == group || builtins.any (u: u == user) groups.${cert.group}.members;
3 message = "Group for certificate ${cert.domain} must be ${group}, or user ${user} must be a member of group ${cert.group}";