← Prev in month ← Prev in thread
Next in thread → Next in month →

[security-services] Request All Attributes- was RE: Issues Statu s

From
Hal Lockhart <>
Date
2002-02-15T15:16:46+00:00
ID
Thread
[security-services] Request All Attributes- was RE: Issues Statu s
Title:  [security-services] Request All Attributes- was RE: Issues Status

> I don't like the fact that if there aren't any attributes in 

> the attribute

> query it means "get me all" of them. This ruins the montonicity of the

> function the service is providing. Which means special cases 

> have to be

> made when generating requests.

> 

> I've run into this problem in implemenations before, when 

> automatically

> generating requests for attributes by their types. Some 

> systems due to the

> access decision language and other dynamic information the 

> attribute types

> are automatically derived, which could be for no attribute 

> types. All of a

> sudden, it got a whole host of things it didn't want, which 

> complicated

> the process, not to mention slowed it down.

> 

> If the Query function is "get me the attributes that match 

> these types"

> and there aren't any types supplied, isn't the logical 

> consistent thing to

> do is maintain consitency and return no attributes?

Yes, there were other people uncomfortable with the "nothing means all" scheme way back, but it never reached the point of a specific proposal. As I recall the notion of a "*" or "ALL" key word was discussed. Personally I would prefer that.

However, at this late date, my main concern was that the spec does not currently provide ANY WAY AT ALL that is required to be interpreted as asking for all available attributes.

Hal
← Prev in month ← Prev in thread
Next in thread → Next in month →