RE: XACML TC Charter Revision - Strawman
> maybe i am just being overly cautious., but my concern comes from the > detail of the response. since security is composed of authentication, > authorization and [encryption], i would prefer that failure of > authorization be limited to a predefined list of failure > types to limit > the exposure of one security aspect from antother. 'free > form' specifics > may allow an intruder to determine which 'product' is being used to > perform the authorization (kinda like how nmap generates os profiles > based up network responses), and therby be able to apply a > known exploit > selectively. there can be 500 hundred responses if need be for all i > care just as long as they are predefined. In the case of SAML, the recipient of a AuthZ Decision Assertion is supposed to be a PEP who is enforcing access to some resources, not the end user who is trying to access them. Presumably, the PEP has previously authenticated itself to the satisfaction of the PDP. As I implied in my previous message, if you are worried about leakage, you can use confidentiality (encryption). This could even work if the assertion is passed via the user, assuming the PEP knows the key and the user does not. In the positive side, we do have requirements in SAML to be able to save Assertions for non-repudiation purposes. In SAML v1 the Assertion will tell you if the actions is allowed, but except for the object, the things in the assertion and the inputs to the policy decision may not be the same. I was hoping we could eventually fix this. Hal
×
New Best Answer
This thread already has a best answer. Would you like to mark this message as the new best answer?
No
$(document).ready(function () {
$("div.messageContentColumn").find("img.media-object").on('click', function () {
if ($(this)[0].parentElement.tagName !== "A") {
var $messageContentColumn = $(this);
var source = "";
if ($messageContentColumn.data("modalsrc") !== undefined) {
source = $messageContentColumn.data("modalsrc")
} else {
source = $messageContentColumn.attr("src").replace("-T.jpg", ".jpg");
source = source.replace("-M.jpg", ".jpg");
source = source.replace("-L.jpg", ".jpg");
}
var title = $messageContentColumn.data('title') !== undefined
? $messageContentColumn.data("title")
: $messageContentColumn.attr("title") !== undefined
? $messageContentColumn.attr("title")
: "";
var $discussionImgModal = $("#discussion-img-modal");
var modalHtml = '
×' +
'
';
if ($discussionImgModal.length == 0) {
$("form").append(modalHtml);
$discussionImgModal = $("#discussion-img-modal");
$discussionImgModal.find(".close").on('click', function () {
$discussionImgModal.modal("hide");
});
}
loadImage($discussionImgModal, source, title);
}
});
function loadImage($discussionImgModal, source, title) {
var discussionImg = $discussionImgModal.find("#modalImg")[0];
discussionImg.onload = function () {
$discussionImgModal.modal("show");
};
discussionImg.src = source;
$discussionImgModal.find("#caption").html(title);
}
var replyInlineParam = HigherLogic.Util.getParameterByName('ReplyInline');
if (!HigherLogic.Util.stringIsNullOrWhiteSpace(replyInlineParam)) {
var $replyInline = $('.reply-inline[data-message-key="' + replyInlineParam + '"]');
if ($replyInline.length > 0) {
openEditor($replyInline);
}
}
$('.reply-inline').on('click',
function () {
hl_common_ui_blockUI();
var $this = $(this);
if ($('.inline-reply-snippet').length > 0) {
hl_common_ui_unBlockUI();
$('.inline-reply-snippet').find('.modal.inline-confirm').modal('show');
$('.inline-reply-snippet').find('.modal.inline-confirm').data('reply-id', $this.prop('id'));
} else {
openEditor($this);
}
});
function openEditor($this) {
$('.inline-reply-snippet').remove();
var postData = { MessageKey: $this.data('message-key'), currentUrl: window.location.href };
HigherLogic.Util.post(
'/higherlogic/ui/mvc/eGroups/eGroups/GetReplyInline',
JSON.stringify(postData),
'html'
).done(function (data) {
var redirectUrl = $(data).data('redirect-url');
if (redirectUrl) {
// gives return location for unauthenticated user redirect to login
redirectUrl = hl_common_util_updateQueryStringParameter(redirectUrl,
'ReturnUrl',
encodeURIComponent(window.location.href));
// gives return location for unsubscribed user redirect to subscribe
window.location.href = hl_common_util_updateQueryStringParameter(redirectUrl,
'PostByLink',
encodeURIComponent(window.location.href));
return;
}
$this.closest('li').append(data);
var $div = $('#' + $(data).first('div').prop('id'));
var bottomOfDiv = $div.offset().top + 500;
$('html, body').animate({
scrollTop: bottomOfDiv - $(window).height()
},
1000);
hl_common_ui_unBlockUI();
});
}
});
.related-results.block {
display: flex;
flex-wrap: wrap;
flex-direction: row;
}
.related-results.block .related-result-row {
flex: 1;
border: 1px solid #cccccc;
margin: 10px;
min-width: 200px;
max-width: 200px;
}
.related-results.block .related-result-row .meta-content-date.block {
float: left;
margin: 0px;
}
.related-results.block .related-result-row .hl-type.block {
margin-top: 5px;
margin-right: 0px;
padding-left: 0px;
margin-bottom: 10px;
text-align: center;
clear: both;
}
.related-results .related-result-row h4 {
margin-bottom: 10px;
}
.related-results .related-result-row .meta-content-date {
color: #666666;
font-size: 12px;
margin: 0px 20px 3px;
display: block;
float: right;
}
.related-results .related-result-row .meta-block {
border-left: 1px solid #ebebeb;
padding-left: 15px;
margin-top: 20px;
font-size: 12px;
}
.related-results .related-result-row .meta-block a {
color: #666;
}
.related-results .related-result-row .meta-content {
margin: 3px 0;
}
.related-results .related-result-row .img-circle {
border-radius: 50%;
width: 20px;
}
.related-results .related-result-row .owner-image {
width: 20px;
float: left;
}
.related-results .related-result-row .owner-name {
color: #666666;
font-size: 12px;
display: block;
float: left;
margin: 2px 5px;
}
.related-results .related-result-row .content-type {
padding-bottom: 5px;
padding-top: 5px;
color: #006621;
font-size: 12px;
font-weight: bold;
}
.related-results .related-result-row .content-tags {
margin-bottom: 5px;
margin-top: 10px;
}
.related-results .related-result-row .content-tags a {
margin-bottom: 10px;
}
.related-results .related-result-row .content-tags a {
display: inline-block;
}
.related-results .related-result-row .match-block {
color: #808080;
}
.related-results .related-result-row .result-indent {
padding-left: 15px;
}
.related-results .related-result-row p.result-indent-event {
padding-left: 15px;
margin-top: 0;
margin-bottom: 0;
color: #333333;
}
.related-results .related-result-row .label-search-tag {
background-color: #fff;
border: 1px solid #ccc;
text-decoration: none;
margin-bottom: 4px;
color: #333;
font-weight: normal;
}
.related-results .related-result-row .label-search-tag:hover {
background-color: #ebebeb;
border: 1px solid #ccc;
margin-bottom: 4px;
color: #333;
font-weight: normal;
text-decoration: none;
}
.related-results .related-results.search-divider hr {
width: 100%;
margin-top: 5px;
margin-bottom: 10px;
border: 1px solid #eeeeee;
}
.related-results .row.search-divider {
margin-left: 0;
margin-right: 0;
}
.related-results .related-result-row .hl-type .label, .hl-type-alt-2.label {
background-color: #f2f2f2;
border: 1px solid #ebebeb;
color: #888;
font-family: Verdana,Geneva,sans-serif;
font-size: 10px;
font-weight: normal;
margin-bottom: 20px;
}
.related-results .related-result-row .hl-type {
padding-bottom: 0px;
padding-left: 8px;
margin-top: -6px;
margin-right: 20px;
}
.related-results .related-result-row .hl-type-alt .label, .hl-type-alt-2 {
background-color: #f2f2f2;
border: 1px solid #ebebeb;
color: #888;
font-family: Verdana,Geneva,sans-serif;
font-size: 10px;
font-weight: normal;
margin-bottom: 20px;
}
.related-results .related-result-row a {
text-decoration: none;
}
.related-results .related-result-row a:hover {
text-decoration: underline;
}
.related-results .related-result-row a.focus-search {
font-weight: normal;
text-decoration: underline;
}
.related-results .related-result-row a.focus-search:hover {
font-weight: normal;
text-decoration: none;
}
.related-results .related-result-row .focus-search {
color: #666;
}
/*========== Non-Mobile First Method ==========*/
/* Large Devices, Wide Screens */
@media only screen and (max-width : 1200px) {
}
/* Medium Devices, Desktops */
@media only screen and (max-width : 992px) {
}
/* Small Devices, Tablets */
@media only screen and (max-width : 768px) {
.related-results .related-result-row {
padding-left: 15px;
padding-right: 15px;
}
.related-results .related-result-row .meta-block {
border-left: none;
padding-left: 0;
margin-top: 5px;
}
.related-results .related-result-row .meta-content {
display: inline-block;
padding-right: 10px;
}
}
/* Extra Small Devices, Phones */
@media only screen and (max-width : 480px) {
.related-results .related-result-row {
padding-left: 15px;
padding-right: 15px;
}
.related-results .related-result-row .meta-block {
border-left: none;
padding-left: 0;
margin-top: 5px;
}
.related-results .related-result-row .meta-content {
display: inline-block;
padding-right: 10px;
}
.related-results .pull-right.hl-type {
float: none !important;
margin-top: 0;
padding-bottom: 15px;
padding-left: 0;
text-align: left;
}
}
/* Custom, iPhone Retina */
@media only screen and (max-width : 320px) {
}
Related Content
Encryption and data leakage
Rob Weir
Added 05-11-2010
Discussion Thread
2
Strawman non-repudiation issues
Nick Pope
Added 04-28-2005
Discussion Thread
1
Re: [office] Encryption and data leakage
Malte Timmermann
Added 05-12-2010
Discussion Thread
1
Re: [office] Encryption and data leakage
Malte Timmermann
Added 05-12-2010
Discussion Thread
11
Re: XACML TC Charter Revision - Strawman
Bill Parducci
Added 06-08-2001
Discussion Thread
1
Contact Us
OASIS Open
400 TradeCenter, Suite 5900
Woburn, MA 01801
USA
Phone
+1 781 425 5073
Membership
Get Involved
Join an Open Project
Join a Technical Committee
Privacy & Terms
About Us
Privacy