RE: XACML TC Charter Revision - Strawman

From
System <>
Date
2001-06-07T18:14:00+00:00
ID
Thread
RE: XACML TC Charter Revision - Strawman
Sorry to be slow on this, but there is another issue I think we need to consider and include or explicitly reject. I will describe this informally because it is easier to express that way and I hope will be easier to understand. If we get some consensus we can worry about more precise expression.  Since this bears on the use of XACML by SAML, I have cross posted this.  As I understand it the current scope of the XACML schema is to express:  1. Some policy is  this .  SAML is interested in using XACML as a means of expressing a Authorization Policy Decisions. In other words something like:  2. The result of evaluating  this  is TRUE (or FALSE)  It seems to me that under the current charter for XACML, this should work.  However, in order to do this, SAML needs to be able to make a request for this to be done. Presumably, making the request does not require knowing what policies apply. Therefore it needs to be possible to say:  3. Please evaluate the policies that apply to target X. Here are some inputs that may be needed for this decision. [The PDP will fill in any missing values, either by observing them for itself (e.g. date/time) or by using default values (e.g. unauthenticated subject).]  It seems to me that XACML could help with this. For example, XACML will certainly have to define a generalized syntax for expressing the name of a target.   Also, if you can say:  a) True if signinglimit > $5000  Then similar syntax could be used to express:  b) Current value of signinglimit = $10,000  Any opinions?  Hal   > 

                                                

					
                                                    

        
                                                
				

                                                

                                                    
                                                

                                                
                                            

                                        

                                        
                                        

                                    
			

                                    
                                

                                
                                

                                

                            
		

                
        
    

    

        

            

                ×
                New Best Answer
            

            

                This thread already has a best answer.  Would you like to mark this message as the new best answer?
            

            

                

                    
                    
                    No
                

            

        

    

    $(document).ready(function () {

        $("div.messageContentColumn").find("img.media-object").on('click', function () {

            if ($(this)[0].parentElement.tagName !== "A") {

                var $messageContentColumn = $(this);

                var source = "";
                if ($messageContentColumn.data("modalsrc") !== undefined) {

                    source = $messageContentColumn.data("modalsrc")

                } else {

                    source = $messageContentColumn.attr("src").replace("-T.jpg", ".jpg");
                    source = source.replace("-M.jpg", ".jpg");
                    source = source.replace("-L.jpg", ".jpg");
                }
                
                var title = $messageContentColumn.data('title') !== undefined
                    ? $messageContentColumn.data("title")
                    : $messageContentColumn.attr("title") !== undefined
                        ? $messageContentColumn.attr("title")
                        : "";
                
                var $discussionImgModal = $("#discussion-img-modal");

                var modalHtml = '
×' +
                    '

';

                if ($discussionImgModal.length == 0) {

                    $("form").append(modalHtml);
                    $discussionImgModal = $("#discussion-img-modal");

                    $discussionImgModal.find(".close").on('click', function () {
                        $discussionImgModal.modal("hide");
                    });
                }

                loadImage($discussionImgModal, source, title);
            }
        });

        function loadImage($discussionImgModal, source, title) {
                
            var discussionImg = $discussionImgModal.find("#modalImg")[0];
            discussionImg.onload = function () {
                $discussionImgModal.modal("show");
            };
                
            discussionImg.src = source;

            $discussionImgModal.find("#caption").html(title);
        }

        var replyInlineParam = HigherLogic.Util.getParameterByName('ReplyInline');
        if (!HigherLogic.Util.stringIsNullOrWhiteSpace(replyInlineParam)) {
            var $replyInline = $('.reply-inline[data-message-key="' + replyInlineParam + '"]');
            if ($replyInline.length > 0) {
                openEditor($replyInline);
            }
        }

        $('.reply-inline').on('click',
            function () {
                hl_common_ui_blockUI();
                var $this = $(this);
                if ($('.inline-reply-snippet').length > 0) {
                    hl_common_ui_unBlockUI();
                    $('.inline-reply-snippet').find('.modal.inline-confirm').modal('show');
                    $('.inline-reply-snippet').find('.modal.inline-confirm').data('reply-id', $this.prop('id'));
                } else {
                    openEditor($this);
                }
            });

        function openEditor($this) {
            $('.inline-reply-snippet').remove();
            var postData = { MessageKey: $this.data('message-key'), currentUrl: window.location.href };
            HigherLogic.Util.post(
                '/higherlogic/ui/mvc/eGroups/eGroups/GetReplyInline',
                JSON.stringify(postData),
                'html'
            ).done(function (data) {
                var redirectUrl = $(data).data('redirect-url');
                if (redirectUrl) {
                    // gives return location for unauthenticated user redirect to login
                    redirectUrl = hl_common_util_updateQueryStringParameter(redirectUrl,
                        'ReturnUrl',
                        encodeURIComponent(window.location.href));
                    // gives return location for unsubscribed user redirect to subscribe
                    window.location.href = hl_common_util_updateQueryStringParameter(redirectUrl,
                        'PostByLink',
                        encodeURIComponent(window.location.href));
                    return;
                }

                $this.closest('li').append(data);

                var $div = $('#' + $(data).first('div').prop('id'));
                var bottomOfDiv = $div.offset().top + 500;

                $('html, body').animate({
                        scrollTop: bottomOfDiv - $(window).height()
                    },
                    1000);
                hl_common_ui_unBlockUI();
            });
        }
    });

            

        

    

	

    .related-results.block {
        display: flex;
        flex-wrap: wrap;
        flex-direction: row;
    }

        .related-results.block .related-result-row {
            flex: 1;
            border: 1px solid #cccccc;
            margin: 10px;
            min-width: 200px;
            max-width: 200px;
        }

            .related-results.block .related-result-row .meta-content-date.block {
                float: left;
                margin: 0px;
            }

            .related-results.block .related-result-row .hl-type.block {
                margin-top: 5px;
                margin-right: 0px;
                padding-left: 0px;
                margin-bottom: 10px;
                text-align: center;
                clear: both;
            }

    .related-results .related-result-row h4 {
        margin-bottom: 10px;
    }

    .related-results .related-result-row .meta-content-date {
        color: #666666;
        font-size: 12px;
        margin: 0px 20px 3px;
        display: block;
        float: right;
    }

    .related-results .related-result-row .meta-block {
        border-left: 1px solid #ebebeb;
        padding-left: 15px;
        margin-top: 20px;
        font-size: 12px;
    }

        .related-results .related-result-row .meta-block a {
            color: #666;
        }

    .related-results .related-result-row .meta-content {
        margin: 3px 0;
    }

    .related-results .related-result-row .img-circle {
        border-radius: 50%;
        width: 20px;
    }

    .related-results .related-result-row .owner-image {
        width: 20px;
        float: left;
    }

    .related-results .related-result-row .owner-name {
        color: #666666;
        font-size: 12px;
        display: block;
        float: left;
        margin: 2px 5px;
    }

    .related-results .related-result-row .content-type {
        padding-bottom: 5px;
        padding-top: 5px;
        color: #006621;
        font-size: 12px;
        font-weight: bold;
    }

    .related-results .related-result-row .content-tags {
        margin-bottom: 5px;
        margin-top: 10px;
    }

        .related-results .related-result-row .content-tags a {
            margin-bottom: 10px;
        }

        .related-results .related-result-row .content-tags a {
            display: inline-block;
        }

    .related-results .related-result-row .match-block {
        color: #808080;
    }

    .related-results .related-result-row .result-indent {
        padding-left: 15px;
    }

    .related-results .related-result-row p.result-indent-event {
        padding-left: 15px;
        margin-top: 0;
        margin-bottom: 0;
        color: #333333;
    }

    .related-results .related-result-row .label-search-tag {
        background-color: #fff;
        border: 1px solid #ccc;
        text-decoration: none;
        margin-bottom: 4px;
        color: #333;
        font-weight: normal;
    }

        .related-results .related-result-row .label-search-tag:hover {
            background-color: #ebebeb;
            border: 1px solid #ccc;
            margin-bottom: 4px;
            color: #333;
            font-weight: normal;
            text-decoration: none;
        }

    .related-results .related-results.search-divider hr {
        ​​​​​​width: 100%;
        margin-top: 5px;
        margin-bottom: 10px;
        border: 1px solid #eeeeee;
    }

    .related-results .row.search-divider {
        margin-left: 0;
        margin-right: 0;
    }

    .related-results .related-result-row .hl-type .label, .hl-type-alt-2.label {
        background-color: #f2f2f2;
        border: 1px solid #ebebeb;
        color: #888;
        font-family: Verdana,Geneva,sans-serif;
        font-size: 10px;
        font-weight: normal;
        margin-bottom: 20px;
    }

    .related-results .related-result-row .hl-type {
        padding-bottom: 0px;
        padding-left: 8px;
        margin-top: -6px;
        margin-right: 20px;
    }

    .related-results .related-result-row .hl-type-alt .label, .hl-type-alt-2 {
        background-color: #f2f2f2;
        border: 1px solid #ebebeb;
        color: #888;
        font-family: Verdana,Geneva,sans-serif;
        font-size: 10px;
        font-weight: normal;
        margin-bottom: 20px;
    }

    .related-results .related-result-row a {
        text-decoration: none;
    }

        .related-results .related-result-row a:hover {
            text-decoration: underline;
        }

        .related-results .related-result-row a.focus-search {
            font-weight: normal;
            text-decoration: underline;
        }

            .related-results .related-result-row a.focus-search:hover {
                font-weight: normal;
                text-decoration: none;
            }

    .related-results .related-result-row .focus-search {
        color: #666;
    }
    /*==========  Non-Mobile First Method  ==========*/

    /* Large Devices, Wide Screens */
    @media only screen and (max-width : 1200px) {
    }

    /* Medium Devices, Desktops */
    @media only screen and (max-width : 992px) {
    }

    /* Small Devices, Tablets */
    @media only screen and (max-width : 768px) {
        .related-results .related-result-row {
            padding-left: 15px;
            padding-right: 15px;
        }

            .related-results .related-result-row .meta-block {
                border-left: none;
                padding-left: 0;
                margin-top: 5px;
            }

            .related-results .related-result-row .meta-content {
                display: inline-block;
                padding-right: 10px;
            }
    }

    /* Extra Small Devices, Phones */
    @media only screen and (max-width : 480px) {
        .related-results .related-result-row {
            padding-left: 15px;
            padding-right: 15px;
        }

            .related-results .related-result-row .meta-block {
                border-left: none;
                padding-left: 0;
                margin-top: 5px;
            }

            .related-results .related-result-row .meta-content {
                display: inline-block;
                padding-right: 10px;
            }

        .related-results .pull-right.hl-type {
            float: none !important;
            margin-top: 0;
            padding-bottom: 15px;
            padding-left: 0;
            text-align: left;
        }
    }

    /* Custom, iPhone Retina */
    @media only screen and (max-width : 320px) {
    }

    

         
    Related Content

        
           
                

                    

                        

                            

                                
                                    
                                        imperative syntax for generalized xacml
                                    
                                

                                        

                                            

                                                
                                            

                                        

                                        

                                                
                                                    Simon Godik
                                                    

                                                
                                        

                                                                    

                                        Added 03-17-2005
                                    

                                                                    

                                        
                                            Discussion Thread
                                                1
                                        
                                    

                            

                        

                    

                

                

                    

                        

                            

                                
                                    
                                        Using XACML Policies to Express Scope in OAuth
                                    
                                

                                        

                                            

                                                
                                            

                                        

                                        

                                                
                                                    Hal Lockhart
                                                    

                                                
                                        

                                                                    

                                        Added 06-05-2013
                                    

                                                                    

                                        
                                            Discussion Thread
                                                15
                                        
                                    

                            

                        

                    

                

                

                    

                        

                            

                                
                                    
                                        Generalizing on-permit-apply-second
                                    
                                

                                        

                                            

                                                
                                            

                                        

                                        

                                                
                                                    Erik Rissanen
                                                    

                                                
                                        

                                                                    

                                        Added 05-17-2013
                                    

                                                                    

                                        
                                            Discussion Thread
                                                35
                                        
                                    

                            

                        

                    

                

                

                    

                        

                            

                                
                                    
                                        RE: [xacml] Using XACML Policies to Express Scope in OAuth
                                    
                                

                                        

                                            

                                                
                                            

                                        

                                        

                                                
                                                    Anthony Nadalin
                                                    

                                                
                                        

                                                                    

                                        Added 06-24-2013
                                    

                                                                    

                                        
                                            Discussion Thread
                                                5
                                        
                                    

                            

                        

                    

                

                

                    

                        

                            

                                
                                    
                                        Groups - Using XACML Policies to Express OAuth Scope.ppt uploaded
                                    
                                

                                        

                                            

                                                
                                            

                                        

                                        

                                                
                                                    Hal Lockhart
                                                    

                                                
                                        

                                                                    

                                        Added 06-27-2013
                                    

                                                                    

                                        
                                            Discussion Thread
                                                1
                                        
                                    

                            

                        

                    

                

        

    

        

		
        
	

        
    

						
						

						
					

					
					
					
				

			

			

				

					
					
					

						

							

	
							

                

Contact Us

OASIS Open
400 TradeCenter, Suite 5900
Woburn, MA 01801
USA

Phone
+1 781 425 5073

Membership

Get Involved

Join an Open Project

Join a Technical Committee

Privacy & Terms

About Us
Privacy