RE: XACML TC Charter Revision - Strawman
I am not suggesting either. SAML (and I) assumes that you know where to go to get an Authorization Decision and that the PDP you ask knows how to compute the answer. I see XACML as currently chartered as a good way to provision a PDP with policies. This is completely outside the current SAML scope. I also see XACML as a way of providing a more complete Authorization Decision Assertion, as in case #2 below. I think what will happen in SAML v1 (at least with our product) is that you will get an answer, but not all the information that was used to make the policy decision will be included in the response. For example, you will ask Can Joe access x? and you will get the answer Yes, joe can access X , but the fact of the matter is the same request would get a different answer 1 sec later. Also perhaps it didn't even matter that it was Joe. Probably for accountability purposes that is good enough, but I continue to be concerned that the assertion will be wrongly construed. Case #3 came from the fact that we keep punting anything that looks complicated and saying XACML will take care of that. Since I have been prominent among the punters (that's a joke, Phill) I started thinking about how XACML might help us with our current major struggle -- Requests. It occured to me that although requests for policies are not the same as policies, perhaps we could steal some bits of XACML for our purposes. This would help justify my position of saying do something simple now and leave a hook for XACML . Hal >
×
New Best Answer
This thread already has a best answer. Would you like to mark this message as the new best answer?
No
$(document).ready(function () {
$("div.messageContentColumn").find("img.media-object").on('click', function () {
if ($(this)[0].parentElement.tagName !== "A") {
var $messageContentColumn = $(this);
var source = "";
if ($messageContentColumn.data("modalsrc") !== undefined) {
source = $messageContentColumn.data("modalsrc")
} else {
source = $messageContentColumn.attr("src").replace("-T.jpg", ".jpg");
source = source.replace("-M.jpg", ".jpg");
source = source.replace("-L.jpg", ".jpg");
}
var title = $messageContentColumn.data('title') !== undefined
? $messageContentColumn.data("title")
: $messageContentColumn.attr("title") !== undefined
? $messageContentColumn.attr("title")
: "";
var $discussionImgModal = $("#discussion-img-modal");
var modalHtml = '
×' +
'
';
if ($discussionImgModal.length == 0) {
$("form").append(modalHtml);
$discussionImgModal = $("#discussion-img-modal");
$discussionImgModal.find(".close").on('click', function () {
$discussionImgModal.modal("hide");
});
}
loadImage($discussionImgModal, source, title);
}
});
function loadImage($discussionImgModal, source, title) {
var discussionImg = $discussionImgModal.find("#modalImg")[0];
discussionImg.onload = function () {
$discussionImgModal.modal("show");
};
discussionImg.src = source;
$discussionImgModal.find("#caption").html(title);
}
var replyInlineParam = HigherLogic.Util.getParameterByName('ReplyInline');
if (!HigherLogic.Util.stringIsNullOrWhiteSpace(replyInlineParam)) {
var $replyInline = $('.reply-inline[data-message-key="' + replyInlineParam + '"]');
if ($replyInline.length > 0) {
openEditor($replyInline);
}
}
$('.reply-inline').on('click',
function () {
hl_common_ui_blockUI();
var $this = $(this);
if ($('.inline-reply-snippet').length > 0) {
hl_common_ui_unBlockUI();
$('.inline-reply-snippet').find('.modal.inline-confirm').modal('show');
$('.inline-reply-snippet').find('.modal.inline-confirm').data('reply-id', $this.prop('id'));
} else {
openEditor($this);
}
});
function openEditor($this) {
$('.inline-reply-snippet').remove();
var postData = { MessageKey: $this.data('message-key'), currentUrl: window.location.href };
HigherLogic.Util.post(
'/higherlogic/ui/mvc/eGroups/eGroups/GetReplyInline',
JSON.stringify(postData),
'html'
).done(function (data) {
var redirectUrl = $(data).data('redirect-url');
if (redirectUrl) {
// gives return location for unauthenticated user redirect to login
redirectUrl = hl_common_util_updateQueryStringParameter(redirectUrl,
'ReturnUrl',
encodeURIComponent(window.location.href));
// gives return location for unsubscribed user redirect to subscribe
window.location.href = hl_common_util_updateQueryStringParameter(redirectUrl,
'PostByLink',
encodeURIComponent(window.location.href));
return;
}
$this.closest('li').append(data);
var $div = $('#' + $(data).first('div').prop('id'));
var bottomOfDiv = $div.offset().top + 500;
$('html, body').animate({
scrollTop: bottomOfDiv - $(window).height()
},
1000);
hl_common_ui_unBlockUI();
});
}
});
.related-results.block {
display: flex;
flex-wrap: wrap;
flex-direction: row;
}
.related-results.block .related-result-row {
flex: 1;
border: 1px solid #cccccc;
margin: 10px;
min-width: 200px;
max-width: 200px;
}
.related-results.block .related-result-row .meta-content-date.block {
float: left;
margin: 0px;
}
.related-results.block .related-result-row .hl-type.block {
margin-top: 5px;
margin-right: 0px;
padding-left: 0px;
margin-bottom: 10px;
text-align: center;
clear: both;
}
.related-results .related-result-row h4 {
margin-bottom: 10px;
}
.related-results .related-result-row .meta-content-date {
color: #666666;
font-size: 12px;
margin: 0px 20px 3px;
display: block;
float: right;
}
.related-results .related-result-row .meta-block {
border-left: 1px solid #ebebeb;
padding-left: 15px;
margin-top: 20px;
font-size: 12px;
}
.related-results .related-result-row .meta-block a {
color: #666;
}
.related-results .related-result-row .meta-content {
margin: 3px 0;
}
.related-results .related-result-row .img-circle {
border-radius: 50%;
width: 20px;
}
.related-results .related-result-row .owner-image {
width: 20px;
float: left;
}
.related-results .related-result-row .owner-name {
color: #666666;
font-size: 12px;
display: block;
float: left;
margin: 2px 5px;
}
.related-results .related-result-row .content-type {
padding-bottom: 5px;
padding-top: 5px;
color: #006621;
font-size: 12px;
font-weight: bold;
}
.related-results .related-result-row .content-tags {
margin-bottom: 5px;
margin-top: 10px;
}
.related-results .related-result-row .content-tags a {
margin-bottom: 10px;
}
.related-results .related-result-row .content-tags a {
display: inline-block;
}
.related-results .related-result-row .match-block {
color: #808080;
}
.related-results .related-result-row .result-indent {
padding-left: 15px;
}
.related-results .related-result-row p.result-indent-event {
padding-left: 15px;
margin-top: 0;
margin-bottom: 0;
color: #333333;
}
.related-results .related-result-row .label-search-tag {
background-color: #fff;
border: 1px solid #ccc;
text-decoration: none;
margin-bottom: 4px;
color: #333;
font-weight: normal;
}
.related-results .related-result-row .label-search-tag:hover {
background-color: #ebebeb;
border: 1px solid #ccc;
margin-bottom: 4px;
color: #333;
font-weight: normal;
text-decoration: none;
}
.related-results .related-results.search-divider hr {
width: 100%;
margin-top: 5px;
margin-bottom: 10px;
border: 1px solid #eeeeee;
}
.related-results .row.search-divider {
margin-left: 0;
margin-right: 0;
}
.related-results .related-result-row .hl-type .label, .hl-type-alt-2.label {
background-color: #f2f2f2;
border: 1px solid #ebebeb;
color: #888;
font-family: Verdana,Geneva,sans-serif;
font-size: 10px;
font-weight: normal;
margin-bottom: 20px;
}
.related-results .related-result-row .hl-type {
padding-bottom: 0px;
padding-left: 8px;
margin-top: -6px;
margin-right: 20px;
}
.related-results .related-result-row .hl-type-alt .label, .hl-type-alt-2 {
background-color: #f2f2f2;
border: 1px solid #ebebeb;
color: #888;
font-family: Verdana,Geneva,sans-serif;
font-size: 10px;
font-weight: normal;
margin-bottom: 20px;
}
.related-results .related-result-row a {
text-decoration: none;
}
.related-results .related-result-row a:hover {
text-decoration: underline;
}
.related-results .related-result-row a.focus-search {
font-weight: normal;
text-decoration: underline;
}
.related-results .related-result-row a.focus-search:hover {
font-weight: normal;
text-decoration: none;
}
.related-results .related-result-row .focus-search {
color: #666;
}
/*========== Non-Mobile First Method ==========*/
/* Large Devices, Wide Screens */
@media only screen and (max-width : 1200px) {
}
/* Medium Devices, Desktops */
@media only screen and (max-width : 992px) {
}
/* Small Devices, Tablets */
@media only screen and (max-width : 768px) {
.related-results .related-result-row {
padding-left: 15px;
padding-right: 15px;
}
.related-results .related-result-row .meta-block {
border-left: none;
padding-left: 0;
margin-top: 5px;
}
.related-results .related-result-row .meta-content {
display: inline-block;
padding-right: 10px;
}
}
/* Extra Small Devices, Phones */
@media only screen and (max-width : 480px) {
.related-results .related-result-row {
padding-left: 15px;
padding-right: 15px;
}
.related-results .related-result-row .meta-block {
border-left: none;
padding-left: 0;
margin-top: 5px;
}
.related-results .related-result-row .meta-content {
display: inline-block;
padding-right: 10px;
}
.related-results .pull-right.hl-type {
float: none !important;
margin-top: 0;
padding-bottom: 15px;
padding-left: 0;
text-align: left;
}
}
/* Custom, iPhone Retina */
@media only screen and (max-width : 320px) {
}
Related Content
Re: [xacml] Is authorization decision a postcondition?
System
Added 11-29-2001
Discussion Thread
1
RE: [xacml] Is authorization decision a postcondition?
Michiharu Kudo
Added 11-30-2001
Discussion Thread
1
RE: [xacml] Is authorization decision a postcondition?
System
Added 11-29-2001
Discussion Thread
1
[xacml] Is authorization decision a postcondition?
System
Added 11-29-2001
Discussion Thread
1
RE: [xacml] Is authorization decision a postcondition?
Tim Moses
Added 11-30-2001
Discussion Thread
1
Contact Us
OASIS Open
400 TradeCenter, Suite 5900
Woburn, MA 01801
USA
Phone
+1 781 425 5073
Membership
Get Involved
Join an Open Project
Join a Technical Committee
Privacy & Terms
About Us
Privacy