Here is my proposed rewording. Does this seem more clear?
xacml-context:Request [Optional]
The information used to make the authorization decision.
If the AuthorizationDecisionRequest "ReturnContext"
attribute is TRUE, then this element MUST be supplied and
MUST include all XACML Attributes used in making the
Authorization Decision, whether supplied in the original
AuthorizationDecisionQuery or obtained from external
sources. The xacml-context:Request MAY include additional
XACML Attributes that were not used in making the
Authorization Decision.
If the AuthorizationDecisionRequest "ReturnContext"
attribute is FALSE, then this element MUST NOT be supplied.
So far, this is the only change I have made to the proposal
mailed out on 20 March
(http://lists.oasis-open.org/archives/xacml/200303/msg00007.html).
I have attached a copy of the modified proposal to this e-mail.
Unless other comments come in, this is the proposal we will be
voting on at the 3 April TC meeting.
-Anne
On 27 March, bill parducci writes: Re: [xacml] Proposed Agenda for April 3 concall...
> is it me, or is this confusing:
>
> | xacml-context:Request [Optional]
>
> | The information used to make the authorization decision.
> | This element MUST be supplied if the
> | AuthorizationDecisionRequest "ReturnContext" attribute is
> | TRUE and MUST NOT be supplied if the
> | AuthorizationDecisionRequest "ReturnContext" attribute is
> | FALSE. The xacml-context:Request MUST include all XACML
> | Attributes used in making the Authorization Decision,
> | whether supplied in the original AuthorizationDecisionQuery
> | or obtained from external sources. The
> | xacml-context:Request MAY include additional XACML
> | Attributes that were not used in making the Authorization
> | Decision.
>
> 'MUST/MUST NOT' and 'optional' seem conflicting. is the intent to
> indicate 'IF USED, this element MUST ...?'
--
Anne H. Anderson Email:
Sun Microsystems Laboratories
1 Network Drive,UBUR02-311 Tel: 781/442-0928
Burlington, MA 01803-0902 USA Fax: 781/442-1692