>> It should not be required
I think it should be required to clarify
how to process a hierarchical resource and the "scope" attribute.
Satoshi Hada
IBM Tokyo Research Laboratory
mailto:
"Daniel Engovatov"
<>
2004/01/06 11:02
To
Satoshi Hada/Japan/IBM@IBMJP,
"XACML" <>
cc
Subject
RE: [xacml] [Issue] How many
resourceIds in request context?
Ouch. This is bad. This is real
bad. I did not notice this sentence. It should not be required.
Will think on what interpretation I can suggest instead.
Daniel.
Also, Section 7.8 says that if the "scope" value is "Immediate"
or omitted, the request SHALL be interpreted to apply to
just the single resource specified by the "resource-id"
attribute.
I think this description implies that
there must be one and only one "resource-id" attribute
in any request context.