RE: [xacml] Hierarhical resources.. part 0.1

From
Daniel Engovatov <>
Date
2004-05-11T18:41:00+00:00
ID
Thread
RE: [xacml] Hierarhical resources.. part 0.1
MHonArc v2.5.0b2 -->
















xacml message






[Date Prev]
 | [Thread Prev]
 | [Thread Next]
 | [Date Next]

--

[Date Index]
 | [Thread Index]
 | [List Home]








Subject: RE: [xacml] Hierarhical resources.. part 0.1




From: "Daniel Engovatov" <>
To: <>
Date: Tue, 11 May 2004 11:45:20 -0700






>RESOURCE-ANCESTORS: One important difference is that there can't
>be a single "resource-ancestors" Attribute.  We do not allow
>"bags of bags", and have no functions for operating on them.


Actually - that is the whole idea that "ancestors" is a single bag.
It is not a bag of bags.  It is a bag or URI - all ancestor resources
fully flattened out and unordered.   I think that is the least common
denominator
Structure to accommodate different hierarchical topologies and avoid
Reconstruction/circular connection problems.

It seems to me that it works just fine as I described - I do not
understand why would be want bag of bags?



>REQUESTS FOR MULTIPLE NODES: On the topic of requests for
>multiple nodes in one Request, I think we all agree that the
><Result> elements must be equivalent to those obtained by
>evaluating access to each node independently.  For this reason, I
>don't think the "scope" Attribute or a "resource-id" Attribute

I agree.