Re: [xacml] interior node

From
Polar Humenn <>
Date
2004-05-11T19:02:00+00:00
ID
Thread
Re: [xacml] interior node
MHonArc v2.5.0b2 -->

















xacml message






[Date Prev]
 | [Thread Prev]
 | [Thread Next]
 | [Date Next]

--

[Date Index]
 | [Thread Index]
 | [List Home]








Subject: Re: [xacml] interior node <Result> elements for a hierarchy




From: Polar Humenn <>
To: XACML TC <>
Date: Tue, 11 May 2004 15:05:25 -0400 (EDT)






On Tue, 11 May 2004, Anne Anderson wrote:

> We have decided to retain the XACML 1.1 semantics that a Request
> for multiple nodes SHALL be equivalent to the <Result> elements
> produced by evaluating each requested node individually: i.e. the
> fact.  This means an unambiguous <Result> can be returned for
> each node.  For some types of hierarchy, an interior node will
> get Permit only if all its children get Permit, or will get Deny
> unless all its children get Permit, but this is up to the policy.

How do you indicate the difference?

What if I want a node that only gets Deny, only if all its children are
Deny, and it gets Permit otherwise?

-Polar