RE: [xacml] Hierarhical resources.. part 0.1

From
Anne Anderson <>
Date
2004-05-11T20:30:00+00:00
ID
Thread
RE: [xacml] Hierarhical resources.. part 0.1
MHonArc v2.5.0b2 -->

xacml message

[Date Prev]
 | [Thread Prev]
 | [Thread Next]
 | [Date Next]

--

[Date Index]
 | [Thread Index]
 | [List Home]

Subject: RE: [xacml] Hierarhical resources.. part 0.1

From: Anne Anderson <>

To: Daniel Engovatov <>

Date: Tue, 11 May 2004 16:33:30 -0400

On 11 May, Daniel Engovatov writes: RE: [xacml] Hierarhical resources.. part 0.1
 > Dang, you may be right.   We bypassed this issue for constraints as we
 > had functions to make a bag of values.  As I was not working with
 > request schema I forgot about that.
 > 
 > But, couldn't you just specify multiple instances of the same attribute
 > in request context?  Attribute currently has exactly one attribute value
 > (which is a bad outage in my opinion - we need to be able to  bags) -
 > but is it prohibited to have multiple attribute with the same
 > attributeId?
 > In request:

 > <resource>
 > 	<Attribute AttributeID = "foo" DataType = "string">
 > 		<AttributeValue >bar</AttributeValue>
 > 	</Attribute>
 > 	<Attribute AttributeID = "foo" DataType = "string">
 > 		<AttributeValue >spam</AttributeValue>
 > 	</Attribute>
 > <resource>
 > 
 > Would not that define bag[string]   foo = ["bar", "spam"] ?

It is perfectly legal to have multiple Request Attributes with
the same AttributeId.

Also, we have already decided to define

    <Attribute >
      <AttributeValue>val1</AttributeValue>
      <AttributeValue>val2</AttributeValue>
      <AttributeValue>val3</AttributeValue>
    </Attribute>

as equivalent to:

    <Attribute >
      <AttributeValue>val1</AttributeValue>
    </Attribute>
    <Attribute >
      <AttributeValue>val2</AttributeValue>
    </Attribute>
    <Attribute >
      <AttributeValue>val3</AttributeValue>
    </Attribute>

so, yes, that is an alternative way to specify the multiple
values for "resource-ancestor" and "resource-parent" Attributes.

 > 
 > 
 > Of cause defining "bag" metadata along with datatype, and supplying
 > multiple
 > <AttributeValue>'s is much better.
 > 
 > Remind me - why do we not send bags in a request?

1) We do not have functions to operate on bags of bags, if that
   is what you are asking
2) We already have syntax for sending "bags" in the request, if
   you are just asking for an <AttributeDescriptor> or
   <AttributeSelector> that evaluates to a "bag": they always
   evaluate to a bag that contains one element for each Attribute
   or nodeset node that matches.  See above.

Polar can probably give you more reasons :-)

Anne

 >