RE: [xacml] Hierarhical resources.. part 0.1

From
Daniel Engovatov <>
Date
2004-05-11T20:37:00+00:00
ID
Thread
RE: [xacml] Hierarhical resources.. part 0.1
MHonArc v2.5.0b2 -->
















xacml message






[Date Prev]
 | [Thread Prev]
 | [Thread Next]
 | [Date Next]

--

[Date Index]
 | [Thread Index]
 | [List Home]








Subject: RE: [xacml] Hierarhical resources.. part 0.1




From: "Daniel Engovatov" <>
To: <>
Date: Tue, 11 May 2004 13:40:27 -0700






Right.

But then were the problem with "ancestor" that you were referring to
comes from?

Each <resource> has a single, defined bag of "ancestors".
ResourceAttributeDesignator returns this bag.   Were do bag of bags come
from?

If we are to specify multiple <Resource> elements in the request, it is
natural that any <ResourceAttributeDesignator> returns attributes for
the particular single resource that is used in evaluation.

Daniel.

P.S. And again: I do not think we can define a generic enough way to
define mandatory "parents" attributes.