← Prev in month ← Prev in thread
Next in thread → Next in month →

RE: [xacml] Groups - oasis-xacml-profile-multiple-resources-wd-03 .pdfuploaded

From
Anne Anderson <>
Date
2004-08-26T18:07:00+00:00
ID
Thread
RE: [xacml] Groups - oasis-xacml-profile-multiple-resources-wd-03 .pdfuploaded
MHonArc v2.5.0b2 -->

xacml message

[Date Prev]
 | [Thread Prev]
 | [Thread Next]
 | [Date Next]

--

[Date Index]
 | [Thread Index]
 | [List Home]

Subject: RE: [xacml] Groups - oasis-xacml-profile-multiple-resources-wd-03	.pdfuploaded

From: Anne Anderson <>

To: Tim Moses <>

Date: Thu, 26 Aug 2004 14:07:14 -0400

Tim,

Thanks for the comments.  Here is how I responded to them in
Draft 04.

On 17 August, Tim Moses writes: RE: [xacml] Groups - oasis-xacml-profile-multiple-resources-wd-03	.pdf uploaded
 > In sections 3.1.3 and 3.2.3 outcomes of "Indeterminate" and "NotApplicable"
 > are not currently discussed.

I changed text to say explicitly "If any of the new request
contexts evaluates to "Deny", "Indeterminate", or
"NotApplicable", then a single <Result> containing a <Decision>
of "Deny" SHALL be placed into the response context returned to
the PEP.  This is as if the responses were being combined under a
"DenyOverrides" combining algorithm, which seems to be the only
safe single choice.

 > Trivial ...
 > 
 > 19 - Include instructions for using the Web form to submit comments (see
 > text on the front page of the core spec.).

Done.

 > 52 - unbold "authorization".  Only "decision request" is in
the glossary.

I deleted "authorization" and changed to say just "decision
request".

 > 121 and elsewhere - I prefer not to use the section title in the section
 > reference (e.g. Section 4.1:"scope").  This is because it isn't always clear
 > where the section title ends and the normal text continues.

Done.

 > 132 - Change "is the contents of the <AttributeValue>" to "SHALL be the
 > contents of the <AttributeValue> element".

Done.

 > 146 - <children> to <Children> and <descendants> to <Descendants>.  Also,
 > how about a shorter title for sections 2.1 and 2.2.  I suggest: "Nodes
 > identified by scope" and "Nodes identified by XPath"?

I took your suggestions for the shorter titles.

 > In Section 2.1, include a note to the effect that "scope" is defined in
 > Section 4.

Done.

 > 161 - Eliminate duplicate "be".

Done.

 > 168 & 170 - Change "the Individual Resources are" to "each Individual
 > Resource is".

Done.

 > 196 - Change "attribute evaluates" to "attribute is an xpath expression that
 > evaluates".

Done.

 > 223 - Correct formatting of <Resource>.

Done.

 > 224 - Change "the mechanisms" to "the other mechanisms".

Done.

 > 243 - Eliminate duplicate "a".

Done.

 > 266 - Eliminate leading space.

Done.

 > 277 - Change "containing" to "contains".

Done.

 > 277 - Eliminate "That node SHALL be the one corresponding to the new request
 > context.".  I think this is redundant.  Isn't it?

I removed the sentence, but changed the previous sentence to say
"nodeset that contains exactly that one node in the
                               ^^^^
<ResourceContent> element"

My concern was that the XPath expression might well evaluate to
only a single node, but that node might be some node other than
the one that this new Request Context is being constructed for.

 > 295 - Eliminate leading space.

Done.  Eagle eye!

 > 305 - Eliminate "That node SHALL be the one corresponding to the new request
 > context.".  I think this is redundant.  Isn't it?

Same changes as for 277.

Thanks again.

Anne
 >
← Prev in month ← Prev in thread
Next in thread → Next in month →