← Prev in month ← Prev in thread

MAD conceptual model

From
Tyson, Paul H <>
Date
2009-10-16T14:59:29+00:00
ID
Thread
MAD conceptual model
Attached find proposed description of conceptual model for producing
single authorization decision requests from a multiple authorization
decision (MAD) request.

This would replace some content in sections 2.1, 2.2, 2.3.

I came up with a few questions and concerns:

1. I still don't like the idea of mutable resource-ids.  Either the
original request should have something like "resource-selector", or the
resulting context should have "decision-node-id" or something.  But then
the problem is, how does the PEP request the resource-id to be returned
(using "IncludeInResult")?  We might have to specify some built-in
semantics to handle this.

2. This does not specify how the xpathExpression resource-id for
individual resources will be constructed.  The TC is still discussing
whether to specify this, and if so, what the form should be.  In any
case, it seems necessary to say something about the namespace binding
context that will be used for name prefixes.  Default might be to use
the namespace binding context represented by the union of the contexts
in <Content> children, but this is not specified. One way to facilitate
regexp matching on xpath strings would be to allow policies and/or
requests to specify a namespace binding context.

3. scope=EntireHierarchy is out of place here.  Consider moving Section
3 to hierarchical profile.  The conceptual model and expected results
are different than the other multiple authorization decision modes.  The
"multiple" processing only takes place internally--a single decision is
expected (possibly multiplied by additional subjects or actions).

Regards,
--Paul
← Prev in month ← Prev in thread