Re: [xacml] wd-19 indeterminate policy target handling

From
Erik Rissanen <>
Date
2011-05-19T13:43:08+00:00
ID
Thread
Re: [xacml] wd-19 indeterminate policy target handling
Decision denyOverridesRuleCombiningAlgorithm(Node[] nodes) { // see 1 below
    Boolean atLeastOneErrorD = false;
    Boolean atLeastOneErrorP = false;
    Boolean atLeastOneErrorDP = false;
    Boolean atLeastOnePermit = false;
    for ( i=0; i<lengthOf(nodes); i++  ) {
        Decision decision = evaluate(nodes[i]);   // see #2 below
        if (decision==Deny) {
            return Deny;        // loop breakout (#2 below)
        }
        // the next two "if"s are the same as C.10:
        if (decision==Permit) {
            atLeastOnePermit = true;
            continue; // i.e. skip the rest of the logic for current
                      // iteration of loop, and start next iteration
        }
        if (decision==NotApplicable) {
            continue;
        }
        // Ind{} (no qualifier) can only be returned for rules (#3 below)
        if (decision==Indeterminate) { 
            // cast node to Rule, then get its effect
            if ( effect((Rule)nodes[i])==Deny) ) { 
                atLeastOneErrorD = true;
            }
            else {
                atLeastOneErrorP = true;
            }
            continue;
        }
        it (decision == Indeterminate{D}) {
            atLeastOneErrorD = true;
        }
        it (decision == Indeterminate{P}) {
            atLeastOneErrorp = true;
        }
        it (decision == Indeterminate{DP}) {
            atLeastOneErrorDP = true;
        }
    } // end for loop
    if (atLeastOneErrorD==true &&
          (atLeastOneErrorP==true || atLeastOnePermit==true) {
        atLeastOneErrorDP = true;
    }
    if (atLeastOneErrorDP==true) {
        return Indeterminate{DP};
    }
    if (atLeastOneErrorD==true) {
        return Indeterminate{D};
    }
    if (atLeastOnePermit==true) {
        return Permit;
    }
    if (atLeastOneErrorP == true) {
        return Indeterminate{P};
    }
    return NotApplicable;
} // end algorithm