Danny,
If I were serious about supporting dynamic template reduction I would take
a different approach, drawing on capabilities that would have more general
uses.
We would need to iterate over the parameter groups. You may recall a
message I wrote on the xacml-comment list describing iterators in the
form of new ForAny and ForAll expressions. Those expressions iterate over
a collection of attribute values. A parameter group is effectively a group
of attributes, so we would need a new concept of a compound attribute value
to iterate over. That is, an attribute value of a new data type that allows
it to contain a nested collection of XACML attributes. The final new bit is
a function that can extract a specified nested attribute from a compound
attribute value.
Each policy template data becomes a single compound attribute value stored
by the PIP. The parameter values for a policy template data are XACML
attributes nested in that compound attribute value. The entire collection
of policy template data is a single XACML attribute containing the compound
attribute values, which the PDP can fetch from the PIP by evaluating a
single attribute designator once.
Instead of a policy template, there is a single policy that uses ForAny
(or ForAll) to iterate over the collection of compound attribute values,
extracting nested attributes from the current compound attribute value
as required as it evaluates the pertinent sub-expression in each iteration.
A limitation is that the iterators can only operate within a condition,
so the "template" has to be described in a single expression, whereas a
Policy Template Engine could expand a template policy or even a template
policy set. I don't think that is showstopper, and is adequate for the
current examples, but may be inconvenient at times.
So there you have it. For the cost of two new expressions, one new data-type
and one new function (and no protocol extensions) I could reproduce the
effect of dynamic template reduction.
I can expand on these ideas if anyone is interested, though I don't expect
there is much interest in dynamic template reduction. I mention them only
because some folks may find some of these things useful in other contexts.
I originally described ForAny and ForAll as a way of properly handling
multi-valued attributes in XACML. Compound attribute values I thought about in
the context of IPC and EC-US where there is a problem correlating multi-valued
attributes. For example, organization could be a compound attribute where
each primary organization value can have its relationship to the subject or
the subject's organization described by nested attributes.
Regards,
Steven
On 10/10/2012 1:03 PM, Danny Thorpe wrote: