I think you are making the OAuth model very complex here by trying to add in XACML, there are size restrictions for the implicit flows that would prohibit XACML type policies, there are size restriction on refresh tokens (that would contain the original asked for scope), etc.
-----Original Message-----
From: Hal Lockhart [mailto:]
Sent: Thursday, June 20, 2013 12:52 PM
To: Anthony Nadalin
Cc: ; Steven Legg
Subject: RE: [xacml] Using XACML Policies to Express Scope in OAuth
Well simplicity depends on what you know and what tools you have access to. Most OAuth types would describe writing a _javascript_ program as "simple" because they know _javascript_ and know a _javascript_ interpreter/compiler can be provided in the development environment they intend to use. However objectively, an XACML PDP is WAY simpler than a _javascript_ interpreter/compiler and the policy language is certainly simpler than a Turing complete language. Further, as I say in the paper, I am assuming it is easy to provide PDPs which are cheap or free. I think using a standard policy language is easier than inventing a new one, as has been done in Amazon's AWS, for example.
Its not entirely clear that the Client is supposed to understand the scope _expression_. For example, RFC 6749 says:
"An access token is a string representing an authorization issued to the client. The string is usually opaque to the client."
However, if the requirement is for the Client to check the Scope before the Resource Server checks it, there is no reason the Client can't also have a PDP.
The point is, there are many organizations in fields such as Healthcare and GeoSpatial who have requirements for complex policies. There is no reason why they shouldn't be able to use OAuth in appropriate situations, just as those who have simpler requirements do.
Hal