Dear all,
In addition to the revision notes, I wanted to make a couple points:
I tracked changes in the document so that everyone can see what has changed - there's quite a bit as a matter of fact (lots of fixes or clarifications)
I added comments where I wanted to ask the TC how to move forward.
The comments / questions are:
Can we decide to change the profile name? Is there a process we need to respect? This is in line with Ray's request from a weeks back.
Suggested new name: JSON Profile of XACML 3.0
(as per Remon Sinnema’s email dated March 6 2014)
In the XACML 3.0 spec, the XPathExpressionDatatype object contains an XPathCategory property. This property seems to be redundant since an XPathExpressionDatatype belongs to a parent which already indicates the category. Am I reading this correctly? Can we get rid of XPathCategory?
With respect to the special numerical values, and generally if input or output is non conformant to spec, should we throw an error or an INdeterminate? In other words should we delegate error throwing to the transport layer or should we specify w/in the XACML spec?
Thanks,
David.
On Wed, Mar 19, 2014 at 5:08 PM, David Brossard <> wrote:
Submitter's message
Dear all,
Here's the long awaited WD16 which fixes most of the comments on the XACML list. Here is the summary of the changes:
- Fixed issues with special numerical values: based on input from the XACML TC, special values (NaN, Inf, -0) are now excluded
- Rewrote section 3.4.2 and added reference to 3.4.1
- Added a section defining the shorthand notation for standard XACML categories
- Added normative reference to XACML 3.0 standard
- Added optional category objects for all default categories in XACML 3.0 instead of the 4 most common ones only.
- Updated example in 4.2.4.1
- Fixed the Transport section to reference the REST profile.
- Fixed broken samples
- Added references to IEEE 754-1985 rather than _javascript_ for the special numerical values
- Fixed the Content section to include the namespaces requirement
- Fixed the default value for XPathVersion to be in accordance with [XACML30].
- Added the MissingAttributeValue object definition.
-- Mr. David Brossard
Document Name: Request / Response Interface based on JSON and HTTP for XACML 3.0 Version 1.0
Description
With the rise in popularity of APIs and its consumerization, it becomes
important for XACML to be easily understood in order to increase the
likelihood it will be adopted. In particular, XML is often considered to be
too verbose. Developers increasingly prefer a lighter representation using
JSON, the _javascript_ object notation.
This profile aims at defining a JSON format for the XACML request and
response. It also defines the transport between client (PEP) and service
(PDP).
Download Latest Revision
Public Download Link
Submitter: Mr. David Brossard
Group: OASIS eXtensible Access Control Markup Language (XACML) TC
Folder: Specifications and Working Drafts
Date submitted: 2014-03-19 09:07:53
Revision: 14
--
David Brossard, M.Eng, SCEA, CSTP
VP of Customer Relations
+46(0)760 25 85 75
Axiomatics AB
Skeppsbron 40
S-111 30 Stockholm, Sweden
Support: https://support.axiomatics.com
Web: http://www.axiomatics.com
Axiomatics for developers: http://developers.axiomatics.com
Connect with us on LinkedIn | Twitter | Google + | Facebook | YouTube