Re: [xacml] Groups - Request / Response Interface based on JSON and HTTP for XACML 3.0 Version 1.0 uploaded

From
David Brossard <>
Date
2014-03-19T16:13:56+00:00
ID
CABSq=
Thread
Re: [xacml] Groups - Request / Response Interface based on JSON and HTTP for XACML 3.0 Version 1.0 uploaded
Dear all,

In addition to the revision notes, I wanted to make a couple points:

I tracked changes in the document so that everyone can see what has changed - there's quite a bit as a matter of fact (lots of fixes or clarifications)

I added comments where I wanted to ask the TC how to move forward.

The comments / questions are:

Can we decide to change the profile name? Is there a process we need to respect? This is in line with Ray's request from a weeks back.

Suggested new name: JSON Profile of XACML 3.0
(as per Remon Sinnema’s email dated March 6 2014) 

In the XACML 3.0 spec, the XPathExpressionDatatype object contains an XPathCategory property. This property seems to be redundant since an XPathExpressionDatatype belongs to a parent which already indicates the category. Am I reading this correctly? Can we get rid of XPathCategory?

With respect to the special numerical values, and generally if input or output is non conformant to spec, should we throw an error or an INdeterminate? In other words should we delegate error throwing to the transport layer or should we specify w/in the XACML spec?

Thanks,

David.

On Wed, Mar 19, 2014 at 5:08 PM, David Brossard <> wrote:

        Submitter's message

        Dear all,

Here's the long awaited WD16 which fixes most of the comments on the XACML list. Here is the summary of the changes:

 - Fixed issues with special numerical values: based on input from the XACML TC, special values (NaN, Inf, -0) are now excluded

 - Rewrote section 3.4.2 and added reference to 3.4.1

 - Added a section defining the shorthand notation for standard XACML categories

 - Added normative reference to XACML 3.0 standard

 - Added optional category objects for all default categories in XACML 3.0 instead of the 4 most common ones only.

 - Updated example in 4.2.4.1

 - Fixed the Transport section to reference the REST profile.

 - Fixed broken samples

 - Added references to IEEE 754-1985 rather than _javascript_ for the special numerical values

 - Fixed the Content section to include the namespaces requirement

 - Fixed the default value for XPathVersion to be in accordance with [XACML30].

 - Added the MissingAttributeValue object definition.

        

-- Mr. David Brossard
        
    

    
        Document Name: Request / Response Interface based on JSON and HTTP for  XACML 3.0 Version 1.0

        
        Description

        With the rise in popularity of APIs and its consumerization, it becomes

important for XACML to be easily understood in order to increase the

likelihood it will be adopted. In particular, XML is often considered to be

too verbose. Developers increasingly prefer a lighter representation using

JSON, the _javascript_ object notation.

This profile aims at defining a JSON format for the XACML request and

response. It also defines the transport between client (PEP) and service

(PDP).        

        Download Latest Revision

        Public Download Link
        

        Submitter: Mr. David Brossard

                Group: OASIS eXtensible Access Control Markup Language (XACML) TC

        Folder: Specifications and Working Drafts

        Date submitted: 2014-03-19 09:07:53

                Revision: 14

                

            
    

-- 

David Brossard, M.Eng, SCEA, CSTP
VP of Customer Relations
+46(0)760 25 85 75

Axiomatics AB
Skeppsbron 40
S-111 30 Stockholm, Sweden
Support: https://support.axiomatics.com 

Web: http://www.axiomatics.com

Axiomatics for developers: http://developers.axiomatics.com

Connect with us on LinkedIn | Twitter | Google + | Facebook | YouTube