Hi Steven,
If itâs possible for multiple dynamic attributes to exist in the decision context how do you see ignore-initial-values obligation working? Wouldnât there have to be arbitration amongst those as well?
thanks
b
On Sep 9, 2021, at 10:40 PM, Steven Legg <> wrote:
All,I've been considering the issue of how to handle dynamic attributes generated by the DynamicAttribute Authority that are attributes already in the request context (see Section 3.4 ofhttps://www.oasis-open.org/apps/org/workgroup/xacml/download.php/68861/xacml-3.0-dyn-attr-v1.0-wd03.docx ).The three main options are "merge", "dynamic attribute overrides" and "existing attributeoverrides". There are straightforward ways to get the effect of "merge" or "existing attributeoverrides", whatever the default behaviour, by judicious use of the issuer field and theexisting DAA obligations, but not in the case of "dynamic attribute overrides". This wouldsuggest that "dynamic attribute overrides" should be the default, though it feels a bit like asledgehammer and isn't the path of least resistance.XACML allows the same attribute to appear multiple times in the request, with one or morepossibly-duplicated attribute values in each instance, so tacking on a few more generated bythe DAA is trivially easy and is likely to involve the least disruption to existing contexthandler implementations. This is the "merge" option. The current DAA draft merges whileavoiding adding duplicate values, but it would be simpler to not worry about duplicates sincethey rarely matter and there are a few ways to avoid them if required.If "merge" is the default then I would propose adding a new obligation so as to get the effectof "dynamic attribute overrides" when desired. Call it the ignore-initial-values obligation.It would have the same components as the exclude-all-values obligation and its effect would beto cause the context handler the exclude any original values of the nominated attribute fromthe request context.If I don't hear any arguments to the contrary, in the next DAA draft I will keep "merge" asthe nominal behaviour, except in the presence of an ignore-initial-values obligation, and dropthe need to check for duplicates. I'll add a non-normative section on ways to get thedifferent behaviours.Regards,Steven---------------------------------------------------------------------To unsubscribe from this mail list, you must leave the OASIS TC that generates this mail. Follow this link to all your TCs in OASIS at:https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php