I'm voting against #2. I guess in favor of #3 for simplicity and
first-release sake.
> For each <InputDocument>, we're sending a 'RefURI' attribute which tells
> the server how to refer to it, so the server can figure out which to treat
> it as (i.e whether it's a same-document reference or not). I don't think
> we need to do anything else to support this distinction, but I'm not sure.
I agree; I think it's enough but I'm not positive.
/r$
--
Rich Salz Chief Security Architect
DataPower Technology http://www.datapower.com
XS40 XML Security Gateway http://www.datapower.com/products/xs40.html
XML Security Overview http://www.datapower.com/xmldev/xmlsecurity.html