I think the point is that SAML will make no attempt to standardise the
contents of assertions like this.
- irving -
> From: Philip Hallam-Baker [mailto:]
> Subject: RE: Requirement for Isolated Request for Authorization
> Atributes
>
> OK maybe I should have said 'appears to be out of scope but
> attempting to
> prevent a user from making such an assertion will require
> specific effort'.
>
> Phillip Hallam-Baker
> > From: Darren Platt [mailto:]
> > Subject: RE: Requirement for Isolated Request for Authorization
> > Atributes
> >
> > I do not believe this is currently considered in scope (by
> > the requirements
> > group anyway), nor should it be:
> >
> > > "Any party with the rights identifier PQR is authorized to
> > access the file
> > > xyz.html"
> > > Appears to be in scope but is very definitely a policy
> > > statement