RE: XACML TC Charter Revision - Strawman
Sorry to be slow on this, but there is another issue I think we need to consider and include or explicitly reject. I will describe this informally because it is easier to express that way and I hope will be easier to understand. If we get some consensus we can worry about more precise expression. Since this bears on the use of XACML by SAML, I have cross posted this. As I understand it the current scope of the XACML schema is to express: 1. Some policy is this . SAML is interested in using XACML as a means of expressing a Authorization Policy Decisions. In other words something like: 2. The result of evaluating this is TRUE (or FALSE) It seems to me that under the current charter for XACML, this should work. However, in order to do this, SAML needs to be able to make a request for this to be done. Presumably, making the request does not require knowing what policies apply. Therefore it needs to be possible to say: 3. Please evaluate the policies that apply to target X. Here are some inputs that may be needed for this decision. [The PDP will fill in any missing values, either by observing them for itself (e.g. date/time) or by using default values (e.g. unauthenticated subject).] It seems to me that XACML could help with this. For example, XACML will certainly have to define a generalized syntax for expressing the name of a target. Also, if you can say: a) True if signinglimit > $5000 Then similar syntax could be used to express: b) Current value of signinglimit = $10,000 Any opinions? Hal >
×
New Best Answer
This thread already has a best answer. Would you like to mark this message as the new best answer?
No
$(document).ready(function () {
$("div.messageContentColumn").find("img.media-object").on('click', function () {
if ($(this)[0].parentElement.tagName !== "A") {
var $messageContentColumn = $(this);
var source = "";
if ($messageContentColumn.data("modalsrc") !== undefined) {
source = $messageContentColumn.data("modalsrc")
} else {
source = $messageContentColumn.attr("src").replace("-T.jpg", ".jpg");
source = source.replace("-M.jpg", ".jpg");
source = source.replace("-L.jpg", ".jpg");
}
var title = $messageContentColumn.data('title') !== undefined
? $messageContentColumn.data("title")
: $messageContentColumn.attr("title") !== undefined
? $messageContentColumn.attr("title")
: "";
var $discussionImgModal = $("#discussion-img-modal");
var modalHtml = '
×' +
'
';
if ($discussionImgModal.length == 0) {
$("form").append(modalHtml);
$discussionImgModal = $("#discussion-img-modal");
$discussionImgModal.find(".close").on('click', function () {
$discussionImgModal.modal("hide");
});
}
loadImage($discussionImgModal, source, title);
}
});
function loadImage($discussionImgModal, source, title) {
var discussionImg = $discussionImgModal.find("#modalImg")[0];
discussionImg.onload = function () {
$discussionImgModal.modal("show");
};
discussionImg.src = source;
$discussionImgModal.find("#caption").html(title);
}
var replyInlineParam = HigherLogic.Util.getParameterByName('ReplyInline');
if (!HigherLogic.Util.stringIsNullOrWhiteSpace(replyInlineParam)) {
var $replyInline = $('.reply-inline[data-message-key="' + replyInlineParam + '"]');
if ($replyInline.length > 0) {
openEditor($replyInline);
}
}
$('.reply-inline').on('click',
function () {
hl_common_ui_blockUI();
var $this = $(this);
if ($('.inline-reply-snippet').length > 0) {
hl_common_ui_unBlockUI();
$('.inline-reply-snippet').find('.modal.inline-confirm').modal('show');
$('.inline-reply-snippet').find('.modal.inline-confirm').data('reply-id', $this.prop('id'));
} else {
openEditor($this);
}
});
function openEditor($this) {
$('.inline-reply-snippet').remove();
var postData = { MessageKey: $this.data('message-key'), currentUrl: window.location.href };
HigherLogic.Util.post(
'/higherlogic/ui/mvc/eGroups/eGroups/GetReplyInline',
JSON.stringify(postData),
'html'
).done(function (data) {
var redirectUrl = $(data).data('redirect-url');
if (redirectUrl) {
// gives return location for unauthenticated user redirect to login
redirectUrl = hl_common_util_updateQueryStringParameter(redirectUrl,
'ReturnUrl',
encodeURIComponent(window.location.href));
// gives return location for unsubscribed user redirect to subscribe
window.location.href = hl_common_util_updateQueryStringParameter(redirectUrl,
'PostByLink',
encodeURIComponent(window.location.href));
return;
}
$this.closest('li').append(data);
var $div = $('#' + $(data).first('div').prop('id'));
var bottomOfDiv = $div.offset().top + 500;
$('html, body').animate({
scrollTop: bottomOfDiv - $(window).height()
},
1000);
hl_common_ui_unBlockUI();
});
}
});
.related-results.block {
display: flex;
flex-wrap: wrap;
flex-direction: row;
}
.related-results.block .related-result-row {
flex: 1;
border: 1px solid #cccccc;
margin: 10px;
min-width: 200px;
max-width: 200px;
}
.related-results.block .related-result-row .meta-content-date.block {
float: left;
margin: 0px;
}
.related-results.block .related-result-row .hl-type.block {
margin-top: 5px;
margin-right: 0px;
padding-left: 0px;
margin-bottom: 10px;
text-align: center;
clear: both;
}
.related-results .related-result-row h4 {
margin-bottom: 10px;
}
.related-results .related-result-row .meta-content-date {
color: #666666;
font-size: 12px;
margin: 0px 20px 3px;
display: block;
float: right;
}
.related-results .related-result-row .meta-block {
border-left: 1px solid #ebebeb;
padding-left: 15px;
margin-top: 20px;
font-size: 12px;
}
.related-results .related-result-row .meta-block a {
color: #666;
}
.related-results .related-result-row .meta-content {
margin: 3px 0;
}
.related-results .related-result-row .img-circle {
border-radius: 50%;
width: 20px;
}
.related-results .related-result-row .owner-image {
width: 20px;
float: left;
}
.related-results .related-result-row .owner-name {
color: #666666;
font-size: 12px;
display: block;
float: left;
margin: 2px 5px;
}
.related-results .related-result-row .content-type {
padding-bottom: 5px;
padding-top: 5px;
color: #006621;
font-size: 12px;
font-weight: bold;
}
.related-results .related-result-row .content-tags {
margin-bottom: 5px;
margin-top: 10px;
}
.related-results .related-result-row .content-tags a {
margin-bottom: 10px;
}
.related-results .related-result-row .content-tags a {
display: inline-block;
}
.related-results .related-result-row .match-block {
color: #808080;
}
.related-results .related-result-row .result-indent {
padding-left: 15px;
}
.related-results .related-result-row p.result-indent-event {
padding-left: 15px;
margin-top: 0;
margin-bottom: 0;
color: #333333;
}
.related-results .related-result-row .label-search-tag {
background-color: #fff;
border: 1px solid #ccc;
text-decoration: none;
margin-bottom: 4px;
color: #333;
font-weight: normal;
}
.related-results .related-result-row .label-search-tag:hover {
background-color: #ebebeb;
border: 1px solid #ccc;
margin-bottom: 4px;
color: #333;
font-weight: normal;
text-decoration: none;
}
.related-results .related-results.search-divider hr {
width: 100%;
margin-top: 5px;
margin-bottom: 10px;
border: 1px solid #eeeeee;
}
.related-results .row.search-divider {
margin-left: 0;
margin-right: 0;
}
.related-results .related-result-row .hl-type .label, .hl-type-alt-2.label {
background-color: #f2f2f2;
border: 1px solid #ebebeb;
color: #888;
font-family: Verdana,Geneva,sans-serif;
font-size: 10px;
font-weight: normal;
margin-bottom: 20px;
}
.related-results .related-result-row .hl-type {
padding-bottom: 0px;
padding-left: 8px;
margin-top: -6px;
margin-right: 20px;
}
.related-results .related-result-row .hl-type-alt .label, .hl-type-alt-2 {
background-color: #f2f2f2;
border: 1px solid #ebebeb;
color: #888;
font-family: Verdana,Geneva,sans-serif;
font-size: 10px;
font-weight: normal;
margin-bottom: 20px;
}
.related-results .related-result-row a {
text-decoration: none;
}
.related-results .related-result-row a:hover {
text-decoration: underline;
}
.related-results .related-result-row a.focus-search {
font-weight: normal;
text-decoration: underline;
}
.related-results .related-result-row a.focus-search:hover {
font-weight: normal;
text-decoration: none;
}
.related-results .related-result-row .focus-search {
color: #666;
}
/*========== Non-Mobile First Method ==========*/
/* Large Devices, Wide Screens */
@media only screen and (max-width : 1200px) {
}
/* Medium Devices, Desktops */
@media only screen and (max-width : 992px) {
}
/* Small Devices, Tablets */
@media only screen and (max-width : 768px) {
.related-results .related-result-row {
padding-left: 15px;
padding-right: 15px;
}
.related-results .related-result-row .meta-block {
border-left: none;
padding-left: 0;
margin-top: 5px;
}
.related-results .related-result-row .meta-content {
display: inline-block;
padding-right: 10px;
}
}
/* Extra Small Devices, Phones */
@media only screen and (max-width : 480px) {
.related-results .related-result-row {
padding-left: 15px;
padding-right: 15px;
}
.related-results .related-result-row .meta-block {
border-left: none;
padding-left: 0;
margin-top: 5px;
}
.related-results .related-result-row .meta-content {
display: inline-block;
padding-right: 10px;
}
.related-results .pull-right.hl-type {
float: none !important;
margin-top: 0;
padding-bottom: 15px;
padding-left: 0;
text-align: left;
}
}
/* Custom, iPhone Retina */
@media only screen and (max-width : 320px) {
}
Related Content
imperative syntax for generalized xacml
Simon Godik
Added 03-17-2005
Discussion Thread
1
Using XACML Policies to Express Scope in OAuth
Hal Lockhart
Added 06-05-2013
Discussion Thread
15
Generalizing on-permit-apply-second
Erik Rissanen
Added 05-17-2013
Discussion Thread
35
RE: [xacml] Using XACML Policies to Express Scope in OAuth
Anthony Nadalin
Added 06-24-2013
Discussion Thread
5
Groups - Using XACML Policies to Express OAuth Scope.ppt uploaded
Hal Lockhart
Added 06-27-2013
Discussion Thread
1
Contact Us
OASIS Open
400 TradeCenter, Suite 5900
Woburn, MA 01801
USA
Phone
+1 781 425 5073
Membership
Get Involved
Join an Open Project
Join a Technical Committee
Privacy & Terms
About Us
Privacy