Re: [xacml] WI#9 Proposal: policies referring to hierarchical resources

From
Daniel Engovatov <>
Date
2004-04-08T20:23:00+00:00
ID
Thread
Re: [xacml] WI#9 Proposal: policies referring to hierarchical resources
MHonArc v2.5.0b2 -->
















xacml message






[Date Prev]
 | [Thread Prev]
 | [Thread Next]
 | [Date Next]

--

[Date Index]
 | [Thread Index]
 | [List Home]








Subject: Re: [xacml] WI#9 Proposal: policies referring to hierarchical resources




From: "Daniel Engovatov" <>
To: <>
Date: Thu, 8 Apr 2004 13:39:10 -0700






>The Request Context is notional.  It does NOT mean the PEP has to
>translate the entire filesystem into an XML Hierarchy instance
>and actually put it into the Request Context. 

I am not talking about XML, but about making the resource structure part
of the policy, instead of being part of dynamic context.

>I am specifically addressing the problem of how to handle
>tree-structured hierarchical resources.  How do you define a
>"hierarchical resource"?

Ordered graph? But that is not the important part.

>Many resources are organized in tree-structured hierarchies.

The issue is whether you need to know the structure while writing policy
and who owns that structure.

I think that if we can define specification that addresses your use case
while being more flexible, that would be a good thing, wouldn't it? :)


Daniel;