RE: XACML's limitations in the access control for XML documents use case - AW: AW: [xacml] CD-1 issue #11: strictness of xpath definition

From
Tyson, Paul H <>
Date
2009-09-24T19:02:21+00:00
ID
Thread
RE: XACML's limitations in the access control for XML documents use case - AW: AW: [xacml] CD-1 issue #11: strictness of xpath definition
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE Request [
<!ENTITY xacml10 "urn:oasis:names:tc:xacml:1.0:">
<!ENTITY xacml20 "urn:oasis:names:tc:xacml:2.0:">
<!ENTITY xacml30 "urn:oasis:names:tc:xacml:3.0:">
<!ENTITY xs "http://www.w3.org/2001/XMLSchema#">
]>
<Request xmlns="urn:oasis:names:tc:xacml:3.0:core:schema:wd-07"
	 xmlns:ns1="http://example.org"
	 ReturnPolicyIdList="false">
  <Attributes Category="&xacml10;subject-category:subject">
    <Attribute AttributeId="&xacml10;subject-id"
	       IncludeInResult="false">
      <AttributeValue DataType="&xs;string">Bob</AttributeValue>
    </Attribute>
  </Attributes>
  <Attributes Category="&xacml30;attribute-category:resource">
    <Content>
      <objects xmlns="http://example.org">
	<book>
	  <title>xxx</title>
	  <author>Bob</author>
	  <id>100</id>
	  <price>30</price>
	  <book-content>foo</book-content>
	</book>
	<book>
	  <title>yyy</title>
	  <author>Alice</author>
	  <id>200</id>
	  <price>80</price>
	  <book-content>bar</book-content >
	</book>
      </objects>
    </Content>
    <Attribute AttributeId="&xacml10;resource-id"
	       IncludeInResult="true">
      <AttributeValue DataType="&xacml30;data-type:xpathExpression">ns1:objects/ns1:book</AttributeValue>
    </Attribute>
    <Attribute AttributeId="&xacml10;resource:xpath"
	       IncludeInResult="false">
      <AttributeValue DataType="&xacml30;data-type:xpathExpression">ns1:objects/ns1:book</AttributeValue>
    </Attribute>
    <Attribute AttributeId="&xacml20;resource:scope"
	       IncludeInResult="false">
      <AttributeValue DataType="&xs;string">XPath-expression</AttributeValue>
    </Attribute>
  </Attributes>
</Request>