Attached version has a few corrections and clarifications.
--Paul
> -----Original Message-----
> From: Tyson, Paul H
> Sent: Friday, October 16, 2009 09:59
> To:
> Subject: [xacml] MAD conceptual model
>
> Attached find proposed description of conceptual model for
> producing single authorization decision requests from a
> multiple authorization decision (MAD) request.
>
> This would replace some content in sections 2.1, 2.2, 2.3.
>
> I came up with a few questions and concerns:
>
> 1. I still don't like the idea of mutable resource-ids.
> Either the original request should have something like
> "resource-selector", or the resulting context should have
> "decision-node-id" or something. But then the problem is,
> how does the PEP request the resource-id to be returned
> (using "IncludeInResult")? We might have to specify some
> built-in semantics to handle this.
>
> 2. This does not specify how the xpathExpression resource-id
> for individual resources will be constructed. The TC is
> still discussing whether to specify this, and if so, what the
> form should be. In any case, it seems necessary to say
> something about the namespace binding context that will be
> used for name prefixes. Default might be to use the
> namespace binding context represented by the union of the
> contexts in <Content> children, but this is not specified.
> One way to facilitate regexp matching on xpath strings would
> be to allow policies and/or requests to specify a namespace
> binding context.
>
> 3. scope=EntireHierarchy is out of place here. Consider
> moving Section
> 3 to hierarchical profile. The conceptual model and expected
> results are different than the other multiple authorization
> decision modes. The "multiple" processing only takes place
> internally--a single decision is expected (possibly
> multiplied by additional subjects or actions).
>
> Regards,
> --Paul
>