xacml — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
RE: [xacml] Proposal on item 7 ConditionReference
MHonArc v2.5.0b2 -->xacml message
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: RE: [xacml] Proposal on item 7 ConditionReference
- From: "Daniel Engovatov" <[email protected]>
- To: "Polar Humenn" <[email protected]>, "Michiharu Kudoh" <[email protected]>
- Date: Wed, 3 Dec 2003 17:28:31 -0800
But shouldn't the LET statement be evaluated as a part of context, not within a particular policy? I think that is one more case for having the third schema. We have <request> - with data pertinent to the individual query, <policy>, and we can use <context> schema for a document relevant to all policies evaluation. A place to declare named attributes and types, there location/source information, functions, that PDP is supposed to understand, and now this LET statement equivalent, for dynamic expression that are to be computed once and used for all policies evaluations. For example a place to define five-minutes-from-now attribute of datetime type defined as (add-time current-time 5 minutes) and so on. Daniel;
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]