xacml — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
RE: [xacml] Hierarhical resources.. part 0.1
MHonArc v2.5.0b2 -->xacml message
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: RE: [xacml] Hierarhical resources.. part 0.1
- From: Anne Anderson <[email protected]>
- To: Daniel Engovatov <[email protected]>
- Date: Tue, 11 May 2004 16:33:30 -0400
On 11 May, Daniel Engovatov writes: RE: [xacml] Hierarhical resources.. part 0.1
> Dang, you may be right. We bypassed this issue for constraints as we
> had functions to make a bag of values. As I was not working with
> request schema I forgot about that.
>
> But, couldn't you just specify multiple instances of the same attribute
> in request context? Attribute currently has exactly one attribute value
> (which is a bad outage in my opinion - we need to be able to bags) -
> but is it prohibited to have multiple attribute with the same
> attributeId?
> In request:
> <resource>
> <Attribute AttributeID = "foo" DataType = "string">
> <AttributeValue >bar</AttributeValue>
> </Attribute>
> <Attribute AttributeID = "foo" DataType = "string">
> <AttributeValue >spam</AttributeValue>
> </Attribute>
> <resource>
>
> Would not that define bag[string] foo = ["bar", "spam"] ?
It is perfectly legal to have multiple Request Attributes with
the same AttributeId.
Also, we have already decided to define
<Attribute >
<AttributeValue>val1</AttributeValue>
<AttributeValue>val2</AttributeValue>
<AttributeValue>val3</AttributeValue>
</Attribute>
as equivalent to:
<Attribute >
<AttributeValue>val1</AttributeValue>
</Attribute>
<Attribute >
<AttributeValue>val2</AttributeValue>
</Attribute>
<Attribute >
<AttributeValue>val3</AttributeValue>
</Attribute>
so, yes, that is an alternative way to specify the multiple
values for "resource-ancestor" and "resource-parent" Attributes.
>
>
> Of cause defining "bag" metadata along with datatype, and supplying
> multiple
> <AttributeValue>'s is much better.
>
> Remind me - why do we not send bags in a request?
1) We do not have functions to operate on bags of bags, if that
is what you are asking
2) We already have syntax for sending "bags" in the request, if
you are just asking for an <AttributeDescriptor> or
<AttributeSelector> that evaluates to a "bag": they always
evaluate to a bag that contains one element for each Attribute
or nodeset node that matches. See above.
Polar can probably give you more reasons :-)
Anne
>
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]