OASIS Open Mailing List Archives  ·  All Lists  ·  xacml  ·  2004-08

xacml — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

RE: [xacml] Groups - oasis-xacml-profile-multiple-resources-wd-03 .pdfuploaded


 MHonArc v2.5.0b2 -->

















xacml message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [xacml] Groups - oasis-xacml-profile-multiple-resources-wd-03 .pdfuploaded


Tim,

Thanks for the comments.  Here is how I responded to them in
Draft 04.

On 17 August, Tim Moses writes: RE: [xacml] Groups - oasis-xacml-profile-multiple-resources-wd-03	.pdf uploaded
 > In sections 3.1.3 and 3.2.3 outcomes of "Indeterminate" and "NotApplicable"
 > are not currently discussed.

I changed text to say explicitly "If any of the new request
contexts evaluates to "Deny", "Indeterminate", or
"NotApplicable", then a single <Result> containing a <Decision>
of "Deny" SHALL be placed into the response context returned to
the PEP.  This is as if the responses were being combined under a
"DenyOverrides" combining algorithm, which seems to be the only
safe single choice.

 > Trivial ...
 > 
 > 19 - Include instructions for using the Web form to submit comments (see
 > text on the front page of the core spec.).

Done.

 > 52 - unbold "authorization".  Only "decision request" is in
the glossary.

I deleted "authorization" and changed to say just "decision
request".

 > 121 and elsewhere - I prefer not to use the section title in the section
 > reference (e.g. Section 4.1:"scope").  This is because it isn't always clear
 > where the section title ends and the normal text continues.

Done.

 > 132 - Change "is the contents of the <AttributeValue>" to "SHALL be the
 > contents of the <AttributeValue> element".

Done.

 > 146 - <children> to <Children> and <descendants> to <Descendants>.  Also,
 > how about a shorter title for sections 2.1 and 2.2.  I suggest: "Nodes
 > identified by scope" and "Nodes identified by XPath"?

I took your suggestions for the shorter titles.

 > In Section 2.1, include a note to the effect that "scope" is defined in
 > Section 4.

Done.

 > 161 - Eliminate duplicate "be".

Done.

 > 168 & 170 - Change "the Individual Resources are" to "each Individual
 > Resource is".

Done.

 > 196 - Change "attribute evaluates" to "attribute is an xpath expression that
 > evaluates".

Done.

 > 223 - Correct formatting of <Resource>.

Done.

 > 224 - Change "the mechanisms" to "the other mechanisms".

Done.

 > 243 - Eliminate duplicate "a".

Done.

 > 266 - Eliminate leading space.

Done.

 > 277 - Change "containing" to "contains".

Done.

 > 277 - Eliminate "That node SHALL be the one corresponding to the new request
 > context.".  I think this is redundant.  Isn't it?

I removed the sentence, but changed the previous sentence to say
"nodeset that contains exactly that one node in the
                               ^^^^
<ResourceContent> element"

My concern was that the XPath expression might well evaluate to
only a single node, but that node might be some node other than
the one that this new Request Context is being constructed for.

 > 295 - Eliminate leading space.

Done.  Eagle eye!

 > 305 - Eliminate "That node SHALL be the one corresponding to the new request
 > context.".  I think this is redundant.  Isn't it?

Same changes as for 277.

Thanks again.

Anne
 > 

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]